Principal Security Research - Microsoft Defender ( Identity Threat Detection and Response)
Responsibilities
Set the technical direction for a major area of our identity protection research charter, owning the multi-quarter strategy from threat landscape framing to shipped detection and measurable customer protection impact.
Drive multiple concurrent end-to-end research initiatives, breaking ambiguous problems into tractable workstreams and unblocking the team on the hardest technical questions.
Lead deep investigation and research of data across identity and adjacent sources to surface novel threats, attacker tradecraft, and detection opportunities others miss.
Stay ahead of the evolving attacker landscape and design robust, sophisticated detection logics across the entire kill-chain — raising the bar on quality, coverage, and resilience to attacker evasion.
Influence across organizational boundaries — partner with product management, engineering, data science, and peer research teams to shape product strategy, define new identity protection capabilities, and align roadmaps on a data-driven foundation.
Mentor and grow other researchers (IC3–IC4), elevating the technical bar of the team through code/design review, research coaching, and apprenticeship on complex investigations.
Shape how the team and discipline leverage Generative AI — define patterns, evaluate tools, and build durable AI-assisted workflows that scale research throughput across data triage, hypothesis generation, code and KQL authoring, and detection synthesis.
Represent Microsoft Security externally through high-quality research publications, conference talks, blog posts, and engagement with the broader security research community.
Qualifications
You have at least 10 years of experience in security research.
Proficiency in developing with either C++, C#, Java or Python.
You have experience leading a feature from design through to production delivery (design, coding, testing, deployment).
Strong cross-group collaboration and interpersonal skills.
8+ years of experience in cybersecurity research, with a strong background in the modern attacker kill chain and MITRE ATT&CK, and deep expertise in identity-based threats and identity protection, ideally in the context of enterprise security or Identity Threat Detection and Response (ITDR).
Preferred Qualifications
- B.Sc. or M.Sc. in Computer Science, Software Engineering, or equivalent practical experience (e.g., service in an elite technology unit in the IDF).
- Demonstrated track record of leading multi-quarter research initiatives end-to-end from problem framing through execution to shipped outcomes and measurable customer impact, across organizational boundaries.
- Demonstrated technical leadership and influence beyond your immediate team, including cross-org partnerships, setting technical standards, mentoring senior peers, driving consensus on ambiguous technical decisions, and influencing without authority.
- Deep technical expertise in OS internals and forensics, including key forensic artifacts related to lateral movement and credential theft, as well as strong knowledge of identity protocols (e.g., Kerberos, NTLM, LDAP, OAuth 2.0, OpenID Connect, SAML) and modern cloud identity architectures such as Entra ID.
- Experience with cloud forensics and hybrid environments, including identity attack artifacts and lateral movement techniques across on-premises and cloud environments.
- Demonstrated fluency with Generative AI tools and AI-assisted workflows, including prompt design, model output validation, and building reusable AI-assisted patterns for security research, detection engineering, or threat intelligence at scale.
- Established external thought leadership in the security research community, demonstrated through research papers, conference talks, high-impact blogs, CVEs, or open-source contributions.
- Prior experience operating at Principal (IC5) or equivalent level, with a drive to tackle the hardest and most ambiguous problems in the identity threat landscape.
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:
- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
#MSFTSecurity #ITDR #IdentityProtection #SecurityCopilot #GenAI #PrincipalEngineer
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- At least 10 years of experience in security research
- 8+ years of experience in cybersecurity research
- Proficiency developing with C++, C#, Java, or Python
- Experience leading a feature from design through production delivery, including coding, testing, and deployment
- Strong cross-group collaboration and interpersonal skills
- Background in the modern attacker kill chain, MITRE ATT&CK, identity-based threats, and identity protection
- Bachelor’s or master’s degree in Computer Science, Software Engineering, or equivalent practical experience
- Experience leading multi-quarter research initiatives from problem framing through shipped outcomes and measurable customer impact
- Technical leadership and influence across organizational boundaries, including mentoring and setting technical standards
- Deep expertise in OS internals, forensics, lateral movement, credential theft, identity protocols, and cloud identity architectures
- Experience with cloud forensics and hybrid on-premises and cloud environments
- Fluency with generative AI tools and AI-assisted workflows for security research or detection engineering
- External security research thought leadership through papers, talks, blogs, CVEs, or open-source contributions
- Prior Principal-level or equivalent experience
- Ability to pass Microsoft background and Microsoft Cloud background checks
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.







