Senior Security Researcher - Microsoft Defender for Endpoint
Microsoft Corporation
Come and be part of a dynamic group, focusing on emerging threats against organizational -enterprise environments.
Come and be part of the team building one of Microsoft’s most exciting security products, Microsoft Defender for Endpoint (https://www.microsoft.com/en-us/microsoft-365/security/endpoint-defender?ocid=tia-260153000) . As cyber-attacks have become more sophisticated and evasive, MDE helps enterprises detect, investigate, and automatically disrupt advanced attacks and data breaches on their networks.
There is a unique opportunity to join a new team focuses on advanced and sophisticated attacks, our research team brings deep knowledge of the attacker landscape and tradecraft to create the innovations necessary to uncover and protect against even the most well-funded adversaries.
We are seeking an experienced security researcher who is excited by uncovering unknown attacks to join our Israeli research team and focus on detecting and disrupting sophisticated enterprise attacks.
The job includes ideation to customer facing detection, researching novel attack techniques, hunting through our rich sensor data, identifying necessary optics for detecting malicious behaviour and crafting detection and protection logic to ensure compromise does not go undetected.
**Responsibilities**
Primary responsibilities would include:
+ Conduct in-depth research for detection mechanisms to detect novel and front line offensive tradecraft – from exploits to implants and End-to-end implementation from offensive PoC to wide-scale deployable detection PoC, necessary development on agent and cloud platforms.
+ Keep up to date with latest trends in cyber-attacks and create robust, sophisticated detection logics across the entire kill-chain.
+ Investigate, analyse, and expandMDEsecurity, by exploringreal incidents, developing durable protection strategies, and circumventing threats across the entire kill-chain
+ Collaborate with multiple product teams to design sensors, implement protection ideas, and validate their effectiveness using a data-driven approach
+ Collaborate with data science teams to drive ML based protections,understand, and identify detection gaps, capabilities, assumptions,and improvements
+ Be involved in customer conversations toidentify opportunities, gaps, and concernsto improve product protection value
**Qualifications**
Required qualifications:
+ BS+ in Computer Science\Computer Engineering or equivalent engineering degrees
+ 6+ years of software development/research experience
+ In-depth knowledge and experience with the security threat landscape, background in the modern attacker kill-chain and MITRE ATT&CK, preferably in endpoint/network -based threat scenarios.
+ Full stack research capabilities - from technique PoC to detection engineering and implementation within all required organizational process.
+ A drive to tackle hard problems with level of ambiguity.
+ Extensive, practical OS internals knowledge of Windows
+ Low level development experience - preferably at windows environment at User&Kernel modes, at C\C++.
+ For network role - Good knowledge of network protocols and services and network security practices.
+ Excellent cross-group and interpersonal skills
+ Code fluency in eitherC#, C, Python or Rust
Preferred qualifications:
+ Offensive security research experience
+ Digital forensics, Incident responseand threat hunting skills
+ Reverse Engineering skills: familiar with debuggers, disassemblers, protocols, file formats
+ Industry recognized author of security research papers, blogs, or books
+ Low-level/security knowledge of other operating systems
+ Familiarity with cloud environments, and hybrid cloudenterprise services
+ This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
\#MSFTSecurity #MDEIL#MTPR
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations (https://careers.microsoft.com/v2/global/en/accessibility.html) .
Confirm your E-mail: Send Email
All Jobs from Microsoft Corporation