Home
/
Comprehensive
/
Principal Security Researcher
Principal Security Researcher-May 2024
Redmond
May 13, 2026
About Principal Security Researcher

  Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.

  The Microsoft Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) research team empowers security teams around the world to efficiently and effectively detect and respond to cyber-attacks. We accomplish this through a multifaceted approach, which involves several key areas: understanding, normalizing, conceptualizing, and distilling unparalleled security data volumes into meaningful security value, conducting extensive research on adversary tradecraft, tracking emerging techniques in the public domain, and embracing our researchers' curiosity and 'think like an attacker' mentality. This approach leads to a profound understanding of the technology used within the enterprise environment and drives the application of this technology towards the identification and protection of novel attack vectors. It is our objective to rapidly understand new threats and develop automated actions and investigation methods to protect customers and help security operations teams be as effective as possible.

  We are looking for a Principal Security Researcher who is interested in making a meaningful impact in the security industry, enjoy the challenge of working with extensive, disparate data from across the Microsoft security product stack, driving solutions for data availability, normalization and usability to empower security research to easily correlate and bring context to attacks for customers, and, most importantly, are fascinated by protecting humanity through curiosity.

  Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

  Responsibilities

  Use your deep security research and data wrangling background to help design the next generation security platform.

  Driving and implementing solutions that accelerates efficiency and effectiveness of threat research across Microsoft Security.

  Empower the easy use and access of data for the purposes of adversary tradecraft research and threat landscape investigation on attacks spanning devices, identities, email, applications, and cloud infrastructure.

  Analyze, drive data requirements, and enable report building on cross-product correlated security incidents that will drive identification of new threat intelligence including attack trends, new techniques, and other information relevant to further threat research and protection of Microsoft’s customers.

  Drive Research platform improvements discovered through the process of threat research: developing automated protections, combining alerts and signals across the Microsoft Defender security products and Microsoft Sentinel ecosystem.

  Conduct data studies to gain a deep understanding of the data produced, not only by our own technology but also by the services our customers use, including third-party sources.

  Qualifications

  Required Qualifications:

  7+ years of computer security industry experience with knowledge of security data platforms, security data manipulation, adversary tradecraft and of emerging threats and techniques for attacks against cloud and identity services

  OR Doctorate in Statistics, Mathematics, Computer Science or related field.

  Experience designing and driving engineering requirements for security data use at scale such as with Azure Synapse, Azure Data Lake, SQL, Cosmos, Kusto, or similar systems AND experience with one or more of the following: Azure Functions, Azure Static Web Sites, Azure Containers, Azure DevOps pipelines, Github actions, Github Codespaces, and Jupyter Notebooks.

  Experience within coding with languages such as C#, Python and/or PowerShell AND language independent data formats such as JSON/ YAML/XML.

  Experience applying MITRE ATT&CK to assess threat scenarios and protection coverage across both cloud and hybrid (cloud + on prem) attacks.

  Other Requirements:

  Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

  Preferred Qualifications:

  Offensive security research experience for cloud or hybrid-based attacks.

  Reverse engineering and/or Incident Response experience.

  Experience with cross-group and interpersonal skills, with the ability to articulate the business need for product improvements and a desire to engage directly with customers.

  Demonstrated experience in conducting data studies, including the ability to work with available telemetry and drive improvements with engineering teams for previously unexplored data sources.

  Security Research IC5 - The typical base pay range for this role across the U.S. is USD $133,600 - $256,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $173,200 - $282,200 per year.

  Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

  #MSFTSecurity

  Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations (https://careers.microsoft.com/v2/global/en/accessibility.html) .

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Store Associate
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced
Customer Service Associate
Job Description: Models and delivers a distinctive and delightful customer experience. Registers sales on assigned cash register, provides customers with courteous, fair, friendly, and efficient chec
TSSCI Cyber Network Defense Analyst
Job Description An employer is looking for a TSSCI Cyber Countermeasures Analyst to sit at Fort Meade. This person is going to be responsible for being the subject matter expert of a specific system
Cleaner
Overview Position Summary Details The Cleaner position provides the cleaning and upkeep of an assigned area. Essential Functions Cleans and maintains buildings/facilities. Performs heavy cleaning dut
Special Education Teacher - Fortville, IN $45 Hourly
Special Education Teacher –Fortville, IN $45 Hourly Hours: 35 Location:Fortville, IN Start Date: asap $45 Hourly 23/24 school year, 6thgrade Requirements:IN SPED License The Special Education Teacher
School Bus Driver
School Bus Driver Location352 Concord Rd Sudbury, Massachusetts 01776 USPhone NumberCategoriesDriversReq IDJR367 School Bus Driver (Open) First for a reasonFirst Student is the largest school transpo
Security Officer
Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workp
Merchandiser Stocker
Job Overview Merchandiser for Greater Moon Township, PA The Merchandiser is responsible for providing high-quality merchandising support for Keurig Dr Pepper brands like 7UP, Snapple, Core, Bai and o
Senior Member of Technical Staff
Job Description Cloud Engineering Infrastructure Development - Virtual Machine Control Plane At Oracle Cloud Infrastructure (OCI), we build the future of the cloud for Enterprises as a diverse team o
Retail Cashier Part Time
Req ID: 431465 Address: 7791 NW 47th Ave Ocala, FL, 34482 Benefits: * Paid Time Off * Flexible Scheduling * 401(k) – 100% Match up to 5% * Medical/Dental/Vision Insurance after 30 days * Competitive
Copyright 2023-2026 - www.zdrecruit.com All Rights Reserved