Senior Applied Threat Intelligence Analysts
Microsoft · Redmond, WA · 3 wk ago
Hybrid$102k–$202k/yrFull-time
Responsibilities
- Lead with AI to understand the threat landscape and the latest attacker tradecraft.
- Track threat actors, including financially motivated threat actors; their infrastructure, their targets, and their shifting techniques, tactics, and procedures.
- Translate complex technical findings into clear, prescriptive guidance for security operations teams, executives, and the broader defender community.
- Partner with product, research, marketing, and communications teams to ensure high-quality intelligence experiences through Microsoft's customer-facing surfaces and managed services (Agentic Security, Defender XDR, Defender Experts, Sentinel, blogs, briefings).
- Build and refine the pipelines, tooling, and workflows that allow Microsoft to stream insightful cyber threat intelligence to customers machine speed.
- Represent Microsoft Threat Intelligence in customer briefings, industry conferences, and cross-industry working groups.
Qualifications
- Minimum Qualifications: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR equivalent experience.
- Other Requirements: Ability to meet Microsoft, customer and/or government security screening requirements are required for this role.
- Preferred Qualifications: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR equivalent experience.
- 3+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline.
- Attribution experience creating threat groups, assessing connections between established threat groups, and communicating attribution assessments to internal stakeholders and customers in a timely manner.
- Demonstrated experience producing finished threat intelligence reporting for technical and/or executive audiences.
- Working experience with Microsoft Sentinel and Microsoft Defender XDR (or directly comparable SIEM/XDR platforms).
- Understanding of adversary tradecraft, the cyber kill chain, and frameworks such as MITRE ATT&CK, the Diamond Model, and structured analytic techniques.
- Written and verbal communication skills, with a portfolio of public or customer-facing intelligence writing.
- Experience tracking and defending against financially motivated threat actors.
- Experience with endpoint, cloud, network, and identity-based attacks and datasets.
- Experience with AI tools and large language models, building agents and skills for information security applications and pipelines.
- Comprehensive OS security/internals knowledge.
- Understanding of network protocols and analytical experience with network infrastructure data & telemetry.
- Reverse-engineering with static and behavioral binary analysis experience.
- Functional understanding of common threat analysis models such as the Diamond Model, Cyber Kill Chain, and MITRE ATT&CK.
- Programming or scripting background (Python, PowerShell, C#, C++, etc.).