Home
/
Comprehensive
/
Principal Security Researcher
Principal Security Researcher-March 2024
Redmond
Mar 28, 2026
About Principal Security Researcher

  Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.

  The Microsoft Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) research team empowers security teams around the world to efficiently and effectively detect and respond to cyber-attacks. We accomplish this through a multifaceted approach, which involves several key areas: understanding, normalizing, conceptualizing, and distilling unparalleled security data volumes into meaningful security value, conducting extensive research on adversary tradecraft, tracking emerging techniques in the public domain, and embracing our researchers' curiosity and 'think like an attacker' mentality. This approach leads to a profound understanding of the technology used within the enterprise environment and drives the application of this technology towards the identification and protection of novel attack vectors. It is our objective to rapidly understand new threats and develop automated actions and investigation methods to protect customers and help security operations teams be as effective as possible.

  We are looking for a Principal Security Researcher who is interested in making a meaningful impact in the security industry, enjoy the challenge of working with extensive, disparate data from across the Microsoft security product stack, driving solutions for data availability, normalization and usability to empower security research to easily correlate and bring context to attacks for customers, and, most importantly, are fascinated by protecting humanity through curiosity.

  Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

  Responsibilities

  Use your deep security research and data wrangling background to help design the next generation security platform.

  Driving and implementing solutions that accelerates efficiency and effectiveness of threat research across Microsoft Security.

  Empower the easy use and access of data for the purposes of adversary tradecraft research and threat landscape investigation on attacks spanning devices, identities, email, applications, and cloud infrastructure.

  Analyze, drive data requirements, and enable report building on cross-product correlated security incidents that will drive identification of new threat intelligence including attack trends, new techniques, and other information relevant to further threat research and protection of Microsoft’s customers.

  Drive Research platform improvements discovered through the process of threat research: developing automated protections, combining alerts and signals across the Microsoft Defender security products and Microsoft Sentinel ecosystem.

  Conduct data studies to gain a deep understanding of the data produced, not only by our own technology but also by the services our customers use, including third-party sources.

  Qualifications

  Required Qualifications:

  7+ years of computer security industry experience with knowledge of security data platforms, security data manipulation, adversary tradecraft and of emerging threats and techniques for attacks against cloud and identity services

  OR Doctorate in Statistics, Mathematics, Computer Science or related field.

  Experience designing and driving engineering requirements for security data use at scale such as with Azure Synapse, Azure Data Lake, SQL, Cosmos, Kusto, or similar systems AND experience with one or more of the following: Azure Functions, Azure Static Web Sites, Azure Containers, Azure DevOps pipelines, Github actions, Github Codespaces, and Jupyter Notebooks.

  Experience within coding with languages such as C#, Python and/or PowerShell AND language independent data formats such as JSON/ YAML/XML.

  Experience applying MITRE ATT&CK to assess threat scenarios and protection coverage across both cloud and hybrid (cloud + on prem) attacks.

  Other Requirements:

  Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

  Preferred Qualifications:

  Offensive security research experience for cloud or hybrid-based attacks.

  Reverse engineering and/or Incident Response experience.

  Experience with cross-group and interpersonal skills, with the ability to articulate the business need for product improvements and a desire to engage directly with customers.

  Demonstrated experience in conducting data studies, including the ability to work with available telemetry and drive improvements with engineering teams for previously unexplored data sources.

  Security Research IC5 - The typical base pay range for this role across the U.S. is USD $133,600 - $256,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $173,200 - $282,200 per year.

  Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

  #MSFTSecurity

  Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations (https://careers.microsoft.com/v2/global/en/accessibility.html) .

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Creative Lead / Designer II
Company Summary DISH, an EchoStar Company, is a Fortune 250 that is reimagining the future of connectivity. For over 40 years, we’ve been challenging the status quo and evolving our company to antici
Health Technician (Dietetic)
Summary The Dayton Veterans Affairs Medical Center (VAMC) is recruiting for a Health Technician. The Health Technician will function with in Nutrition and Food Services. The primary purpose of the po
Hotel Laundry Attendant
Req ID: 431582 Address: 7101 W. Sundust Rd Chandler, AZ, 85226 Welcome to Love’s! * * Where People are the Heart of Our Success * * Hotel Laundry Attendant Laundry Attendants are expected to maintain
Phlebotomist
Description Want to Expand your career-development potential, your ability to help donors and patients, and your access to professional opportunities? We’re growing fast. [You can, too!] There are so
Water / Wastewater Engineering Manager 6 - US Hybrid
Water / Wastewater Engineering Manager 6 - US Hybrid Date: Jan 23, 2024 Location: US Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success.
Intermediate Compliance Specialist (Hybrid Work Option)
36718BR Requisition ID: 36718BR Business Unit: COR Job Description: CDM Smith is seeking an Intermediate Compliance Specialist to join our Corporate Compliance Team. This individual performs basic to
Pharmacy Technician
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced
Dispatcher
Dispatcher Location19 Natalie Way Plymouth, Massachusetts 02360 USPhone NumberCategoriesOperation SupportReq IDJR1372 Dispatcher (Open) First for a reasonFirst Student is the largest school transport
Senior Member of Technical Staff (JoinOCI-SDE)
Job Description We are seeking a strong engineer to join our team which is focused on building and maintaining a scalable software control platform for Compute Infrastructure. Major focus areas of so
L2 Customer Technical Support Analyst - MICROS - Simphony/Ebusiness
Job Description L2 Customer Technical Support Analyst - MICROS - Simphony/Ebusiness Location: Orlando, FL or Columbia, MD highly preferred No visa sponsorship is available for this position. As a mem
Copyright 2023-2026 - www.zdrecruit.com All Rights Reserved