Connecting people I'd hire with companies I'd work at

Matt Wallaert
35
companies
9,700
Jobs

Senior Security Researcher - Microsoft Defender for Endpoint

Microsoft

Microsoft

Posted on Apr 22, 2025

Senior Security Researcher - Microsoft Defender for Endpoint

Multiple Locations, Israel

Save

Share job

Date posted
Apr 21, 2025
Job number
1817338
Work site
Up to 50% work from home
Travel
0-25 %
Role type
Individual Contributor
Profession
Security Engineering
Discipline
Security Research
Employment type
Full-Time

Overview

Come and be part of a dynamic group, focusing on emerging threats against organizational -enterprise environments.

Come and be part of the team building one of Microsoft’s most exciting security products, Microsoft Defender for Endpoint. As cyber-attacks have become more sophisticated and evasive, MDE helps enterprises detect, investigate, and automatically disrupt advanced attacks and data breaches on their networks.

There is a unique opportunity to join a new team focuses on advanced and sophisticated attacks, our research team brings deep knowledge of the attacker landscape and tradecraft to create the innovations necessary to uncover and protect against even the most well-funded adversaries.

We are seeking an experienced security researcher who is excited by uncovering unknown attacks to join our Israeli research team and focus on detecting and disrupting sophisticated enterprise attacks.

The job includes ideation to customer facing detection, researching novel attack techniques, hunting through our rich sensor data, identifying necessary optics for detecting malicious behaviour and crafting detection and protection logic to ensure compromise does not go undetected.

Qualifications

Required qualifications:

  • BS+ in Computer Science\Computer Engineering or equivalent engineering degrees
  • 6+ years of software development/research experience
  • In-depth knowledge and experience with the security threat landscape, background in the modern attacker kill-chain and MITRE ATT&CK, preferably in endpoint/network -based threat scenarios.
  • Full stack research capabilities - from technique PoC to detection engineering and implementation within all required organizational process.
  • A drive to tackle hard problems with level of ambiguity.
  • Extensive, practical OS internals knowledge of Windows
  • Low level development experience - preferably at windows environment at User&Kernel modes, at C\C++.
  • For network role - Good knowledge of network protocols and services and network security practices.
  • Excellent cross-group and interpersonal skills
  • Code fluency in either C#, C, Python or Rust

Preferred qualifications:

  • Offensive security research experience
  • Digital forensics, Incident response and threat hunting skills
  • Reverse Engineering skills: familiar with debuggers, disassemblers, protocols, file formats
  • Industry recognized author of security research papers, blogs, or books
  • Low-level/security knowledge of other operating systems
  • Familiarity with cloud environments, and hybrid cloud enterprise services
  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

#MSFTSecurity #MDEIL#MTPR

Responsibilities

Primary responsibilities would include:

  • Conduct in-depth research for detection mechanisms to detect novel and front line offensive tradecraft – from exploits to implants and End-to-end implementation from offensive PoC to wide-scale deployable detection PoC, necessary development on agent and cloud platforms.
  • Keep up to date with latest trends in cyber-attacks and create robust, sophisticated detection logics across the entire kill-chain.
  • Investigate, analyse, and expand MDE security, by exploring real incidents, developing durable protection strategies, and circumventing threats across the entire kill-chain
  • Collaborate with multiple product teams to design sensors, implement protection ideas, and validate their effectiveness using a data-driven approach
  • Collaborate with data science teams to drive ML based protections, understand, and identify detection gaps, capabilities, assumptions, and improvements
  • Be involved in customer conversations to identify opportunities, gaps, and concerns to improve product protection value

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.