Source description
About the role
As a Senior Security Researcher on the MTP Research Purple Team, you will: Design and execute adversary simulations that emulate real-world threat actors across endpoint, identity, cloud, and SaaS environments. Develop and modify offensive tooling, including custom payloads, loaders, and command-and-control (C2) frameworks. Conduct malware development and tradecraft research to replicate modern attacker techniques such as evasion, persistence, and lateral movement. Leverage threat intelligence to inform adversary emulation scenarios, including campaign design, TTP selection, and operational sequencing. Apply threat modeling frameworks such as MITRE ATT&CK to emulate realistic attack paths and identify defensive gaps. Utilize AI-enabled and agentic systems to generate attack variations, automate tradecraft execution, and scale simulation coverage. Partner with blue team and detection engineering teams to validate detections and improve defensive capabilities. Analyze telemetry generated from simulations to assess detection coverage and identify opportunities for improvement. Contribute to simulation reports, technical documentation, and internal knowledge sharing. Collaborate across teams to improve offensive tooling, methodologies, and research practices. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field. OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. These requirements include, but are not limited to the following specialized security screenings: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR equivalent experience. 5+ years of incident response, threat hunting, and/or SOC experience. Experience leveraging and producing threat intelligence at the campaign or actor level. Knowledge of MITRE ATT&CK and threat modeling methodologies. Security related certifications such as: GCIA, GMON, GCIH, CISA. 3+ years of experience with coding. Experience in classical and deep learning machine learning methods.
More at Microsoft
Related open roles
Program Manager, Global Security Access Management (GSAM)
Seattle · Onsite
Principal Technical Advisor for Cybersecurity Incident Response
Seattle · Dallas–Fort Worth · Onsite
Security Engineer
London · Dublin · Onsite
Security Cloud Solution Architect- CTJ - Poly
Washington DC · Onsite
Senior Cloud Solution Architect - Security / Global Solutions
Tokyo · Onsite
Sr Technology Security Consultant-CTJ-TS/SCI
United States · Onsite