Expoint – all jobs in one place
The point where experts and best companies meet
Limitless High-tech career opportunities - Expoint

Microsoft Principal Security Researcher 
Taiwan, Taoyuan City 
579163492

Today

Required Qualifications:

  • 7+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
    • OR Doctorate in Statistics, Mathematics, Computer Science or related field
  • 5 + years threat intelligence experience tracking threat actors and their infrastructure
  • Deep knowledge of network protocols and internet scanning at scale
  • Experience developing signatures in internet scanning service data (Censys, Shodan, etc) to detect threat actor command and control infrastructure
  • Experience working with engineering teams to develop probes for internet wide scanning capabilities

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

  • This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications:

  • 8+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
    • OR Doctorate in Statistics, Mathematics, Computer Science or related field.
  • Experience developing scripts and tools to enable analysis to query large data sets using python or other scripting languages

  • Ability to conduct malware analysis and analyze network traffic associated with advanced attack campaigns

  • Experience querying large data sets via Kusto Query Language (KQL), python, or other similar query languages

Microsoft will accept applications for the role until July 16, 2025.

Responsibilities
  • Leverage their experience and understanding of tracking threat actors to expand network infrastructure fingerprint signature development to broaden the impact of MSTICs infrastructure detection capability and collaborate with team members to identify opportunities to fingerprint existing and emerging actor infrastructure for improved tracking of threat actors.
  • Partner with Microsoft engineering teams to improve our internet wide scanning through the development of new probes and custom scanning capabilities that can drive additional threat actor insights and infrastructure detection
  • Effectively combine network intelligence with additional data sets to surface new nation state and ransomware campaigns and expand MSTICs visibility into attacks targeting Microsoft and its customers
  • Utilize network-based command and control insights to identify 1st party protection opportunities and partner across the CISO organization to enhance Microsoft’s defenses.
  • Embody our