Senior Security Researcher - Microsoft Defender For Endpoint
Multiple Locations | Security Engineering | May 27, 2024 | Job number 1720323

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. 

Come and be part of the team building one of Microsoft’s most exciting security products, Microsoft Defender for Endpoint (MDE). As cyber-attacks have become more sophisticated, MDE helps enterprises detect, investigate, and automatically disrupt advanced attacks and data breaches on their networks. From detecting and disrupting nation state actors to huge ransomware actors in action, our research team brings deep knowledge of the attacker landscape and tradecraft to create the innovations necessary to uncover and protect against even the most well-funded attacker.  
We are seeking an experienced security researcher who is excited by finding new attacks to join our Israeli research team and focus on detecting and disrupting sophisticated enterprise attacks. The job includes researching novel attack techniques, big data analysis of our rich sensor data, identifying necessary optics for detecting malicious behaviour and crafting detection and protection logic to ensure compromise does not go undetected. 

Our team focuses on diversity of all types in candidates, and we strive to hire people with different experiences and perspectives into our team. To that end, we know that no candidate has every desired skill and experience, but together we make a strong, effective team.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.


  • Conduct in-depth investigation and research of data across multiple endpoints and additional sources, to identify threats and sophisticated attack incidents. 
  • Keep up-to-date with latest trends in cyber attacks and create robust, sophisticated detection logics across the entire kill-chain. 
  • Collaborate with product management, security and engineering teams across the company to design innovative solutions and new disruption capabilities, and validate their effectiveness using a data-driven approach. 
  • Collaborate with data science teams to understand, identify and implement detection gaps, capabilities, assumptions, and improvements 
  • Demonstrate thought leadership, be able to engage and enlighten others through compelling meaningful content and informative sessions. 


  • B.Sc./M.Sc. degree in Computer Science or related technical discipline.  
  • 7+ years of experience in cyber security with a background in the modern attacker kill-chain and MITRE ATT&CK, preferably in endpoint-based threat scenarios. 
  • Windows internals knowledge.  
  • Proficient in at least one programming language such as C# (preferred), Python, or C++.   
  • Proficient in at least one query language such as KQL, SQL, Cypher. 
  • Excellent cross-group, leadership and interpersonal skills. 
  • A drive to tackle hard problems with notable level of ambiguity. 


#MSFTSecurity #MDE #Research




Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.  We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.


Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.