About the Role
The Microsoft Threat Protection Research (MTP-R) Purple Team is seeking a principal-level security researcher with deep experience in threat operations and Defender tooling. This role involves designing, executing, and analyzing advanced adversary simulations, collaborating with engineering and detection teams, and translating attacker tradecraft into defensive improvements. The position operates in an AI-first environment, leveraging agentic systems and LLM-driven workflows to scale simulation design, automation, and validation.
Responsibilities
- Design and execute purple team simulations emulating real-world threat actors, techniques, and campaigns across endpoint, identity, cloud, and email surfaces, incorporating both human-driven and agentic execution models.
- Partner closely with Microsoft Defender engineering, research, and threat intelligence teams to evaluate detection coverage, investigation quality, and response effectiveness.
- Analyze telemetry using Kusto / KQL to validate detection logic, uncover gaps, and measure signal quality at scale.
- Translate attacker tradecraft into actionable insights for defenders, including detection recommendations, telemetry requirements, and investigation improvements.
- Apply frameworks such as MITRE ATT&CK to map adversary behavior, identify coverage gaps, and communicate findings clearly to technical and non-technical audiences.
- Leverage and contribute to threat intelligence by consuming real-world campaign data and producing new insights through simulation outcomes, TTP discovery, and adversary emulation research.
- Design, build, and leverage AI-enabled and agentic systems to automate simulation workflows, generate attack variations, validate detections, and accelerate post-simulation analysis.
- Evaluate the effectiveness of AI-driven detections and defenses, identifying strengths, gaps, and opportunities for improvement across agentic security capabilities.
- Contribute to written simulation reports, executive presentations, and technical documentation that influence product and security strategy.
Requirements
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- Equivalent experience.
- Ability to meet Microsoft, customer and/or government security screening requirements.
- Must pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- 8+ years of incident response, threat hunting, and/or SOC experience.
- Experience leveraging and producing threat intelligence at the campaign or actor level.
- Advanced knowledge of MITRE ATT&CK and threat modeling methodologies.
- Security related certifications such as: GCIA, GMON, GCIH, CISA.
Skills
- Threat operations
- Defender tooling
- Adversary simulations
- AI-first environment
- Agentic systems
- LLM-driven workflows
- Kusto / KQL
- MITRE ATT&CK
- Threat intelligence
- Incident response
- Threat hunting
- SOC experience
Location
- U.S.
Work Type
- Full-time
Experience Level
- Principal
- IC5
Education Level
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field
- Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field
- Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field
Salary/Compensations
- USD $142,800.00 - $274,800.00 per year (U.S.)
- USD $188,000.00 - $304,200.00 per year (San Francisco Bay area and New York City metropolitan area)
Benefits
- Certain roles may be eligible for benefits and other compensation.
About the Company
- Microsoft Security aspires to make the world safer by empowering every user, customer, and developer with a security cloud that delivers end-to-end, simplified protection.
- The Microsoft Threat Protection Research (MTP-R) Purple Team sits at the intersection of offense, defense, and intelligence, working across Microsoft Defender technologies to ensure telemetry, detections, and protections are effective against real-world cyberattacks.
- Our culture is grounded in a growth mindset, inspiring excellence, and enabling teams and leaders to bring their full potential each day.
Equal Opportunity
- Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances.
- If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
