← Back to jobs
M

Principal Security Researcher

Microsoft·Israel·en
Not specifiedFull-timeThreat IntelligenceEnterprise SoftwareCybersecurity

Lead technical strategy and multi-quarter research initiatives for identity threat detection and response. Investigate attacker tradecraft, develop resilient detections, guide AI-assisted research workflows, mentor researchers, and influence security product strategy.

Responsibilities

  • Set technical direction and multi-quarter strategy for identity protection research
  • Lead concurrent end-to-end investigations and resolve complex technical questions
  • Analyze identity and related data to identify novel threats, attacker tradecraft, and detection opportunities
  • Design resilient detection logic across the attack kill chain
  • Partner with product management, engineering, data science, and research teams on product strategy and roadmaps
  • Mentor researchers through technical reviews, coaching, and complex investigations
  • Define and evaluate generative AI patterns and workflows for triage, hypothesis generation, coding, and detection synthesis
  • Represent the security research team through publications, conference talks, blogs, and industry engagement

Requirements

  • At least 10 years of cybersecurity experience, including at least 4 years focused on identity-based attacks through research, hunting, or detection engineering
  • Deep knowledge of the modern attacker kill chain and MITRE ATT&CK
  • Track record of owning defensive research from threat hypothesis through shipped detection and customer impact
  • Knowledge of Windows internals and identity protocols including Kerberos, NTLM, LDAP, OAuth 2.0, and SAML
  • Fluency with generative AI tools, including prompt design, output validation, and integration into investigation, coding, and detection authoring
  • Strong cross-group leadership, communication, and influencing skills

Nice to have

  • B.Sc. or M.Sc. in Computer Science or a related technical discipline
  • Experience with C#, Python, or C++ and a query language such as KQL, SQL, or Cypher
  • Windows or cloud forensics experience involving credential theft and lateral movement
  • Published security research, conference talks, blogs, CVEs, or open-source contributions
  • Experience applying AI or LLM-assisted workflows to security research, detection engineering, or threat intelligence
  • Established external thought leadership in the security research community

Relevance

More opportunities

Similar jobs

The newest open roles in Threat Intelligence.

Questions, answered

Frequently asked questions