עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
Overview
Do you want to join the Microsoft GHOST team as a Security Researcher?
Do you have a passion for helping Microsoft’s clients defend themselves against targeted exploitation? Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry and having a direct impact on the security of all Microsoft customers? Do you want to be on the front lines of helping our customers go toe-to-toe against advanced adversaries? Are you interested in a fast-paced job full of new opportunities? If so, you might be a candidate for the Global Hunting, Oversight, and Strategic Triage team (GHOST).
We are looking for an experienced Security Researcher with a strong analytical background to join our team to perform threat hunts, assist with investigations, develop threat intelligence, and to cultivate investigation best practices into Microsoft tooling and products. Researchers will support a global team to identify and catalogue new attacker TTPs, victims, and deliver notifications to protect customers.
As a Security Researcher, you will be responsible for synthesizing analysis on adversary capabilities, techniques, and targeting from multiple data sources into customer-ready content to support incident response investigations and proactive engagements. They will act as a trusted advisor to investigators and customers identifying and communicating threats effectively to drive clarity. You will work closely with other internal stakeholders to ensure quality analysis.
Qualifications
A BS in Computer Science or Engineering or comparable experience in a related discipline with 3+ years of related work experience along with the following:
- 3-5 years of experience producing tactical and strategic finished threat intelligence deliverables for customers including written content and presentations on threat actors, campaigns, and tactics, techniques, and procedures
- Technical aptitude to translate technical analysis into polished deliverables independently.
- Expert at creating and presenting threat intelligence tailored for a variety of audiences including analysts, responders, and senior executives.
- 3+ years of experience supporting analysis and content delivery related to incident response investigations.
- Proven track record of collaborating across teams with threat hunters, analysts, incident responders, and customer representatives
- Experience creating and presenting polished technical deliverables in a fast-paced environment.
- Extensive knowledge of adversary groups, Diamond Model, and MITRE ATT&CK techniques
- Familiarity and understanding of SQL or Kusto Query Language (KQL) queries (or experience with large database/SIEM query languages such as Splunk/Humio/Kibana, etc.)
- Familiarity and understanding of Jupyter Notebooks, or building equivalent threat hunting automations with scripting languages.
Preferred Qualifications
- Expertise in providing dedicated actionable intelligence support to customers.
- Excellent oral and written communication skills (Hebrew & English).
- Proven knowledge of security fundamentals across Microsoft platforms (Client, Server, Cloud)
- Knowledge of forensic and incident response processes and terminology
- Experience investigating APT groups including familiarity with Indicators of Compromise (IOCs), Indicators of Activity (IOAs) and attack Tools, Techniques and Procedures (TTPs)
Responsibilities
This role is part of a collaborative team, assisting our customers with:
- Creating reports and presentations incorporating threat actor detail, threat detection and hunting guidance, and remediation recommendations.
- Providing intelligence-led recommendations to improve cybersecurity posture.
- Translating intelligence requirements into custom intelligence content.
- Identifying potential threats, allowing for proactive defence before an actual incident
- Notifying customers regarding imminent attacker activity
- Providing recommendations to improve customers’ cybersecurity posture going forward and performing threat intelligence knowledge transfer to prepare customers to defend against today’s threat landscape
- Driving product and tooling improvements by conveying learnings from threat hunting and incident response to engineering partner teams
- Identifies, prioritizes, and targets complex security issues that cause negative impact to customers. Creates and drives adoption of relevant mitigations and provide proactive guidance
- Works with others to synthesize research findings into recommendations for mitigation of security issues. Shares across teams. Drives change within team based on research findings.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
משרות נוספות מומלצות עבורך
-
Security Researcher
-
תל אביב - יפו
Gotfriends
-
-
Security Researcher II /Senior Security Researcher - our Defender (Multipl
-
הרצליה
מיקרוסופט ישראל
-
-
Senior/Principal Linux Security Analytics Researcher (Cortex)
-
תל אביב - יפו
Cyber Ark Software Ltd
-
-
Principal/Senior Linux Security Researcher (Cortex)
-
תל אביב - יפו
Cyber Ark Software Ltd
-
-
Researcher
-
פתח תקווה
Cellebrite
-
-
Vulnerability Researcher - Relocation to NYC
-
תל אביב - יפו
Zealot
-