Microsoft

Senior Security Researcher

Microsoft

Sydney, New South Wales, Australia · Full Time

Be the first to apply

Experience
4+ yrs
Salary
—
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor’s Degree in Statistics, Mathematics, Computer Science, Computer Security, or a related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Overview

The Cloud & AI division propels Microsoft's commitment to secure digital platforms, devices, and cloud services in diverse client environments, alongside safeguarding our own internal infrastructure. We nurture a culture focused on growth mindset, striving for excellence, and motivating teams and leaders daily to deliver transformative innovations impacting billions globally. Microsoft ranks among the largest global enterprise service providers.

This position appeals to individuals passionate about assisting Microsoft clients in defending against sophisticated cyber threats. You will engage with the newest security technologies and influence protection across all Microsoft customers. The role involves frontline challenges with evolving adversaries and constant new opportunities within the Applied Intelligence team.

Key Responsibilities

  • Support investigations by integrating Microsoft Threat Intelligence Center (MSTIC) insights into live internal and customer security incidents.
  • Lead attribution and adversary profiling, handling intelligence ingestion, analysis, and documentation while collaborating with forensic and response units.
  • Assist Microsoft security teams through delivering actor attribution and tailored intelligence support during threat response activities.
  • Translate detected threat actor exploit techniques against Microsoft products into actionable product security enhancements.
  • Identify and research emerging, previously unmonitored adversary groups using multiple analytic frameworks and telemetry.
  • Provide intelligence briefings for external clients and internal stakeholders, and facilitate alerts related to active or imminent cyber threats.
  • Create a feedback process that ensures newly gathered intelligence during investigations is integrated into Microsoft's ongoing adversary tracking and defense programs.

Required Qualifications

  • Advanced degree in Statistics, Mathematics, Computer Science, Security, or a related discipline with significant professional experience in software development, large-scale systems, threat modeling, cybersecurity, vulnerability research, or anomaly detection.
  • Profound expertise in adversary capabilities, infrastructure, and tactics, with innovative abilities for detection and tracking.
  • Experience mapping and attributing advanced financially motivated or state-sponsored attackers using models such as the Diamond Model, with detailed understanding of TTPs, infrastructure, and operational campaigns.
  • A history of generating actionable threat intelligence that materially influenced investigations or enhanced network defense.
  • Knowledge of system, network, and host forensics, common protocols, and adversary command-and-control methods.
  • Competency in log analysis and query languages like KQL/Kusto, SQL, or equivalents applied to SIEM, identity, endpoint, or cloud telemetry environments.
  • Working familiarity with large-scale cloud infrastructure, identity systems, and endpoint telemetry.
  • Experience supporting incident response operations, including an understanding of standard procedures and tools.
  • Effective communication skills tailored to both technical and executive audiences, employing appropriate confidence language.

Preferred Qualifications

  • Higher advanced degree plus extended experience in software development lifecycle, large-scale computing, threat analysis, cybersecurity, vulnerability research, or anomaly detection.
  • Experience with cloud and identity-related intrusions such as token theft, OAuth exploitation, and SaaS-native tactics.
  • Expertise in detection engineering or large-scale threat hunting query creation.
  • Utilization of automation, data science, and AI technologies to speed triage, clustering, and analysis processes.
  • Experience delivering executive or customer briefings promptly during active incident response situations.
  • Knowledge of malware behavior and triage in targeted campaigns.
  • Familiarity with Microsoft security telemetry sources including MDC, Defender XDR, Sentinel, and Azure Resource Graph.

Additional Information

This position will remain open for at least five days with ongoing application acceptance until filled. Microsoft practices equal opportunity in employment, considering qualified applicants regardless of various protected characteristics. Accommodations for disabilities or religious needs during application can be requested as per company policy.

Minimum education

Master's Degree

How they work

Communication Teamwork & Collaboration Problem Solving Attention to Detail

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer