Principal AI Security Researcher

Microsoft Microsoft · Big Tech · Redmond, WA +2 · Security Research

This role is for a Principal AI Security Researcher focused on attacking and defending AI systems, particularly LLMs, copilots, and agents. The researcher will lead purple team simulations, develop and execute AI attacks (e.g., prompt injection, RAG poisoning, agent abuse), build red teaming tooling, evaluate AI defenses, and translate findings into mitigations. The role requires a strong security background combined with a deep understanding of modern AI and its vulnerabilities, with an emphasis on making AI safer and informing security products.

What you'd actually do

  1. Lead the design and execution of purple team simulations aimed at making AI safer, conducting realistic AI attacks whose findings inform our security products and help them protect customers more effectively.
  2. Develop and execute hands-on attacks against AI systems, including:
  3. Build scalable AI red teaming tooling and automation (custom attack harnesses and evaluation frameworks) to generate attack variations, run large evaluations, and continuously test AI systems as they change.
  4. Partner with product, engineering, Responsible AI, and detection teams to translate findings into mitigations: better system prompts, input and output filters, grounding controls, agent guardrails, and detections.
  5. Evaluate the effectiveness of AI defenses (detections, safety classifiers, filters, and monitoring) and provide strategic recommendations to close gaps.

Skills

Required

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field
  • 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Ability to meet Microsoft, customer and/or government security screening requirements

Nice to have

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field
  • 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • A security background: experience finding and exploiting real vulnerabilities (for example penetration testing, red teaming, vulnerability research, or application security), with an adversarial mindset.
  • Solid, practical understanding of how modern AI works: LLMs, prompting, retrieval-augmented generation (RAG), fine-tuning, and agentic / tool-using systems.
  • Hands-on experience and familiarity with agentic AI systems, red teaming harnesses, and AI tooling: building or working with agents, tool-using LLMs, orchestration and evaluation frameworks, LLM APIs, and attack harnesses.
  • Demonstrated hands-on experience attacking AI systems: prompt injection (direct and indirect), jailbreaks, guardrail bypass, data exfiltration, or agent abuse, in research or professional settings.

What the JD emphasized

  • real security background
  • deep, hands-on understanding of how modern AI works
  • hands-on experience attacking AI systems
  • security background: experience finding and exploiting real vulnerabilities
  • Solid, practical understanding of how modern AI works
  • Hands-on experience and familiarity with agentic AI systems, red teaming harnesses, and AI tooling

Other signals

  • AI attacks
  • AI safety
  • AI red teaming
  • AI defenses
  • AI product security