1

Microsoft Security Analyst Jobs (NOW HIRING)

Microsoft Defender * SIEM Platforms * Endpoint Detection and Response (EDR) Platforms * Security ... Strong analytical and problem-solving skills * Excellent written and verbal communication skills

Microsoft Defender * SIEM Platforms * Endpoint Detection and Response (EDR) Platforms * Security ... Strong analytical and problem-solving skills * Excellent written and verbal communication skills

Responsibilities : • Conduct daily security operations and monitoring using Microsoft Defender ... analysis, and remediation. • Manage device onboarding/offboarding and enforce endpoint security ...

Microsoft Defender * SIEM Platforms * Endpoint Detection and Response (EDR) Platforms * Security ... Strong analytical and problem-solving skills * Excellent written and verbal communication skills

Security Analyst

Chantilly, VA · On-site

$85K - $100K/yr

Our security analysts will provide a thorough review of security clearance paperwork and personnel ... Knowledge and ability to use computer operating systems/tools such as Microsoft Office Suite

Security Analyst

Chantilly, VA · On-site

$85K - $100K/yr

Our security analysts will provide a thorough review of security clearance paperwork and personnel ... Knowledge and ability to use computer operating systems/tools such as Microsoft Office Suite

Showing results 21-40

Microsoft Security Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do microsoft security analyst jobs pay per year?

As of Aug 20, 2026, the average yearly pay for microsoft security analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a Microsoft Security Analyst?

A Microsoft Security Analyst is responsible for protecting an organization's IT infrastructure by identifying, assessing, and mitigating security threats. They monitor security incidents, analyze vulnerabilities, and implement security solutions using Microsoft tools like Microsoft Defender, Sentinel, and Azure Security Center. Their role involves investigating potential threats, ensuring compliance with security policies, and continuously improving security measures to safeguard data and systems.

What does a Microsoft Security Analyst do?

A Microsoft Security Analyst typically monitors and analyzes security alerts, investigates potential threats, and responds to incidents within Microsoft environments such as Azure and Office 365. They regularly review security policies, update configurations, and perform risk assessments to ensure compliance with organizational and industry standards. Collaboration is frequently required with IT teams, management, and other security professionals to develop and enforce security best practices. Overall, this role demands a proactive approach to threat detection, threat mitigation, and ongoing security improvement.

What are the key skills and qualifications needed to thrive as a Microsoft Security Analyst?

To thrive as a Microsoft Security Analyst, you need strong analytical skills, experience with cybersecurity frameworks, and a sound understanding of Microsoft security technologies, often supported by a degree in computer science or a related field. Familiarity with tools such as Microsoft Defender, Azure Security Center, and certifications like Microsoft Certified: Security, Compliance, and Identity Fundamentals are highly valued. Attention to detail, problem-solving abilities, and effective communication are key soft skills for success in this position. These competencies are vital for identifying threats, implementing security measures, and working collaboratively to maintain secure Microsoft environments.

More about Microsoft Security Analyst jobs

What cities are hiring for Microsoft Security Analyst jobs?

Cities with the most Microsoft Security Analyst job openings:

What states have the most Microsoft Security Analyst jobs?

States with the most job openings for Microsoft Security Analyst jobs include:

Infographic showing various Microsoft Security Analyst job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Principal Security Research Manager, Applied Threat Intel & Threat Response - Microsoft Security

Microsoft

Redmond, WA • On-site

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Microsoft rating

8.5

Company rating: 8.5 out of 10

Based on 132 frontline employees who took The Breakroom Quiz

78th of 245 rated software companies


Job description

Overview
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' heterogeneous environments, as well as ensuring the security of our own internal estate.
Microsoft Security Research is at the front line of defending Microsoft customers and the broader ecosystem against the world's most sophisticated threat actors. Our Applied Threat Intelligence and Threat Response team serves two complementary missions: producing finished, customer-ready threat intelligence that empowers defenders and shapes the public narrative on the threat landscape - and responding with speed and precision when adversaries act against Microsoft customers and infrastructure in this new AI era.
We are looking for a Principal Security Research Manager to lead this blended team. Your threat intelligence analysts are writers and producers: they author actor profiles, campaign analyses, TTP deep-dives, and vulnerability profiles that ship through Microsoft's customer-facing surfaces and brief C-suite audiences. Your threat response practitioners are operators: they maintain on-call readiness, lead active incident investigations, and close the loop from response findings back into finished intelligence. You own both missions, the talent that executes them, and the standards that make the work credible and impactful.
Responsibilities
People Leadership
  • Recruit, develop, and retain a high-performing blended team spanning two distinct but complementary disciplines: finished intelligence production and threat response operations.
  • Set clear goals for each function, connect individual work to team and business objectives, and adapt priorities as the threat landscape and organizational needs evolve.
  • Foster a culture of analytic rigor, operational excellence, and continuous learning - modeling Microsoft values and driving team culture improvements daily.
  • Mentor analysts and responders on tradecraft, career development, and the standards that define great intelligence and response work.

Finished Intelligence Production
  • Own the team's customer-ready intelligence output - actor profiles, campaign analyses, TTP deep-dives, vulnerability profiles, and trend reports - with accountability for quality, cadence, and real-world impact.
  • Establish and maintain analytic standards, tradecraft guidance, and peer review practices that ensure your team's finished intelligence is credible, prescriptive, and audience-appropriate from SOC analyst to C-suite.
  • Partner with product, research, marketing, and communications teams to land intelligence through Microsoft's customer-facing surfaces (Defender XDR, Sentinel, Agentic Security, blogs, executive briefings).

Threat Response Operations
  • Ensure threat response practitioners are trained, calibrated, and ready for on-call rotation and rapid-response engagements.
  • Hold the team accountable for quality monitoring, root cause analysis, and post-incident process improvements.
  • Drive the closed loop between response and intelligence: response findings feed directly into finished intelligence products and detection improvements, making the next response faster and the next report sharper.

Strategy & Cross-Organizational Influence
  • Develop trusted relationships across the intelligence community, including industry partners, external organizations, and agencies engaged in tracking criminal threat actors.
  • Define the vision, strategy, and priorities for the team to deliver high-quality intelligence and threat response that drives customer protection and business impact.
  • Build and operationalize a hybrid human + agentic intelligence team, applying AI technologies, automation, and workflow innovation to improve scale, speed, and insight generation.

Qualifications
Minimum Qualifications:
• Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR equivalent experience.
• 1+ year(s) people management experience.
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check:
• This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
• This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate's citizenship will be verified via a valid passport.
Preferred Qualifications:
• Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR equivalent experience.
• 3+ years people management and/or informal/indirect team leadership experience.
• Demonstrated experience producing or overseeing finished threat intelligence reporting for technical and/or executive audiences.
• Working experience with Microsoft Sentinel and Microsoft Defender XDR (or directly comparable SIEM/XDR platforms).
• 10+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline.
• Demonstrated track record leading a finished intelligence production function - owning report quality, publication standards, and the analytic tradecraft that makes intelligence credible and actionable.
• Experience managing or operating across both intelligence production and incident response disciplines, with fluency in the tension between long-horizon analysis and rapid-response demand.
• Portfolio of public or customer-facing intelligence writing (actor profiles, campaign reports, vulnerability analyses, or equivalent).
• Understanding of adversary tradecraft and frameworks including MITRE ATT&CK, the Diamond Model, Cyber Kill Chain, and structured analytic techniques.
• Experience with endpoint, cloud, network, and identity-based attacks and datasets.
• Programming or scripting background (Python, KQL, PowerShell, or equivalent) sufficient to evaluate and guide technical work on the team.
• Familiarity with AI-assisted intelligence workflows and automation approaches for threat triage, enrichment, and intelligence delivery at scale.
#MSSecurity
Security Research M5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

What Microsoft employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Microsoft logo

About Microsoft

Sourced by ZipRecruiter

Our infrastructure is comprised of a large global portfolio of more than 100 datacenters and 1 million servers. Our foundation is built upon and managed by a team of subject matter experts working to support services for more than 1 billion customers and 20 million businesses in over 90 countries worldwide. With environmental sustainability and optimization at the forefront of our datacenter design and operations, we continue to grow and evolve as we meet the ever-changing business demands that hold Microsoft as a world-class cloud provider.

Industry

Computer and computer peripheral equipment and software wholesalers

Company size

10,000+ Employees

Headquarters location

Redmond, WA, US

Year founded

1975

Social media