938,563open jobs
57,105companies
155,549added this week
Browse all
Salary
$124k – $214k per year
Location
In office (Cheltenham)
Seniority
Principal

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Jul 20, 2026. Microsoft scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Microsoft is an American multinational technology corporation founded in 1975 by Bill Gates and Paul Allen and headquartered in Redmond, Washington. It built the personal computing era around the Windows operating system and the Office productivity suite, and now generates the largest share of its revenue from Azure cloud infrastructure and commercial subscriptions. The company also owns GitHub, LinkedIn and the Xbox gaming business, and has invested heavily in artificial intelligence through its partnership with OpenAI and the Copilot assistants embedded across its products.
Overview

The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.

Do you have a passion for helping Microsoft’s clients defend themselves against targeted exploitation? Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry and having a direct impact on the security of all Microsoft customers? Do you want to be on the front lines of helping our customers go toe-to-toe against advanced adversaries? Are you interested in a fast-paced job full of new opportunities? If that resonates, consider joining us as a Security Researcher on the Global Hunting, Oversight, and Strategic Triage (GHOST) team! We are looking for an experienced Principal Security Researcher with a Digital Forensics and Incident Response background to join our team to perform threat hunts, assist with investigations, develop threat intelligence, and to cultivate investigation best practices into Microsoft tooling and products. Researchers will support a global team to identify and catalog new attacker TTPs, victims, and deliver customer notifications to protect worldwide enterprise customers and empower customers to protect themselves via constantly improving Microsoft products.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.

Responsibilities

This role is part of a collaborative team, assisting our customers with:

  • Leading technical workstreams during investigations and guiding others to conduct deep analysis of attacker activity in on-premises and cloud environments.

  • Identifying potential threats, allowing for proactive defense before an actual incident

  • Presenting technical findings and recommendations to improve customers’ cybersecurity posture and performing threat intelligence knowledge transfer to prepare customers to defend against today’s threat landscape

  • Defining the requirements for and assisting in the development of production threat hunting tools, automations, and new capabilities.

  • Driving investigation strategy, develop new hunting methodologies, and influence security products and practices across multiple teams

  • Mentoring others, helping the team to upskill in terms of both hard and soft skills.

Qualifications

Required qualifications:

  • Extensive and demonstrated professional experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research.

  • Experience investigating sophisticated cyber threats, including APT or nation-state activity.

  • Extensive experience working with forensically collected data (and tooling), security telemetry, logs and SIEM platforms.

  • Expertise in KQL or equivalent query languages (Splunk, Humio, Kibana, etc.).

  • Experience with EDR and security monitoring technologies such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, or similar platforms.

  • Experience managing or conducting security review of Microsoft Azure tenants, Microsoft 365 and Entra ID.

  • Proven ability to analyze security data to investigate attacker activity, and derive identify indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs.

  • Experience and familiarity with the collection of Digital Forensic data, as well as case management and forensic analysis tooling such as X-Ways Forensics.

  • Excellent written and verbal communication skills in English and ability to work in a global team environment

  • Ability to obtain and maintain a UK Security Clearance.

Preferred qualifications:

  • Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC).

  • Experience across multiple cybersecurity disciplines, including threat hunting, incident response, digital forensics, and threat intelligence.

  • Experience leading technical workstreams in Incident Response scenarios.

  • Extensive knowledge of Microsoft security technologies, including Defender and Sentinel.

  • Extensive knowledge of Microsoft Entra ID.

  • Experience analyzing large-scale security telemetry and hunting across enterprise environments.

  • Understanding of scripting or the ability to read and interpret code and automation workflows.

Security Research IC5 - The typical base pay range for this role across United Kingdom is £ 93,500.00 - £ 161,800.00 per year. Certain roles may be eligible for benefits and other compensation.

Find additional benefits and pay information here:

https://careers.microsoft.com/v2/global/en/corporate-pay/united-kingdom-corporate-pay.html

Security Research IC5 - The typical base pay range for this role across United Kingdom is £ 93,500.00 - £ 161,800.00 per year. Certain roles may be eligible for benefits and other compensation.

Find additional benefits and pay information here:

https://careers.microsoft.com/v2/global/en/corporate-pay/united-kingdom-corporate-pay.html

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
938,563 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Cheltenham
≈ $79k – $227k per year (Estimated) • Hybrid • Full-Time • Reading
Apply
$87k – $115k per year • Remote (Germany, United Kingdom) • 5+ years exp
JavaScript
Node JS
Node JS
Commander.js
Databases
Google BigQuery
BigQuery
DevOps
Splunk
GCP
Heroku
Azure
Cybersecurity
Tines
SIEM
Apply
≈ $83k – $164k per year (Estimated) • In office • PhD • London
DevOps
Terraform
Azure
AWS
Cybersecurity
SIEM
Apply
≈ $79k – $157k per year (Estimated) • Remote (United Kingdom) • Full-Time • 5+ years exp • Maidenhead
DevOps
Incident Management
Management
ITIL
Apply
≈ $79k – $157k per year (Estimated) • Remote (United Kingdom) • Full-Time • 5+ years exp • Maidenhead
DevOps
Incident Management
Linux
Windows
Cybersecurity
Autopsy
Plaso
EnCase
X-Ways Forensics
SIEM
Apply
In office • 3+ years exp • Bachelor's Degree
DevOps
VMWare
Azure
IAM
Windows
VPN
Cybersecurity
ISO 27001
PCI DSS
HIPAA
Zero Trust
Defense in Depth
LDAP
SIEM
Apply
≈ $82k – $170k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Marietta
DevOps
Linux
Cybersecurity
Microsoft Sentinel
Google SecOps
SIEM
Apply
≈ $24k – $55k per year (Estimated) • In office • 13+ years exp • Chennai
Python
PowerShell
Bash
DevOps
Terraform
Puppet
GCP
Azure DevOps
FluxCD
Packer
Prometheus
Azure
CI/CD
GitOps
Windows Server
ArgoCD
Jenkins
Git
AWS
Kubernetes
Grafana
JFrog Artifactory
Windows
DNS
Apply
$72k – $84k per year • Remote (likely Poland) • Full-Time • Gdańsk
JavaScript
TypeScript
SQL
C#
C#
ASP.NET Core
Databases
Redis
Azure SQL Database
AI/ML
Copilot
Frontend
Angular
DevOps
Azure
GitHub
Amazon S3
Management
SharePoint
Apply
≈ $16k – $41k per year (Estimated) • In office • 5+ years exp • Chennai
JavaScript
Java
SQL
Java
Spring Boot
Databases
MySQL
Apache Kafka
Frontend
React.js
Mobile
JUnit
DevOps
Rest API
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Management
Agile
Scrum
QA
Jest
Apply
≈ $95k – $215k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Sydney
DevOps
Incident Management
Cybersecurity
ISO 27001
MITRE ATT&CK
NIST CSF
Management
Agile
Apply
≈ $103k – $274k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Australia
DevOps
Incident Management
Management
Agile
Apply
Security Engineer 5 days ago
$85k – $168k per year • In office • 2+ years exp • Bachelor's Degree • United States
C++
DevOps
Windows
Apply
$143k – $275k per year • In office • 12+ years exp • Bachelor's Degree • Redmond
AI/ML
AI Agents
LLM
Anomaly Detection
DevOps
HPC
Cybersecurity
Microsoft Sentinel
Threat Modeling
Magnet AXIOM
SIEM
Apply
$120k – $235k per year • In office • 8+ years exp • Bachelor's Degree • Redmond
Python
PowerShell
C#
C++
Scala
AI/ML
AI Agents
LLM
DevOps
HPC
TCP/IP
DNS
Cybersecurity
Microsoft Sentinel
Threat Modeling
Magnet AXIOM
SIEM
Apply
≈ $60k – $120k per year (Estimated) • Equity • In office • Full-Time • 1+ year exp • High School Diploma • Cheltenham
Management
Microsoft Office
Apply
In office • Part-Time • Cheltenham
Apply
≈ $35k – $89k per year (Estimated) • Hybrid • Full-Time • Cheltenham
Apply
≈ $38k – $103k per year (Estimated) • Hybrid • Full-Time • Cheltenham
AI/ML
Aider
Apply
≈ $38k – $100k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Cheltenham
Analytics
Power BI
Apply
See all jobs
This is one of many
938,563 more open roles from verified company boards, updated every day.