Principal Applied Threat Intelligence Manager

Microsoft

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Redmond, WAReston, VA
Salary
$142,800–$274,800 / yr
Posted
36 days ago
Freshness
Confirmed live yesterday
Closes
Feb 2, 2027

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $184k
This role $209k
$127k most similar roles pay here $291k

This role pays more than 73% of similar roles. Most pay $156,000–$212,024 — the shaded band above. At the midpoint, this role pays about $209k versus about $184k for comparable roles.

Based on 239 similar postings.

Employer

About Microsoft

Microsoft Corporation is a global technology leader producing software, hardware, and cloud services including Windows, Office 365, Azure cloud platform, Xbox gaming, and Surface devices. Industry: Software & Cloud Computing

Microsoft currently has 598 open roles on FindRole.

Listed pay typically runs $119,800–$234,700 across 586 roles with salary data.

Most-posted roles

View all roles at Microsoft

At a glance

TL;DR · Principal Applied Threat Intelligence Manager

As a Principal Applied Threat Intelligence Manager, you will lead a team of analysts to analyze the threat landscape and modern attacker tradecraft using AI tools and large language models. You will manage the tracking of threat actors, including those motivated by financial gain, while monitoring their infrastructure, targets, and evolving tactics. Your daily responsibilities involve translating complex technical findings into prescriptive guidance for security operations teams, executives, and the broader defender community. You will also mentor analysts and contribute to tradecraft standards. The role requires expertise in the Cyber Kill Chain, Diamond Model, and MITRE ATT&CK framework. Key skills include reverse-engineering, binary analysis, and programming in Python, PowerShell, C#, or C++. You will work with endpoint, cloud, network, and identity-based datasets to defend against sophisticated cyber threats.

What you'll do

  • Manage a team of Applied Threat Intelligence analysts to analyze the threat landscape and attacker tradecraft.
  • Track threat actors, their infrastructure, targets, and shifting tactics, techniques, and procedures.
  • Translate complex technical findings into prescriptive guidance for security operations teams and executives.
  • Mentor analysts and contribute to tradecraft, analytic standards, and team-wide knowledge sharing.
  • Perform attribution by creating threat groups and assessing connections between established actors.
  • Produce finished threat intelligence reports for both technical and executive audiences.
  • Utilize AI tools and large language models to build agents and skills for security applications.
  • Analyze network infrastructure data, telemetry, and perform reverse-engineering with static and behavioral binary analysis.

What we're looking for

  • U.S. citizenship is required to meet legal restrictions for government agency customers.
  • A Doctorate in a relevant field and 3+ years of experience in cybersecurity or related fields are required.
  • A Master's degree in a relevant field and 4+ years of experience in cybersecurity or related fields are required.
  • A Bachelor's degree in a relevant field and 6+ years of experience in cybersecurity or related fields are required.
  • 3+ years of people management and/or informal team leadership experience is required.
  • 10+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline is required.
  • Experience with AI tools, large language models, and building agents for information security applications is required.
  • Proficiency in programming or scripting languages such as Python, PowerShell, C#, or C++ is required.

More like this

Similar roles

Senior Applied Threat Intelligence Analysts

Microsoft

43 days ago $102,100$202,200
Cyber Threat Intelligence Microsoft Sentinel Microsoft Defender XDR MITRE ATT&CK Python PowerShell C# C++ AI Large Language Models Reverse-engineering Cyber Kill Chain Diamond Model Network Protocols Anomaly Detection Vulnerability Research
6+ yrs exp Hybrid

Senior Applied Threat Intelligence Analyst

Microsoft

42 days ago $119,800$234,700
Cyber Threat Intelligence Microsoft Sentinel Microsoft Defender XDR MITRE ATT&CK Python KQL SQL PowerShell C# C++ Cyber Kill Chain Diamond Model Malware Analysis Reverse Engineering Network Protocols OS Internals Data Analysis
4+ yrs exp Hybrid

Senior Threat Intelligence Investigator

Oracle

Nashville, TN +3 10 days ago $114,600$234,600
Threat Intelligence Platforms Cyber Threat Intelligence (CTI) OSINT YARA Snort Suricata Bro/Zeek Malware Analysis Incident Response SOC Digital Forensics Windows Linux macOS OCI
6+ yrs exp

Cyber Threat Intelligence Analyst

Leidos

Washington, DC 59 days ago $107,900$195,050
Cyber Threat Intelligence MITRE ATT&CK Threat Intelligence Platforms (TIP Python PowerShell SIEM SOAR Firewalls IDS/IPS AWS Azure O365 KQL Elastic DSL SPL Cyber Kill Chain Diamond Model Data Correlation
8+ yrs exp Hybrid

Lead, Operational Intelligence & Threat-Informed Defense

Prudential Financial

Newark, NJ 25 days ago $123,700$204,100
Cyber Threat Intelligence Threat Hunting Incident Response MITRE ATT&CK ATLAS D3FEND Detection Engineering EDR SIEM Power BI Tableau Python PowerShell AWS SaaS Cloud Security Query Languages
Hybrid

Cyber Threat Intelligence Analyst III

Leidos

Washington, DC +2 2 days ago
Cyber Threat Intelligence Cyber Kill Chain Diamond Model Splunk Analyst1 Python Bash PowerShell C++ CrowdStrike Falcon Tanium Proofpoint TAP Zscaler Malware Analysis Incident Response Threat Hunting Forensics XML HTML
8+ yrs exp