1

Microsoft Threat Intelligence Jobs (NOW HIRING)

The Threat Intelligence Analyst will work within a physical security function to detect threats to ... including Microsoft Office applications and word processing, spreadsheets, databases, and ...

The Threat Intelligence Analyst will work within a physical security function to detect threats to ... including Microsoft Office applications and word processing, spreadsheets, databases, and ...

Desire to acquire Microsoft SC-200 * Experience with Azure Sentinel, Defender for Cloud and/or Microsoft Defender Threat Intelligence is desired. * Familiarity with Common Vulnerabilities and ...

Senior Cyber Threat Analyst

$99K - $128K/yr

Experience with Microsoft Threat Intelligence and Google Threat Intelligence (Previously Mandiant Advantage Threat Intelligence) Platforms Responsibilities: * Develop and execute strategic plans for ...

Senior Cyber Threat Analyst

$102K - $132K/yr

Experience with Microsoft Threat Intelligence and Google Threat Intelligence (Previously Mandiant Advantage Threat Intelligence) Platforms Responsibilities: * Develop and execute strategic plans for ...

next page

Showing results 1-20

Microsoft Threat Intelligence information

See salary details

$45.5K

$104.6K

$144K

How much do microsoft threat intelligence jobs pay per year?

As of Aug 1, 2026, the average yearly pay for microsoft threat intelligence in the United States is $104,643.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $118,500.00 per year, depending on experience, location, and employer.

What is a Microsoft Threat Intelligence job?

A Microsoft Threat Intelligence job involves analyzing cyber threats, tracking threat actors, and providing intelligence to strengthen cybersecurity defenses. Professionals in this role use advanced tools and data analysis to identify vulnerabilities, assess risks, and develop strategies to mitigate potential attacks. They work closely with security teams, government agencies, and organizations to enhance threat detection and response. This role requires expertise in cybersecurity, threat hunting, and threat intelligence analysis to protect Microsoft and its customers from cyber threats.

What does a typical workday look like for someone in a Microsoft Threat Intelligence role?

A typical day in Microsoft Threat Intelligence involves monitoring global threat landscapes, analyzing risks to Microsoft's cloud and infrastructure, and collaborating with other cybersecurity teams to develop mitigation strategies. Team members frequently assess new vulnerabilities, conduct deep research on emerging attack trends, and generate actionable intelligence reports. Regular interactions with internal engineering, incident response, and product teams are common, ensuring coordinated responses to threats. This dynamic and varied work environment keeps professionals engaged and constantly learning about the latest developments in cyber defense.

What are the key skills and qualifications needed to thrive in the Microsoft Threat Intelligence position, and why are they important?

To excel in Microsoft Threat Intelligence, you need a solid background in cybersecurity, threat analysis, and incident response, often supported by a degree in computer science or related field. Familiarity with tools such as SIEM platforms (like Azure Sentinel), threat intelligence feeds, and industry certifications such as CISSP or GIAC are highly valued. Strong analytical thinking, effective communication, and teamwork skills set exceptional candidates apart. These competencies are crucial for analyzing threats, sharing insights, and collaborating to protect Microsoft’s digital ecosystem.

What cities are hiring for Microsoft Threat Intelligence jobs? Cities with the most Microsoft Threat Intelligence job openings:
What are the most commonly searched types of Microsoft Threat Intelligence jobs? The most popular types of Microsoft Threat Intelligence jobs are:
What states have the most Microsoft Threat Intelligence jobs? States with the most job openings for Microsoft Threat Intelligence jobs include:
Infographic showing various Microsoft Threat Intelligence job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 8% Part Time, and 3% Contract. Highlights an 86% Physical, 4% Hybrid, and 10% Remote job distribution, with an average salary of $104,643 per year, or $50.3 per hour.

Senior Applied Threat Intelligence Analyst - Microsoft Security Threat Response

Microsoft

Redmond, WA • On-site

Full-time

Re-posted 11 days ago


Microsoft rating

8.5

Company rating: 8.5 out of 10

Based on 131 frontline employees who took The Breakroom Quiz

77th of 241 rated software companies


Job description

Overview
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' heterogeneous environments, as well as ensuring the security of our own internal estate.
Microsoft Security Research, is at the front line of defending Microsoft customers and the broader ecosystem against the world's most sophisticated threat actors. Our Applied Threat Intelligence Production team transforms raw signal from Microsoft's scale of telemetry into actionable, customer-facing intelligence that empowers defenders, informs product decisions, and shapes the public narrative on the threat landscape. We partner deeply across Microsoft Threat Intelligence, product engineering, research, marketing, and communications to ship intel that moves markets and protects organizations everywhere.
Responsibilities
As a Senior Applied Threat Intelligence Analyst:
  • Author and publish high-impact threat intelligence reports (actor profiles, campaign analyses, trend reports, TTP deep-dives, vulnerability profiles) for both customer-facing and internal audiences.

  • Build and refine the pipelines, tooling, and workflows that allow Microsoft to stream insightful cyber threat intelligence to customers machine speed.

  • Represent Microsoft Threat Intelligence in customer briefings, industry conferences, and cross-industry working groups.

  • Translate technical findings into clear, actionable insights for security operations teams and technical stakeholders.

  • Partner with product, engineering, and research teams to operationalize intelligence into Microsoft security platforms (e.g., Defender XDR, Sentinel, customer briefings).

  • Contribute to scalable workflows and pipelines that improve how threat intelligence is generated, refined, and delivered to customers.

  • Support customer engagements (briefings, responses, and discussions) with accurate and timely intelligence insights.

  • Collaborate within the team to improve analytic tradecraft, knowledge sharing, and intelligence quality.

Qualifications
Minimum Qualifications:
  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field.
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.

Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check:
  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications:
    • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
      • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
      • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
      • OR equivalent experience.
    • 5+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline.
    • Demonstrated experience producing finished threat intelligence reporting for technical audiences.
    • Attribution experience creating threat groups, assessing connections between established threat groups, and communicating attribution assessments to internal stakeholders and customers in a timely manner.
    • Working experience with Microsoft Sentinel and Microsoft Defender XDR (or directly comparable SIEM/XDR platforms).
    • Understanding of adversary tradecraft, the cyber kill chain, and frameworks such as MITRE ATT&CK, the Diamond Model, and structured analytic techniques.
    • Written and verbal communication skills, with a portfolio of public or customer-facing intelligence writing.
    • Experience analyzing endpoint, cloud, identity, and network telemetry.
    • Familiarity with scripting or data analysis tools (Python, KQL, SQL, PowerShell).
    • Understanding of OS internals, network protocols, and common attack techniques.
    • Exposure to reverse engineering or malware analysis.
    • Functional understanding of common threat analysis models such as the Diamond Model, Cyber Kill Chain, and MITRE ATT&CK.
    • Programming or scripting background (Python, PowerShell, C#, C++, etc.).

Security Research IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

What Microsoft employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Microsoft logo

About Microsoft

Sourced by ZipRecruiter

Our infrastructure is comprised of a large global portfolio of more than 100 datacenters and 1 million servers. Our foundation is built upon and managed by a team of subject matter experts working to support services for more than 1 billion customers and 20 million businesses in over 90 countries worldwide. With environmental sustainability and optimization at the forefront of our datacenter design and operations, we continue to grow and evolve as we meet the ever-changing business demands that hold Microsoft as a world-class cloud provider.

Industry

Computer and computer peripheral equipment and software wholesalers

Company size

10,000+ Employees

Headquarters location

Redmond, WA, US

Year founded

1975

Social media