In this role, youll research and build defenses across AI systems, agentic protocols, Identity platforms, and SaaS applications. One day you might analyze a new class of AI prompt injection attacks or Agents abuse, the next youll be hunting through data or creating novel protection mechanisms for them. Youll work closely with product teams to turn research prototypes into real security features.
Join our threat protection research team and be part of a team who contributes to Microsofts most advanced and innovative security solutions.
Responsibilities
Research and develop detection methods for new and advanced attack techniques - from exploits to implants. Build end-to-end PoCs, from offensive testing to scalable detection, across all our cloud and identity platforms.
Stay up to date on the latest attack trends and build strong detections across the kill chain - covering agentic AI & LLM threats, cloud and identity-based attacks.
Collaborate with multiple product and engineering teams to design the next iteration of security products, implement detection ideas and validate their effectiveness using a data-driven approach.
Collaborate with data science teams to drive ML based protections, understand, and identify detection gaps, capabilities, assumptions, and improvements
Provide cybersecurity expertise as needed during security escalations and incidents to help protect Microsoft and our customers
Requirements: BSc or M.Sc. in Computer Science, Software Engineering, or relevant practical experience (e.g. service in elite technology unit in IDF)
You have at least 6+ years of computer security industry experience with knowledge of adversary tradecraft, security operations, incident response, threat hunting, and of emerging threats and techniques for attacks against modern cloud environments.
3+ years of experience researching, prototyping, and driving engineering requirements for threat protection systems.
Code fluency in either C, Python or Rust
Knowledge of the security threat landscape, with experience in the modern attacker kill chain and MITRE ATT&CK - especially in cloud, application, identity, and AI-related threat scenarios.
Preferred Qualifications
Good hands-on knowledge of AI/LLM fundamentals and concepts, including technical aspects related to usage of AI/LLM in production systems and agentic frameworks
Familiarity with OAuth and other identity protocols, as well as knowledge of the AI domain - especially MCP, A2A, and related technologies.
Industry recognized author of security research papers, blogs, or books
Low-level/security knowledge of other operating systems
Team player open to ideas and enjoys working with others to achieve shared goals.
Experience leading a project from start to finish - including idea, design, coding, testing, and ongoing maintenance.
Familiarity with cloud environments, and hybrid cloud enterprise services
A drive to tackle hard problems with level of ambiguity.
.המשרה מיועדת לנשים ולגברים כאחד