Senior Security Researcher

Microsoft Microsoft · Big Tech · Redmond, WA +2 · Security Research

Senior Security Researcher role focused on offensive security research using AI-enabled and agentic systems to emulate real-world cyberattacks. The role involves designing and executing adversary simulations, developing offensive tooling, conducting malware research, and leveraging threat intelligence. A key aspect is utilizing AI and LLM-driven workflows to scale attack development, automation, and simulation fidelity, while partnering with blue teams to improve detections and defensive capabilities.

What you'd actually do

  1. Design and execute adversary simulations that emulate real-world threat actors across endpoint, identity, cloud, and SaaS environments.
  2. Develop and modify offensive tooling, including custom payloads, loaders, and command-and-control (C2) frameworks.
  3. Conduct malware development and tradecraft research to replicate modern attacker techniques such as evasion, persistence, and lateral movement.
  4. Leverage threat intelligence to inform adversary emulation scenarios, including campaign design, TTP selection, and operational sequencing.
  5. Utilize AI-enabled and agentic systems to generate attack variations, automate tradecraft execution, and scale simulation coverage.

Skills

Required

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field
  • Experience in software development lifecycle
  • Experience in large-scale computing
  • Experience in threat analysis or modeling
  • Experience in cybersecurity
  • Experience in vulnerability research
  • Experience in anomaly detection
  • coding
  • red team operations
  • adversary emulation
  • offensive security research
  • large language models
  • machine learning
  • classical and deep learning machine learning methods
  • threat intelligence research

Nice to have

  • Security related certifications such as OSCP, OSWE, GPEN, GREM, GCPN

What the JD emphasized

  • AI-enabled and agentic systems
  • LLM-driven workflows
  • scale attack development
  • automation
  • simulation fidelity

Other signals

  • AI-enabled offensive research
  • agentic systems
  • LLM-driven workflows
  • scale attack development
  • automation
  • simulation fidelity