Responsibilities (Text Only)
This role is part of a collaborative team, assisting our customers with:
- Performing deep analysis of attacker activity in on-premises and cloud environments
- Identifying potential threats to enable proactive defense before incidents occur
- Notifying customers about imminent attacker activity
- Providing recommendations to improve cybersecurity posture and performing threat intelligence knowledge transfer
- Building proof-of-concept and prototype threat hunting tools, automations, and capabilities
- Driving product and tooling improvements by sharing insights from threat hunting and incident response with engineering teams
- Identifying, prioritizing, and targeting complex security issues impacting customers and driving adoption of mitigations
- Synthesizing research findings into mitigation recommendations and sharing across teams to foster change
Qualifications (Text Only)
Required qualifications include:
- Bachelor's degree in Computer Science, Engineering, or related experience
- Proven knowledge of security fundamentals across Microsoft platforms (Client, Server, Cloud)
- Strong understanding of malware and the modern threat landscape, especially identity-based attacks
- Excellent communication skills, both oral and written
- Critical thinking skills and willingness to learn new concepts and technologies
- Familiarity with SQL or Kusto Query Language (KQL), and threat hunting automations
- Experience with forensic analysis tools and security solutions
- Knowledge of Windows internals, Linux/macOS forensic analysis, and third-party cybersecurity solutions
- Certifications such as Azure, CISSP, SANS GIAC, etc., are advantageous
- The candidate must be able to obtain or have Security Check (SC) or Developed Vetting (DV) clearance as required
If you are passionate about strengthening customer security, this role offers a promising future within Microsoft's Global Hunting Oversight and Strategic Triage team.
Microsoft is an equal opportunity employer. For accommodations due to disability, please contact us through the provided form.