New job, posted less than a week ago!
Job Details
Posted date: Sep 10, 2025
There have been 26 jobs posted with the title of Security Researcher all time at Microsoft.There have been 26 Security Researcher jobs posted in the last month.
Category: Security Engineering
Location: Redmond, WA
Estimated salary: $158,000
Range: $100,600 - $215,400
Employment type: Full-Time
Travel amount: 25.0%
Work location type: 3 days / week in-office
Role: Individual Contributor
Description
The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.We are hiring a Security Researcher for the GHOST team. Do you want to join the Microsoft GHOST team as a Security Researcher specializing in Identity?⯠Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry and having a direct impact on the security of all Microsoft customers? Are you interested in a fast-paced job full of new opportunities? If so, you might be a candidate for the IDFIRE team within the Global Hunting, Oversight, and Strategic Triage (GHOST) organization.â¯â¯â¯
IDFIRE, is the premier identity cyber threat hunting and investigation team in the industry. We are looking for an experienced Security Researcher with a strong analytical background to join our team to perform threat hunts, assist with investigations, develop threat intelligence, and to cultivate investigation best practices into Microsoft tooling and products.⯠We partner with data scientists and engineers to ensure the integrity and security ofâ¯the services we operate (Entra & Microsoft Account), as well as the consumer and commercial identities we manage.⯠We are seeking a talented individual to join our world-class team of Security Researchers. Your passion for protecting customers, comfort with ambiguity, and motivation to deliver consistently exceptional performance under high pressure, will be highly valued. Your ability to efficiently sift through PB sized datasets via automation to extract key insights in a timely manner, will be critical in helping us continue to successfully execute against our mission. If you are motivated by the challenge of using your skills & knowledge to help protect Microsoft and the world from cyber threats - come join us!
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
This role is part of a collaborative team, assisting our customers with responding to security incidents (on-call) spanning fraud, abuse and compromise and identity-related operational issues to identify, isolate, remediate, and root causePerforming deep analysis of attacker activity in on-premises and cloud environmentsâ¯Identifying potential threats, allowing for proactive defence before an actual incidentâ¯Building proof-of-concept and prototype threat hunting tools, automations, and new capabilitiesâ¯
Driving product and tooling improvements by conveying learnings from threat hunting and incident response at scale to engineering partner teams.â¯â¯Identifying, prioritizing, and targeting complex security issues that cause negative impact to customers.Creating and driving adoption of relevant mitigations and providing proactive guidanceWorks with others to synthesize research findings into recommendations for mitigation of security issues. Shares across teams. Drives change within team based on research findings.â¯â¯Embody our culture and values
Qualifications
Required/Minimum QualificationsBachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection.1+ years knowledge of security fundamentals across Microsoft platforms (Client, Server, Cloud)â¯2+ years of experience in threat landscape and malware, especially attacks targeting identity.Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter. Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. â¯As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. 1324b(a)(3)) for assessment of eligibility to access the export controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.
Citizenship & Citizenship Verification: This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport.
Preferred Qualifications
Master's Degree in Statistics, Mathematics, Computer Science or related field OR 4+ years experience in software development lifecycle, large-scale computing, modeling, cyber-security, and/or anomaly detection.Understanding of SQL or Kusto Query Language (KQL) queries (or experience with large database/SIEM query languages such as Splunk/Humio/Kibana, etc.)â¯Familiarity and understanding of Jupyter Notebooks, or building equivalent threat hunting automations with scripting languagesâ¯
Perform data analysis using a variety of analytical tools (Python, Synapse, etc), and interpret results with actionable recommendations.Active Directory subject matter expertiseâ¯Experience with sophisticated threat actor evidence including familiarity with typical Indicators ofCompromise (IOCs), Indicators of Activity (IOAs) and Tools, Techniques and Procedures (TTPs)â¯Microsoft Azure and/or Office365 platform knowledge and experienceâ¯Experience with various forensic log artifacts found in SIEM logs, web server logs, AV logs, protection logs such as HIDS and NIDS logsâ¯Familiarity with Microsoft Defender 365 security stack (for Endpoints, Identity, Cloud, etc), especially with Advanced Hunting query writingâ¯Knowledge of third-party cybersecurity solutions, especially EDR and SIEM solutionsâ¯Linux and/or macOS forensic analysis and threat hunting skillsâ¯Technical certifications based on domain (e.g., Azure, SharePoint)â¯Investigation/Cybersecurity/Digital Forensics/DFIR certifications (e.g. CISSP, SANS GIAC, etc)â¯
Security Research IC3 - The typical base pay range for this role across the U.S. is USD $100,600 - $199,000 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $131,400 - $215,400 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications for the role until September 17,2025.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Check out other jobs at Microsoft.