Who we are:
We are the Security, Compliance and Management (S+C+M) team; we are committed to defending Microsoft customers from cyber-attacks as well as providing sophisticated tooling for securing important data. S+C fosters an agile development environment, continuously gathering and analyzing data to combat evolving threats. Our mission is to help protect customers with truly innovative proactive protection, advise customers on emerging trends, and engage in valuable partnerships.
As the Research organization within S+C, it’s our job to stay one step ahead of malicious adversaries and predict the threats of the future. We work with partners across Microsoft to innovate new approaches for detecting and tracking threats, attacker techniques.
We are always learning. Insatiably curious. We lean into uncertainty, take risks, and learn quickly from our mistakes. We stand in awe of what humans dare to achieve and are motivated every day to empower others to do and achieve more through our technology and innovation. Together we make a difference for all of our customers, from end-users to Fortune 50 enterprises.
What we Build:
We build innovative security and data compliance products. Our security products are brought together in the Microsoft 365 Defender (M365D)suite. M365Denables Microsoft’s enterprise customers to detect, investigate,understand,and respond to advanced threats on their networks via a combination of behavioral sensors, cloud security analytics,and threat intelligence.
The Microsoft Threat Experts Team is looking for threat hunters! No matter how sophisticated attacker behaviors become, Microsoft 365 Defender (M365D) will help enterprises detect, investigate, and respond to advanced attacks and data breaches on their networks.Our team uses deep knowledge of the attacker landscape and rich telemetry from our sensors to perform root-cause analysis and generate custom alerts, ensuring that M365D customers are well equipped to quickly respond to human adversaries identified in their unique environments.
Ensuring that no human adversary can operate silently begins with experts harnessing the powerful optics provided by M365D, across the attacker kill-chain, coupled with world-class detections. We’re looking for a skilled hunter to harness the power of Microsoft’s trillions of security signals to quickly identify and report the latest human adversary behaviors, drive critical context-rich alerts, build new tools and automations in support of hunting objectives, and drive innovations for detecting advanced attacker tradecraft.
Job Location : Banagalore , Noida, Hyderabad
Responsibilities
Primary responsibilities would include:
Explore and correlate large data sets to uncover novel attack techniques, monitor and catalog changes in activity group tradecraft, to research and provide new detection mechanisms.
Acquire new and leverage existing knowledge of attacker tools, tactics and procedures to improve security posture of customers.
Self-driven and team cooperated research on novel attack techniques to simulate them in lab on endpoints and cloud infrastructure to identify required detection mechanisms.
Identify need of required tools for research and analysis and effectively engage and collaborate with partners in engineering and data science to develop and maintain them.
Effectively engage and collaborate with partners in data science, threat research to develop and maintain high-fidelity detection rules.
Build hunting tools and automations for use in the discovery of human adversaries.
You would be expected to support a 24/7 operation model that may sometimes involve working in night shifts.
Qualifications
Required experiences.
5+ years of experience in a technical role in the areas of Security Operations, Malware analysis, Threat Intelligence, Cyber Incident Response, or Penetration Testing/Red Team
Comfortable working with extremely large data sets for analysis and visualization, using tools and scripting languages such as: Excel, SQL, Python, Splunk Query Language, Kusto query language and PowerBI
Ability to track, analyze, and brief on new and ongoing cyber-attacks in cloud infrastructure with understanding on AAD, ADFS and popular authentication/authorization protocols like SAML, OAUTH, OpenID connect
In-depth understanding of latest cloud-based techniques used by attackers for persistence, privilege escalation, defense evasion and lateral movement in platforms such as Azure AD, Office 365 and Google Workspace
Functional understanding of common threat analysis models such as the Diamond Model, Cyber Kill Chain, and MITRE ATT&CK.
Advanced experience using analysis tools (e.g. file/network/OS monitoring tools and/or debuggers) and advanced knowledge of operating system internals and security mechanisms
Excellent cross-group and interpersonal skills, with the ability to articulate business need for detection improvements and strong ability to use data to ‘tell a story’.
Following additional experiences are favorable, but not required:
Technical BS degree preferred in Computer Science, Computer Engineering, Information Security, Mathematics, or Physics
Experience with system administration in a large enterprise environment including Windows and Linux servers, along with workstations, network and cloud administration. For example, expertise in EDR (Microsoft Defender for Endpoint), MDO, MDI, MCAS, MTP or M365D
Experience with system administration in a large enterprise environment including Windows and Linux servers and workstations, network administration, cloud administration.
1+ years of experience developing software or tools using C++, C#, Python, Ruby, or similar , kusto
Experience with reverse engineering, digital forensics (DFIR) or incident response, or machine learning models
Experience with offensive security including tools such as Metasploit, exploit development, Open Source Intelligence Gathering (OSINT), and designing ways to breach enterprise networks
Experience with advanced persistent threats and human adversary compromises
Additional advanced technical degrees or cyber security-based certifications such as CISSP, OSCP, CEH, or GIAC certifications
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form (https://careers.microsoft.com/us/en/accommodationrequest) .
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
#EXDIndiajobs
We are seeking a talented individual to join our Operations team at Mercer. This role will be based in Gurugram....
Apply For This JobJob Description As a Textile Merchandiser, the job description would be: Analyzing sales information Sending Inquiries Negotiating with Suppliers Order...
Apply For This Jobbr{display:none;}.css-58vpdc ul > li{margin-left:0;}.css-58vpdc li{padding:0;}]]> Hiring Accounts Executive for US Logistic Company Location – Mohali Qualification- B.Com/M.Com/CA inter Exp- Min...
Apply For This JobJob Number 23009597 Job Category Food and Beverage & Culinary Location The Westin Chennai Velachery, 154 Velachery Main Road, Chennai,...
Apply For This JobJob Description looking for a dynamic female konkani speaking female candidate who can handle the front desk as well as...
Apply For This JobNazwa jednostki organizacyjnej ZUS I Oddział w Łodzi Nazwa komórki organizacyjnej Departament Świadczeń Emerytalno-Rentowych Miejsce pracy ZUS I Oddział w...
Apply For This Job