Principal Security Researcher at Microsoft | England, GB | Rezi

Principal Security Researcher at Microsoft

Principal Security Researcher

Microsoft · England, GB

1 weeks ago

Principal Security Researcher

Microsoft · England, GB

11 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Join the Global Hunting, Oversight, and Strategic Triage (GHOST) team as a Principal Security Researcher with a Digital Forensics and Incident Response background. This role involves performing threat hunts, assisting with investigations, developing threat intelligence, and cultivating investigation best practices into Microsoft tooling and products. You will support a global team to identify and catalog new attacker TTPs, victims, and deliver customer notifications to protect worldwide enterprise customers and empower them to protect themselves via constantly improving Microsoft products.

Responsibilities

  • Lead technical workstreams during investigations and guide others in deep analysis of attacker activity in on-premises and cloud environments.
  • Identify potential threats for proactive defense before an incident.
  • Present technical findings and recommendations to improve customers’ cybersecurity posture.
  • Perform threat intelligence knowledge transfer to prepare customers to defend against the current threat landscape.
  • Define requirements for and assist in the development of production threat hunting tools, automations, and new capabilities.
  • Drive investigation strategy and develop new hunting methodologies.
  • Influence security products and practices across multiple teams.
  • Mentor others and help the team upskill in hard and soft skills.

Requirements

  • Extensive and demonstrated professional experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research.
  • Experience investigating sophisticated cyber threats, including APT or nation-state activity.
  • Extensive experience working with forensically collected data (and tooling), security telemetry, logs, and SIEM platforms.
  • Expertise in KQL or equivalent query languages (Splunk, Humio, Kibana, etc.).
  • Experience with EDR and security monitoring technologies such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, or similar platforms.
  • Experience managing or conducting security review of Microsoft Azure tenants, Microsoft 365, and Entra ID.
  • Proven ability to analyze security data to investigate attacker activity, and derive indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs.
  • Experience and familiarity with the collection of Digital Forensic data, as well as case management and forensic analysis tooling such as X-Ways Forensics.
  • Excellent written and verbal communication skills in English.
  • Ability to work in a global team environment.
  • Ability to obtain and maintain a UK Security Clearance.

Skills

  • Threat Hunting
  • Incident Response (DFIR)
  • Threat Intelligence
  • Security Research
  • Digital Forensics
  • KQL
  • Splunk
  • Humio
  • Kibana
  • EDR
  • Microsoft Defender
  • Microsoft Sentinel
  • CrowdStrike
  • Microsoft Azure
  • Microsoft 365
  • Entra ID
  • X-Ways Forensics
  • Cybersecurity

Location

  • United Kingdom

Work Type

  • Full-time

Experience Level

  • Principal
  • IC5

Education Level

  • Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC) are preferred.

Salary/Compensations

  • £ 93,500.00 - £ 161,800.00 per year

Benefits

  • Certain roles may be eligible for benefits and other compensation.

About the Company

  • The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.
  • Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day.
  • In doing so, we create life-changing innovations that impact billions of lives around the world.
  • Microsoft is one of the largest enterprise service companies in the world.
  • Microsoft’s mission is to empower every person and every organization on the planet to achieve more.
  • As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals.
  • Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
  • In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.

Equal Opportunity

  • Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances.
  • If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.