Principal Security Researcher @Microsoft
All Others
Salary usd 142,800 - 3..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2mths ago

[Hiring] Principal Security Researcher @Microsoft

2mths ago - Microsoft is hiring a remote Principal Security Researcher. πŸ’Έ Salary: usd 142,800 - 304,200 per year πŸ“Location: USA

Role Description

The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution. You will combine deep vulnerability research with AI experimentation:

  • Researching vulnerability classes and language ecosystems.
  • Identifying representative evaluation targets.
  • Building and reviewing ground truth.
  • Analyzing missed and incorrect findings.
  • Developing improvements that measurably increase recall, precision, consistency, and fix quality.

You will carry research from hypothesis through implementation and measurement, directly building and evaluating improvements to MDASH's agents, tools, model configurations, and analysis methods while collaborating with engineering and applied science partners.

Responsibilities

  • Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures.
  • Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods.
  • Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation.
  • Drive MDASH's eval-driven development and hill-climbing loop by running evaluations and uncovering patterns in missed and incorrect results.
  • Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement.
  • Provide technical leadership across the MDASH security research team.
  • Collaborate across research, engineering, applied science, and product teams to deliver improvements and communicate results.

Qualifications

  • Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in the same fields AND 6+ years experience OR equivalent experience.
  • Ability to meet Microsoft, customer and/or government security screening requirements.
  • Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience.
  • 8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work.
  • Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities.
  • Experience with fuzzing and at least one additional vulnerability research technique.
  • Proficiency developing security research tooling or automation in one or more programming languages.
  • Experience communicating complex technical findings through clear written reports, vulnerability analyses, or presentations.
  • Deep knowledge of multiple vulnerability classes and their exploitation patterns.
  • Experience building fuzzing harnesses, custom mutators, or large-scale fuzzing infrastructure.
  • Experience analyzing vulnerabilities across multiple programming languages and ecosystems.
  • Experience constructing security benchmarks and translating root-cause analysis into generalized improvements.
  • Experience building and improving AI agents or agentic systems using large language models.
  • Experience with static application security testing, software composition analysis, or secure development lifecycle practices.
  • Record of vulnerability disclosures, security advisories, CVEs, research publications, conference presentations, or contributions to the security community.

Requirements

  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Benefits

  • The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year.
  • In the San Francisco Bay area and New York City metropolitan area, the base pay range is USD $188,000 - $304,200 per year.
  • Certain roles may be eligible for benefits and other compensation.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Principal Security Researcher @Microsoft
All Others
Salary usd 142,800 - 3..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,100+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later