Match your resume skills with our AI powered skill match!
The role involves applying threat intelligence to live investigations across Microsoft products and customer estates to drive attribution and incident response. You will collaborate with internal teams to discover emerging adversary activity and translate findings into actionable product improvements.
The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.
Do you have a passion for helping Microsoft’s clients defend themselves against targeted exploitation? Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry and having a direct impact on the security of all Microsoft customers? Do you want to be on the front lines of helping our customers go toe-to-toe against advanced adversaries? Are you interested in a fast-paced job full of new opportunities? Consider applying for the Senior Security Researcher position within the Applied Intelligence team.
As an Applied Intelligence Analyst, you will apply Microsoft Threat Intelligence Center (MSTIC)’s threat intelligence to live investigations across Microsoft's products, services, and customer estates. You sit where intelligence meets incident response: enriching investigations with threat actor context, driving attribution, producing actionable intelligence, discovering and building out emerging clusters of adversary activity, and feeding what you learn back into Microsoft's threat actor tracking mission. In this role, you will collaborate with internal teams (GHOST, DART, etc.) across incident response, threat intelligence, and product groups to protect both Microsoft and Microsoft’s customers. You will strengthen existing partnerships and build new ones with key organizations to deliver benefits to Microsoft and its customers.
Background in cloud and identity-based intrusions — token theft, OAuth abuse, SaaS-native tradecraft
Detection engineering or hunting query development at scale
Use of automation, data science, or AI tooling to accelerate triage, clustering, and analysis
Experience delivering customer or executive briefings under time pressure during active incidents
Working knowledge of malware used in targeted campaigns, including triage of malicious capabilities.
Familiarity with Microsoft security data sources - MDC, Defender XDR, Sentinel, Azure Resource Graph.
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 222,160+ Jobs in Others
Answer easy questions
222,160+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”