Principal Security Researcher

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Security Research

Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution. This role involves deep vulnerability research combined with AI experimentation, including researching vulnerability classes, identifying evaluation targets, building ground truth, analyzing findings, and developing improvements to measurably increase recall, precision, consistency, and fix quality. The researcher will also be responsible for translating research insights into implemented improvements and driving the eval-driven development loop.

What you'd actually do

  1. Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures to discover and validate vulnerabilities, assess reachability and exploitability, evaluate fixes for security correctness, and identify opportunities to expand MDASH coverage.
  2. Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods, and measure their impact.
  3. Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation.
  4. Drive MDASH's eval-driven development and hill-climbing loop by running evaluations, uncovering patterns in missed and incorrect results, and creating adversarial and regression cases that turn blind spots into measurable capability gains.
  5. Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement.

Skills

Required

  • Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.
  • Ability to meet Microsoft, customer and/or government security screening requirements
  • Microsoft Cloud Background Check

Nice to have

  • Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience.
  • 8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work.
  • Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness.
  • Experience with fuzzing and at least one additional vulnerability research technique, such as manual code review, static analysis, dynamic analysis, debugging, reverse engineering, symbolic execution, taint analysis, or exploit development.
  • Proficiency developing securi

What the JD emphasized

  • hands-on vulnerability researcher
  • assess exploitability
  • reachability
  • evaluate fixes for security correctness
  • eval-driven development

Other signals

  • multi-agent system
  • multi-model system
  • vulnerability discovery
  • validation
  • developer guidance
  • AI experimentation
  • vulnerability research
  • ground truth
  • missed findings
  • incorrect findings
  • recall
  • precision
  • consistency
  • fix quality
  • hands-on vulnerability researcher
  • read unfamiliar code
  • trace attacker-controlled data
  • security-sensitive operations
  • fuzzers
  • analysis tools
  • reproduce vulnerabilities
  • assess exploitability
  • reachability
  • proposed fix
  • underlying weakness
  • hypothesis
  • implementation
  • measurement
  • evaluating improvements
  • agents
  • tools
  • model configurations
  • analysis methods
  • collaborating with engineering
  • applied science partners