Microsoft

Principal Security Researcher

Microsoft
Apply
29 days ago
Remote, WorldwideStaff+
H1B Sponsor

Base Salary

$143k - $275k/yr

Responsibilities

  • Conduct hands-on vulnerability research across vulnerability classes, programming languages, frameworks, and codebase architectures.
  • Discover, reproduce, validate, and assess the reachability and exploitability of vulnerabilities and evaluate whether fixes address underlying weaknesses.
  • Implement and measure improvements to MDASH agents, tools, model configurations, and analysis methods.
  • Create evaluation targets, trusted ground truth, adversarial cases, regression cases, benchmarks, datasets, graders, and fuzzing automation.
  • Build fuzzing harnesses and research prototypes to improve vulnerability discovery and validation capabilities.
  • Lead complex investigations, shape security research direction, mentor researchers, and raise research quality.
  • Collaborate with research, engineering, applied science, and product teams and communicate technical results.

Requirements

  • A master’s degree in statistics, mathematics, computer science, risk management, cybersecurity, or a related field plus 4+ years of relevant experience, or a bachelor’s degree in those fields plus 6+ years of relevant experience, or equivalent experience.
  • Preferred education includes a bachelor’s, master’s, or doctorate in computer science, computer security, computer engineering, or a related field, or equivalent experience.
  • Preferred experience includes 8+ years in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work.
  • Hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness.
  • Experience with fuzzing and another vulnerability research technique such as manual code review, static analysis, dynamic analysis, debugging, reverse engineering, symbolic execution, taint analysis, or exploit development.
  • Proficiency developing security research tooling or automation in one or more programming languages.
  • Deep knowledge of multiple vulnerability classes, including memory corruption, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws.
  • Experience with fuzzing harnesses, custom mutators, sanitizers, coverage-guided fuzzing, or large-scale fuzzing infrastructure.
  • Experience analyzing vulnerabilities across multiple programming languages and ecosystems, including C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications.
  • Experience constructing security benchmarks, curating ground truth, measuring evaluation metrics, and translating root-cause analysis into generalized improvements.
  • Experience building or improving AI agents and agentic systems using large language models, including prompt and tool orchestration, model evaluation, automated grading, or reinforcement learning for security tasks.
  • Experience with static application security testing, software composition analysis, SARIF, secure development lifecycle practices, or developer remediation workflows.
  • A record of vulnerability disclosures, security advisories, CVEs, research publications, conference presentations, open-source security tools, or substantive security-community contributions.
  • Ability to meet Microsoft, customer, and government security screening requirements, including the Microsoft Cloud Background Check.

Benefits

  • The role includes a U.S. base pay range of USD $142,800–$274,800 per year, with a separate USD $188,000–$304,200 per year range for specified San Francisco Bay Area and New York City metropolitan locations.
  • Certain roles may be eligible for benefits and other compensation.
  • The position is open for a minimum of five days and accepts applications on an ongoing basis until filled.
Microsoft

About Microsoft

10,000+ employees

Every company has a mission. What's ours? To empower every person and every organization to achieve more. We believe technology can and should be a force for good and that meaningful innovation contributes to a brighter world in the future and today. Our culture doesn’t just encourage curiosity; it embraces it. Each day we make progress together by showing up as our authentic selves. We show up with a learn-it-all mentality. We show up cheering on others, knowing their success doesn't diminish our own. We show up every day open to learning our own biases, changing our behavior, and inviting in differences. Because impact matters. Microsoft operates in 190 countries and is made up of approximately 228,000 passionate employees worldwide.

Contact me