Enable job alerts via email!

Threat Researcher

Abnormal AI

United Kingdom

Remote

GBP 60,000 - 85,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading cybersecurity firm is seeking a Threat Researcher specializing in Microsoft cloud security. This fully remote opportunity involves researching and addressing security threats against Microsoft environments and collaborating with engineering teams to strengthen product capabilities. Ideal candidates will have significant experience in threat intelligence and actionable security enhancement.

Qualifications

  • 5+ years in threat research, cyber threat intelligence, or adversary tracking.
  • 3+ years focused on Microsoft cloud security (Azure, M365, Defender).
  • Deep knowledge of MITRE ATT&CK and Microsoft attack techniques.

Responsibilities

  • Conduct in-depth research on Microsoft cloud security threats.
  • Develop threat models and analyze security posture risks.
  • Collaborate with R&D to enhance Microsoft security product capabilities.

Skills

Threat research
Microsoft cloud security
SaaS security
Adversary TTP analysis
SQL
Data analysis

Tools

Microsoft Defender for Office 365
Defender for Identity
Microsoft Sentinel

Job description

Join to apply for the Threat Researcher role at Abnormal AI

Join to apply for the Threat Researcher role at Abnormal AI

Get AI-powered advice on this job and more exclusive features.

Abnormal AI is looking for a Threat Researcher with expertise in Microsoft cloud security, threat research, and SaaS Security Posture Management (SSPM). In this position, you will look into threats against Microsoft cloud services, learn about attacker techniques, and identify security vulnerabilities. You will also work to strengthen our security and find solutions to stop these threats. You will work closely with R&D and Engineering teams to enhance security product capabilities, refine detections, and develop configuration playbooks for Azure, Microsoft 365, Defender Suite, and Entra ID. This is a fully remote position also open to UK and EMEA locations.

Who You Are

  • Experienced in threat research, with a deep comprehension of Microsoft cloud ecosystems, SaaS security, and identity-based threats.
  • Robust knowledge of Microsoft security tools, including Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Sentinel.
  • Proficient in adversary TTP analysis, phishing attack research, misconfiguration risks, and security posture hardening.
  • Data-driven researcher, with experience using SQL, PySpark, KQL, and other query-based tools to analyze large datasets.
  • Skilled at bridging security research with engineering, ensuring insights lead to practical security improvements.
  • Able to successfully work within agile, cross-functional teams to enhance security in Microsoft cloud environments.
  • Proficient communicator, able to deliver detailed research findings to both technical and non-technical stakeholders.

What You Will Do

Threat Research & Adversary Tracking

  • Conduct in-depth research on Microsoft cloud security threats, phishing techniques, and identity-based attack vectors.
  • Track APT groups, financially motivated actors, and cloud-native threat campaigns targeting Azure and Microsoft 365 environments.
  • Analyze MFA bypass techniques, token theft, session hijacking, and adversary tactics used against Microsoft authentication mechanisms.
  • Reverse-engineer phishing kits, hostile systems, and cloud-based attack plans to enhance our security expertise.
  • Develop threat models and in-depth attack reports to inform Microsoft-focused threat intelligence.

SSPM & Security Posture Research

  • Research misconfigurations, security posture risks, and SaaS security gaps in Microsoft Entra ID, Azure AD, and M365 security settings.
  • Develop SSPM research insights and contribute to configuration playbooks to improve Microsoft cloud security posture.
  • Identify misconfiguration-driven threats and work with Engineering to enhance detection and mitigation strategies.
  • Analyze security posture deviations that could expose Microsoft environments to account takeovers, phishing, and privilege escalation attacks.

Security Research & Cross-Functional Collaboration

  • Provide deep-dive research into Microsoft cloud attack methodologies to help enhance security product capabilities.
  • Work with R&D and Engineering teams to ensure research findings translate into practical security enhancements.
  • Deliver technical briefings and intelligence reports on Microsoft threat trends, attacker tactics, and detection opportunities.
  • Partner with internal stakeholders to evaluate emerging threats and recommend security improvements for Microsoft cloud environments.

Must Haves

  • 5+ years in threat research, cyber threat intelligence, or adversary tracking.
  • 3+ years focused on Microsoft cloud security (Azure, M365, Defender, Entra ID, or Sentinel).
  • Expertise in Microsoft cloud security architecture, identity protection, SaaS security, and misconfiguration risks.
  • Deep knowledge of MITRE ATT&CK, Microsoft attack techniques, and adversary tradecraft.
  • Hands-on experience with Microsoft Defender for Office 365, Defender for Identity, and Microsoft Sentinel.

Nice to Have

  • Experience working with or building SSPM solutions for Microsoft cloud security posture management.
  • Security certifications (GCTI, GCFA, CISSP, or Microsoft security-related).
  • Experience in researching cloud system security, conducting attack simulations, and identifying security problems caused by configuration errors.
  • Background in SaaS security posture analysis and cloud security hardening.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Computer and Network Security

Referrals increase your chances of interviewing at Abnormal AI by 2x

Sign in to set job alerts for “Cyber Threat Investigator” roles.

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Research Scientist (Biology) - AI Trainer

DataAnnotation

Leeds

Remote

GBP 80,000 - 100,000

4 days ago
Be an early applicant

Research Scientist (Biology) - AI Trainer

DataAnnotation

Newcastle upon Tyne

Remote

GBP 80,000 - 100,000

4 days ago
Be an early applicant

Biology Research Scientist - AI Trainer

DataAnnotation

Manchester

Remote

GBP 60,000 - 80,000

4 days ago
Be an early applicant

Senior Data Scientist FE fundinfo Remote (United Kingdom)

Financial Express

Remote

GBP 50,000 - 80,000

3 days ago
Be an early applicant

Senior Data Scientist 3-month FTC FE fundinfo Remote (United Kingdom)

Financial Express

Remote

GBP 55,000 - 75,000

3 days ago
Be an early applicant

Research Scientist (Biology) - AI Trainer

DataAnnotation

Sheffield

Remote

GBP 80,000 - 100,000

4 days ago
Be an early applicant

Research Scientist (Physics)

DataAnnotation

Birmingham

Remote

GBP 80,000 - 100,000

2 days ago
Be an early applicant

Clinical Researcher - AI Trainer

DataAnnotation

Cardiff

Remote

GBP 60,000 - 80,000

3 days ago
Be an early applicant

Clinical Researcher - AI Trainer

DataAnnotation

Bristol

Remote

GBP 60,000 - 80,000

4 days ago
Be an early applicant