Principal Security Researcher
Cheltenham, England, United Kingdom · Full Time
Be the first to apply
- Experience
- Any
- Salary
- GBP 93,500 – GBP 161,800 / year
- Openings
- 1
- Posted
- 12 seconds ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join Microsoft’s Cloud & AI team, dedicated to securing digital platforms, devices, and cloud environments for customers worldwide. The culture fosters growth, innovation, and excellence aimed at creating transformative security solutions impacting billions globally. As a Principal Security Researcher on the Global Hunting, Oversight, and Strategic Triage (GHOST) team, you will play a critical role in defending against advanced cyber threats, supporting global threat hunts, and integrating investigation insights into Microsoft security products.
Role Responsibilities
- Lead incident investigations and guide teams in deep analysis of attacker behaviors across on-premises and cloud infrastructures.
- Proactively detect emerging cyber threats to enable early defensive measures.
- Communicate technical findings and strategic recommendations to enhance customers’ security postures and transmit threat intelligence knowledge.
- Specify and contribute to the development of threat hunting tools, automations, and advanced capabilities in production environments.
- Shape investigation strategies, pioneer new hunting techniques, and influence security practices and products across multiple teams.
- Mentor team members to elevate both technical and communication capabilities.
Candidate Requirements
- Proven extensive experience in Threat Hunting, Digital Forensics and Incident Response (DFIR), Threat Intelligence, or Security Research.
- Background in investigating sophisticated cyber attacks, including Advanced Persistent Threats (APT) and nation-state actors.
- Hands-on experience with forensically acquired data, security logs, telemetry, and SIEM platforms.
- Expert command of query languages such as KQL, Splunk, Humio, or Kibana.
- Familiarity with Endpoint Detection & Response (EDR) and security monitoring tools like Microsoft Defender, Microsoft Sentinel, CrowdStrike, or equivalents.
- Experience managing or assessing Microsoft Azure, Microsoft 365, and Entra ID tenant security.
- Ability to analyze security datasets to detect attacker activities, pinpoint IOCs, IOAs, and Tactics, Techniques, and Procedures (TTPs).
- Knowledge of digital forensic collection procedures and analysis tools like X-Ways Forensics.
- Strong English communication skills and collaboration experience in global teams.
- Eligibility to obtain and maintain UK security clearance.
Preferred Qualifications
- Certifications related to cybersecurity and incident response such as CISSP or GIAC.
- Experience spanning multiple cybersecurity areas including threat hunting, incident response, digital forensics, and threat intelligence.
- Proven leadership in guiding technical workstreams during incident response activities.
- Deep knowledge of Microsoft security platforms such as Defender, Sentinel, and Entra ID.
- Capability to handle large-scale security telemetry and conduct enterprise-wide threat hunting.
- Basic scripting knowledge or aptitude to interpret code and automation workflows.
Compensation and Additional Information
The typical salary range for this role in the United Kingdom is £93,500 to £161,800 annually. The position includes eligibility for benefits and other compensation. Applications are reviewed on a rolling basis until the role is filled, with a minimum posting duration of five days.
Diversity and Inclusion
Microsoft is committed to equal opportunity employment regardless of diverse characteristics including age, gender identity, disability status, ethnicity, and more. Reasonable accommodations for applicants with disabilities or religious needs can be requested during the application process.