Microsoft

AI Security Engineer

Microsoft
Apply
2 days ago
Remote, United StatesSenior / Staff+
H1B sponsor

Base Salary

$102k - $261k/yr

Responsibilities

  • Design, implement, and operate offensive cyber-capability evaluations for frontier, preview, production, and open-weight AI models.
  • Build and maintain evaluation tasks covering vulnerability analysis, exploit development, application and system exploitation, attack-path reasoning, post-exploitation, and multi-step offensive workflows.
  • Execute controlled experiments, define success criteria and baselines, collect telemetry, and document results.
  • Analyze model trajectories and investigate whether results reflect genuine capability or evaluation artifacts.
  • Develop cyber ranges, vulnerable applications, exploit-development targets, and evaluation harnesses with sandboxing, secrets management, telemetry, access, and containment controls.
  • Partner with red-team operators, researchers, engineers, and Responsible AI stakeholders and communicate findings through reports, documentation, and briefings.

Requirements

  • Minimum: master's degree in Statistics, Mathematics, Computer Science, Computer Security, or a related field plus 1+ year of relevant experience; or bachelor's degree in one of these fields plus 2+ years of relevant experience; or equivalent experience.
  • Preferred: doctorate, or master's degree plus 3+ years of relevant experience, or bachelor's degree plus 5+ years of relevant experience, or equivalent experience.
  • Programming ability, particularly in Python, including automation, scripting, or security tooling.
  • Familiarity with large language models, generative AI systems, coding models, AI agents, model APIs, or model-evaluation frameworks.
  • Experience with experimental methodology, controlled experiments, success criteria, result analysis, and technical documentation.
  • Experience or exposure to security labs, cyber ranges, capture-the-flag environments, vulnerable applications, exploit development, vulnerability research, penetration testing, application security, or red teaming.
  • Experience with coding agents, tool-using models, autonomous agent frameworks, or cyber-capability evaluations.
  • Familiarity with PyRIT, adversarial-testing tools, containers, sandboxed execution, or cloud-based test infrastructure.
  • Ability to meet Microsoft, customer, and government security screening requirements, including citizenship or protected-status verification for export-controlled and government-related work.

Benefits

  • The typical U.S. base pay ranges from USD $102,100 to $202,200 for Security Research IC3 and from USD $119,800 to $234,700 for Security Research IC4, with different San Francisco Bay Area and New York City metropolitan area ranges.
  • Applications are accepted on an ongoing basis until the position is filled, with the posting open for a minimum of five days.
  • The role requires Microsoft background and Microsoft Cloud background checks upon hire or transfer and every two years thereafter.
  • Certain roles may be eligible for benefits and other compensation.

Tech Stack

Categories

Microsoft

About Microsoft

10,000+ employees

Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.

Contact me