Senior Security Researcher
Multiple Locations | Security Engineering | Feb 09, 2025 | Job number 1806526


Come and be part of the team building one of Microsoft’s most exciting security products, Microsoft Defender for Endpoint.  As cyber-attacks have become more sophisticated, MDE helps enterprises detect, investigate, and automatically disrupt advanced attacks and data breaches on their networks. From detecting nation state actors to advanced ransomware actors in action, our research team brings deep knowledge of the attacker landscape and tradecraft to create the innovations necessary to uncover and protect against even the most well-funded adversaries. 

 

We are seeking an experienced security researcher who is excited by uncovering unknown attacks to join our Israeli research team and focus on detecting and disrupting sophisticated enterprise attacks. The job includes researching novel attack techniques, hunting through our rich sensor data, identifying necessary optics for detecting malicious behaviour and crafting detection and protection logic to ensure compromise does not go undetected. 

 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.



Responsibilities

  • Investigate, analyse, and expand MDE security, by exploring real incidents, developing durable protection strategies, and circumventing threats across the entire kill-chain 
  • You will collaborate with multiple product teams to design sensors, implement protection ideas, and validate their effectiveness using a data-driven approach 
  • You will collaborate with data science teams to drive ML based protections, understand, and identify detection gaps, capabilities, assumptions, and improvements 
  • Be involved in customer conversations to identify opportunities, gaps, and concerns to improve product protection value 


Qualifications

 

  • BS+ in Computer Science\Computer Engineeringor equivalent engineering degrees 
  • You have 6+ years of software development/research experience 
  • You have In-depth knowledge and experience with the security threat landscape  
  • You have extensive, practical OS internals knowledgeof Windows 
  • You have reverse Engineering skills: familiar with debuggers, disassemblers, protocols, file formats 
  • Excellent cross-group and interpersonal skills 
  • Code fluency in either C#, C, Python or Rust  

 

Preferred qualifications: 

 

  • Offensive security research experience 
  • Digital forensics, Incident response and threat hunting skills 
  • Industry recognized author of security research papers, blogs, or books 
  • Low-level/security knowledge of other operating systems 
  • Familiarity with cloud environments, and hybrid cloud enterprise services 

 

Other Requirements:


Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:
- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: - This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter. - Experience in authoring of security research papers, blogs, or books. - Experience with Windows forensics and an understanding of key forensic artifacts, especially around lateral movement scenarios. - Experience with Cloud forensics, including identity attack artifacts and lateral movement techniques.

 

 

#MSFTSecurity #MSFTSecurity #MSFTSecurity #MDEIL

#researchMailerFeb

 

 

 

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.  We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.

 

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.




Make
your
mark