Overview The Microsoft Specialized Clouds Vulnerability Research team (STORM) is seeking a Security Research Intern to help strengthen the security visibility of Microsoft’s next-generation cloud platforms. STORM is an offensive security research group focused on identifying vulnerabilities across cutting-edge cloud technologies. As part of our growing Blue Team research efforts, this role will contribute to improving the telemetry, logging, and audit capabilities needed to detect sophisticated attacks. Working alongside security researchers, architects, and engineering teams, you will review products during development, identify gaps in security visibility, and help ensure security monitoring capabilities are built in before products reach customers.This hands-on internship offers significant ownership, mentorship from senior researchers, and exposure to technologies that are not yet publicly available. You will analyze product architectures and threat models, assess and improve security telemetry, validate detection coverage for real-world vulnerabilities, develop automation and hunting capabilities, and collaborate closely with engineering teams to integrate security visibility throughout the product lifecycle. Along the way, you will gain practical experience in cloud security research, detection engineering, threat hunting, telemetry design, distributed systems, Kubernetes security, platform security, and AI-assisted security workflows, while directly contributing to the security of Microsoft’s Sovereign Cloud and Adaptive Cloud platforms. Responsibilities Investigate real-world nation state attacks to support the development of high-fidelity protection logic across complex cross-domain kill-chains. Apply security expertise to analyze massive telemetry sets using big-data query languages (KQL), reasoning over data to identify novel malicious patterns and engineer evidence-based detection rules. Contribute to the implementation and coding of automated capab