AMVETS Jobs

Job Information

Microsoft Corporation Security Researcher - Microsoft Defender in Multiple Locations, Israel

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.

Come and be part of a dynamic group, focusing on emerging threats against organizational -enterprise environments. Come and be part of the team building one of Microsoft’s most exciting security products, Microsoft Defender for Endpoint. As cyber-attacks have become more sophisticated and evasive, MDE helps enterprises detect, investigate, and automatically disrupt advanced attacks and data breaches on their networks.  There is a unique opportunity to join a new team focuses on advanced and sophisticated attacks, our research team brings deep knowledge of the attacker landscape and tradecraft to create the innovations necessary to uncover and protect against even the most well-funded adversaries. We are seeking an experienced security researcher who is excited by uncovering unknown attacks to join our Israeli research team and focus on detecting and disrupting sophisticated enterprise attacks. The job includes ideation to customer facing detection, researching novel attack techniques, hunting through our rich sensor data, identifying necessary optics for detecting malicious behaviour and crafting detection and protection logic to ensure compromise does not go undetected.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Conduct in-depth research for detection mechanisms to detect novel and front line offensive tradecraft – from exploits to implants and End-to-end implementation from offensive PoC to wide-scale deployable detection PoC, necessary development on agent and cloud platforms.

  • Keep up to date with latest trends in cyber-attacks and create robust, sophisticated detection logics across the entire kill-chain.

  • Investigate, analyse, and expand MDE security, by exploring real incidents, developing durable protection strategies, and circumventing threats across the entire kill-chain

  • Collaborate with multiple product teams to design sensors, implement protection ideas, and validate their effectiveness using a data-driven approach

  • Collaborate with data science teams to drive ML based protections, understand, and identify detection gaps, capabilities, assumptions, and improvements

  • Be involved in customer conversations to identify opportunities, gaps, and concerns to improve product protection value

Qualifications

Qualifications - Required:

  • BSc+ in Computer Science\Computer Engineering or equivalent engineering degrees

  • 4+ years of software development/research experience

  • In-depth knowledge and experience with the security threat landscape, background in the modern attacker kill-chain and MITRE ATT&CK, preferably in endpoint/network -based threat scenarios.

  • Full stack research capabilities - from technique PoC to detection engineering and implementation within all required organizational process.

  • A drive to tackle hard problems with level of ambiguity.

  • Extensive, practical OS internals knowledge of Windows

  • Knowledge of standard IT network protocols, detection of network attacking phases(Recon\Exploitation\Lateral Movement\Exfiltration).

  • Low level development experience - preferably at windows environment at User&Kernel modes, at C\C++. • Excellent cross-group and interpersonal skills

  • Code fluency in either C#, C, Python or Rust

#MSFTSecurity #MDEIL#MTPR#PORTIL

Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations (https://careers.microsoft.com/v2/global/en/accessibility.html) .

DirectEmployers