Security Researcher

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Applied Sciences

Security Researcher for Microsoft's AI Red Team, focusing on discovering and exploiting GenAI security vulnerabilities in large AI systems and models across Microsoft's AI portfolio. The role involves emulating security experts, testing for security and safety failures, developing new testing techniques, and collaborating with AI Safety, Security, and Product Development teams.

What you'd actually do

  1. Discover and exploit GenAI security vulnerabilities end-to-end in order to assess AI systems and models
  2. Manage product group stakeholders as priority recipients and collaborators for operational sprints
  3. Drive clarity on communication and reporting for red teaming peers when working with product groups
  4. Develop methodologies and techniques to scale and accelerate AI Red Teaming in new and emerging threat areas
  5. Work alongside traditional offensive security engineers, adversarial ML experts, developers to land responsible AI operations

Skills

Required

  • Bachelor's Degree in Statistics, Econometrics, Computer Science, Electrical or Computer Engineering, or related field AND 2+ years related experience OR Master's Degree in Statistics, Econometrics, Computer Science, Electrical or Computer Engineering, or related field AND 1+ year(s) related experience OR Doctorate in Statistics, Econometrics, Computer Science, Electrical or Computer Engineering, or related field OR equivalent experience
  • Ability to meet Microsoft, customer and/or government security screening requirements

Nice to have

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience
  • Penetration testing qualifications; GPEN/GXPN, GWAPT, OSCP/OSCE, CRT/CCT/CCSAS
  • Participation in bug bounties/CTFs
  • Experience of using

What the JD emphasized

  • demonstrated cybersecurity and agents testing experience
  • stress testing the highest risk AI models, products, and systems
  • red teaming prior to launch
  • find safety and security risks
  • security and safety failures

Other signals

  • AI Red Team
  • security and safety failures
  • GenAI security vulnerabilities
  • foundational models plus applications