Security Researcher II

Last updated 12 days ago
Location:Redmond, Washington
Job Type:Full Time

Come and be part of the team building one of Microsoft’s most exciting security products, Microsoft Defender Advanced Threat Protection (MDATP). As cyber-attacks have become more sophisticated, MDATP helps enterprises detect, investigate, and respond to advanced attacks and data breaches on their networks. From detecting nation state actors to patient zero ransomware infections, our research team brings deep knowledge of the attacker landscape and tradecraft to create the innovations necessary to uncover even the most well-funded attacker.

We are seeking a Security Researcher who is excited by uncovering unknown attacks to join our research team.

The job includes researching our rich sensors data, identifying necessary optics for detecting malicious behavior, and crafting detection logic to ensure compromise does not go undetected.





Primary responsibilities would include:

  • Investigate, analyze and learn from security researchers, attackers and real incidents in order to develop durable detection strategies across the entire kill-chain or product enhancements.
  • Collaborate with data science teams to understand and identify detection gaps, capabilities, assumptions, and improvements.
  • Collaborate with multiple product teams to design sensors, implement detection ideas, and validate their effectiveness using a data-driven approach.
  • Collaborate with internal Redteams to research novel ways that can be used to compromise computer infrastructures or break defense layers.


Required qualifications:

  • 2+ years of software development/research experience
  • Deep and practical Windows internals knowledge (other OS experience may count)
  • Reverse Engineering skills: familiar with debuggers, disassemblers, protocols, file formats
  • Excellent cross-group and interpersonal skills

Preferred qualifications:

  • Offensive security research experience for Endpoint and Cloud-based attacks
  • Development skills with C++/C# and scripting languages (PowerShell, Python)
  • Industry recognized author of security research papers, blogs, or books
  • Experience exploiting bugs and bypassing security mitigations

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.