More jobs:
Principal Security Researcher
Job in
Redmond, King County, Washington, 98073, USA
Listed on 2026-08-09
Listing for:
Microsoft Corporation
Full Time
position Listed on 2026-08-09
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
* The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable. We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution.
You will combine deep vulnerability research with AI experimentation: researching vulnerability classes and language ecosystems, identifying representative evaluation targets, building and reviewing ground truth, analyzing missed and incorrect findings, and developing improvements that measurably increase recall, precision, consistency, and fix quality. We are looking for a hands-on vulnerability researcher who can read unfamiliar code, trace attacker-controlled data to security-sensitive operations, develop and use fuzzers and other analysis tools, reproduce vulnerabilities, assess exploitability and reachability, and determine whether a proposed fix addresses the underlying weakness.
You will carry research from hypothesis through implementation and measurement, directly building and evaluating improvements to MDASH's agents, tools, model configurations, and analysis methods while collaborating with engineering and applied science partners.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
** Responsibilities*
* + Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures to discover and validate vulnerabilities, assess reachability and exploitability, evaluate fixes for security correctness, and identify opportunities to expand MDASH coverage.
+ Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods, and measure their impact.
+ Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation.
+ Drive MDASH's eval-driven development and hill-climbing loop by running evaluations, uncovering patterns in missed and incorrect results, and creating adversarial and regression cases that turn blind spots into measurable capability gains.
+ Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement.
+ Provide technical leadership across the MDASH security research team by shaping research direction, leading complex investigations, mentoring other researchers, and raising the quality of vulnerability research and implementation.
+ Collaborate across research, engineering, applied science, and product teams to deliver improvements, communicate results, and influence technical direction.
** Other*
* Embody our Culture and Values
** Qualifications*
* ** Required/minimum qualifications*
* Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.
** Other Requirements*
* Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check:
- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
** Additional or preferred qualifications*
* + Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience.
+ 8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work.
+ Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness.
+
Experience with fuzzing and at least one additional vulnerability research technique, such as manual code review, static analysis, dynamic…
Position Requirements
5+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×