Principal Security Researcher

Microsoft - Redmond, WA

Hiring: Principal Security Researcher Company: Microsoft Location: Redmond, WA Job Posted Time: 2026-09-16 15:40:37 Target Skills & Keywords : C, C#, C++, Java, JavaScript, LLM, Python, Reinforcement Learning, Risk Management, TypeScript About the job Experience: •8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work. Required Skills: •Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures to discover and validate vulnerabilities, assess reachability and exploitability, evaluate fixes for security correctness, and identify opportunities to expand MDASH coverage. •Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods, and measure their impact. •Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation. •Drive MDASH's eval-driven development and hill-climbing loop by running evaluations, uncovering patterns in missed and incorrect results, and creating adversarial and regression cases that turn blind spots into measurable capability gains. •Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement. •Provide technical leadership across the MDASH security research team by shaping research direction, leading complex investigations, mentoring other researchers, and raising the quality of vulnerability research and implementation. •Collaborate across research, engineering, applied science, and product teams to deliver improvements, communicate results, and influence technical direction. •Embody our Culture and Values Qualifications: •This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter. •Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience. •Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness. •Proficiency developing security research tooling or automation in one or more programming languages. •Deep knowledge of multiple vulnerability classes and their exploitation patterns, including memory corruption, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws. Compensation: •$142,800 - $274,800 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!