Security Research IC5

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Data Science · Software Engineering

In short

We are seeking an experienced Principal Security Researcher with a Digital Forensics and Incident Response background to join our Global Hunting, Oversight, and Strategic Triage (GHOST) team. You will perform threat hunts, assist with investigations, develop threat intelligence, and contribute to security tooling and products. This role supports a global team in identifying attacker TTPs and protecting worldwide enterprise customers.

Responsibilities

  • Lead technical workstreams during investigations and guide others in deep analysis of attacker activity in on-premises and cloud environments.
  • Identify potential threats for proactive defense before an incident occurs.
  • Present technical findings and recommendations to improve customers' cybersecurity posture and conduct threat intelligence knowledge transfer.
  • Define requirements for and assist in the development of production threat hunting tools, automations, and new capabilities.
  • Drive investigation strategy, develop new hunting methodologies, and influence security products and practices.
  • Mentor others and help the team upskill in both hard and soft skills.

Requirements

  • Extensive and demonstrated professional experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research.
  • Experience investigating sophisticated cyber threats, including APT or nation-state activity.
  • Extensive experience working with forensically collected data (and tooling), security telemetry, logs and SIEM platforms.
  • Expertise in KQL or equivalent query languages (Splunk, Humio, Kibana, etc.).
  • Experience with EDR and security monitoring technologies such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, or similar platforms.
  • Experience managing or conducting security review of Microsoft Azure tenants, Microsoft 365 and Entra ID.
  • Proven ability to analyze security data to investigate attacker activity, and derive indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs.
  • Experience and familiarity with the collection of Digital Forensic data, as well as case management and forensic analysis tooling such as X-Ways Forensics.
  • Excellent written and verbal communication skills in English and ability to work in a global team environment.
  • Ability to obtain and maintain a UK Security Clearance.

Desired Qualifications

  • Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC).
  • Experience across multiple cybersecurity disciplines, including threat hunting, incident response, digital forensics, and threat intelligence.
  • Experience leading technical workstreams in Incident Response scenarios.
  • Extensive knowledge of Microsoft security technologies, including Defender and Sentinel.
  • Extensive knowledge of Microsoft Entra ID.
  • Experience analyzing large-scale security telemetry and hunting across enterprise environments.
  • Understanding of scripting or the ability to read and interpret code and automation workflows.

Benefits

  • Certain roles may be eligible for benefits and other compensation.
  • Find additional benefits and pay information here: https://careers.microsoft.com/v2/global/en/corporate-pay/united-kingdom-corporate-pay.html

Skills

KQLSplunkHumioKibanaMicrosoft DefenderMicrosoft SentinelCrowdStrikeAzureMicrosoft 365Entra IDX-Ways Forensics
#security#cloud#ai#threat hunting#incident response#threat intelligence#dfir#azure#microsoft 365
Microsoft Logo

About Microsoft

Empowering every person and organization on the planet to achieve more

Every company has a mission. What's ours? To empower every person and every organization to achieve more. We believe technology can and should be a force for good and that meaningful innovation contributes to a brighter world in the future and today. Our culture doesn’t just encourage curiosity; it embraces it. Each day we make progress together by showing up as our authentic selves. We show up with a learn-it-all mentality. We show up cheering on others, knowing their success doesn't diminish our own. We show up every day open to learning our own biases, changing our behavior, and inviting…

Microsoft Logo

Company

Microsoft

Job Posted

20 hours ago

Employment Type

Full Time

Work mode

Hybrid

Salary

£93,500 – £161,800 / year

Experience Level

Senior

Locations

United Kingdom

Applicants

Be an early applicant