Jobs · Washington

Senior Applied Threat Intelligence Analysts

Microsoft · Redmond, WA · 3 wk ago
Hybrid$102k–$202k/yrFull-time

Responsibilities

  • Lead with AI to understand the threat landscape and the latest attacker tradecraft.
  • Track threat actors, including financially motivated threat actors; their infrastructure, their targets, and their shifting techniques, tactics, and procedures.
  • Translate complex technical findings into clear, prescriptive guidance for security operations teams, executives, and the broader defender community.
  • Partner with product, research, marketing, and communications teams to ensure high-quality intelligence experiences through Microsoft's customer-facing surfaces and managed services (Agentic Security, Defender XDR, Defender Experts, Sentinel, blogs, briefings).
  • Build and refine the pipelines, tooling, and workflows that allow Microsoft to stream insightful cyber threat intelligence to customers machine speed.
  • Represent Microsoft Threat Intelligence in customer briefings, industry conferences, and cross-industry working groups.

Qualifications

  • Minimum Qualifications: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
  • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
  • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
  • OR equivalent experience.
  • Other Requirements: Ability to meet Microsoft, customer and/or government security screening requirements are required for this role.
  • Preferred Qualifications: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
  • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
  • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
  • OR equivalent experience.
  • 3+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline.
  • Attribution experience creating threat groups, assessing connections between established threat groups, and communicating attribution assessments to internal stakeholders and customers in a timely manner.
  • Demonstrated experience producing finished threat intelligence reporting for technical and/or executive audiences.
  • Working experience with Microsoft Sentinel and Microsoft Defender XDR (or directly comparable SIEM/XDR platforms).
  • Understanding of adversary tradecraft, the cyber kill chain, and frameworks such as MITRE ATT&CK, the Diamond Model, and structured analytic techniques.
  • Written and verbal communication skills, with a portfolio of public or customer-facing intelligence writing.
  • Experience tracking and defending against financially motivated threat actors.
  • Experience with endpoint, cloud, network, and identity-based attacks and datasets.
  • Experience with AI tools and large language models, building agents and skills for information security applications and pipelines.
  • Comprehensive OS security/internals knowledge.
  • Understanding of network protocols and analytical experience with network infrastructure data & telemetry.
  • Reverse-engineering with static and behavioral binary analysis experience.
  • Functional understanding of common threat analysis models such as the Diamond Model, Cyber Kill Chain, and MITRE ATT&CK.
  • Programming or scripting background (Python, PowerShell, C#, C++, etc.).

Similar jobs