Microsoft

Security Researcher- Cybersecurity Threat Hunter

Microsoft Dubai, Dubai, United Arab Emirates

Software Development · 10,001+ employees

4 d ago
security Senior (5-10 yrs) Full-time United Arab Emirates
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Lead hypothesis-driven threat hunts across complex customer environments to identify and mitigate adversary activity. Convert research findings into durable security detections, architectural improvements, and clear response actions for stakeholders.

What they look for

Threat hunting Cybersecurity Incident response Kusto Query Language Forensics Cloud security Active Directory Entra ID Telemetry analysis Adversary tactics Scripting Automation Network security Endpoint security Risk assessment Technical leadership

Requirements

Requires a Doctorate or Master's degree in a technical field or equivalent experience in cybersecurity and threat analysis. Candidates must possess strong skills in threat hunting, forensic analysis, and querying large-scale security telemetry.

Benefits

Health insurance Professional development Inclusive culture Global collaboration

Full description

Overview With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft’s products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers’ expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft’s portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.

Microsoft’s Detection and Response Team (DART) is seeking a skilled and experienced Cybersecurity Threat Hunter to join the team. DART is the first port of call for many customers during a security incident. This pivotal, customer-facing position calls for a technically deep and agile threat hunter who is adept at pursuing adversaries that have evaded existing detection, across on-premises and cloud estates, and at converting a hypothesis into evidence customers can act on under extreme time pressure.

This position is tailored for an individual who not only excels in cybersecurity technical acumen but also demonstrates robust capabilities in engaging with customers and adjusting to the evolving demands of incident response operations. The successful candidate will be part of a globally distributed, mission-driven team responding to complex and high-impact cybersecurity incidents, working alongside investigation leads, reverse engineers, infrastructure engineers and incident coordinators, and helping shape the future of Defender Experts Cybersecurity Incident Response.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • As a Senior Cybersecurity Threat Hunter, you will independently lead hypothesis-driven hunts, reactively and proactively, across customer environments, identify adversary activity, and turn findings into clear response actions and durable security improvements.
  • Develop, test and refine hunt hypotheses using threat intelligence, adversary tactics, techniques and procedures, and large-scale correlation of endpoint, cloud, identity and network telemetry.
  • Operate as a platform- and vendor-agnostic threat hunter across Windows, Linux, macOS, multi-cloud, and third-party technologies, using telemetry, forensic artefacts and security tooling required by each customer environment.
  • Determine adversary presence, scope compromise, identify visibility gaps, and escalate confirmed findings.
  • Author and optimise queries, automation and responsible AI-enabled workflows to improve hunt scale, analytical quality and time to detection.
  • Convert investigations and research into durable detections, analytics, mitigations and product or architectural improvements.
  • Lead multiple hunt workstreams during high-impact incidents, coordinate priorities and dependencies, maintain evidentiary documentation, and support post-incident and root-cause analysis.
  • Communicate findings, coverage and residual uncertainty clearly to customer technical and non-technical teams, executives, internal and other stakeholders.
  • Provide technical guidance, share research and mentor junior threat hunters while protecting DART information, tools and operational security.
  • Participate in scheduled on-call and follow-the-sun coverage, including weekends and holidays, and complete readiness, compliance, labour, expense and travel obligations accurately and on time.
  • Model Microsoft culture and values and engage customers and partners to improve security outcomes and adoption of protective controls.

Qualifications Required Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master’s Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND experience in software development lifecycle, large-scale computing, threat analysis or modelling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Experience in threat hunting, windows forensics, or investigating identity-based attacks across Active Directory, Entra ID or other enterprise identity platforms.
  • Experience authoring queries against large-scale security telemetry, including scripting or automation.
  • Ability to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.

Preferred Qualifications:

  • Proven hypothesis-led threat hunting at enterprise scale, correlating endpoint, cloud, identity and network telemetry to identify adversary activity and visibility gaps.
  • Advanced Kusto Query Language (KQL) skills, with ability to transform data at scale.
  • Strong forensic capability across Windows, Linux and macOS, including analysis of endpoint artefacts and memory where required.
  • Platform- and vendor-agnostic security experience across Microsoft, AWS, GCP and third-party SIEM, EDR, identity, network and email technologies.
  • Experience leading hunt workstreams in high-pressure, customer-facing incident response while balancing the need for rapid recovery.
  • Ability to communicate evidence, coverage and residual uncertainty clearly to technical teams, executives and partners.
  • Experience converting hunt outcomes into durable detections, analytics, mitigations and threat intelligence.
  • Demonstrated technical leadership through research, stakeholder influence, process improvement and mentoring.
  • Relevant security certifications or equivalent practical expertise; resilience and flexibility to support follow-the-sun incident response.

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Similar roles