Security Research Engineer
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Software Engineering
In short
Responsibilities
- Turn threat research into working scenarios, reproducing real vulnerabilities and emerging adversary techniques in cloud, on-premises, and hybrid environments.
- Build realistic attack chains connecting vulnerable applications, identity weaknesses, and misconfigurations into multi-step scenarios with verified prerequisites and observable security impact.
- Build automated graders and reward signals grounded in system state and telemetry, distinguishing agent success, effective defenses, and environment failures.
- Create attack variants, benign lookalikes, and patched controls that expose missed threats, false positives, and memorization.
- Own scenario code, isolation, evidence capture and reset; partner with AI and environment engineers to turn findings into better training and evaluation.
Requirements
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR equivalent experience.
- Ability to meet Microsoft, customer and/or government security screening requirements.
- Must pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Desired Qualifications
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
- OR equivalent experience.
- 5+ years of experience researching vulnerabilities, conducting authorized offensive security tests, investigating security incidents, or developing security tools.
- 3+ years of experience developing and debugging security tools or scenario automation in Python, C#, Go, C/C++, or TypeScript, using version control and automated tests.
- Experience independently reproducing a vulnerability or adversary technique and documenting its prerequisites, reproduction steps, and observed security impact.
- Experience building or validating multi-step attack chains across applications, identities, or hosts, including the access requirements and evidence for each step.
- Experience assessing cloud IAM in Azure, AWS, or GCP and testing authentication, permissions, or network access in Windows or Linux environments.
- Experience confirming or rejecting security findings through source-code review, telemetry, or controlled tests, including checking whether existing safeguards prevent the claimed impact.
- Experience running authorized security tests with isolated targets, lab-only credentials, execution limits, and cleanup procedures.
- Reconstructed attacks from incident evidence or threat reports for red-team, purple-team, or adversary-emulation exercises.
- Reproduced attack paths across cloud and on-premises identity systems involving federation, service principals, workload identities, or directory services.
- Used source-code analysis, debugging, or reverse engineering to identify a vulnerability's root cause and verify a fix.
- Built automated graders or reward functions that check system state and telemetry, including checks that distinguish scenario failures from agent failures.
- Created attack variants, benign comparison cases, patched scenarios, or simulated user activity to test detection accuracy and false positives.
Benefits
- Certain roles may be eligible for benefits and other compensation.
- Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Skills
Every company has a mission. What's ours? To empower every person and every organization to achieve more. We believe technology can and should be a force for good and that meaningful innovation contributes to a brighter world in the future and today. Our culture doesn’t just encourage curiosity; it embraces it. Each day we make progress together by showing up as our authentic selves. We show up with a learn-it-all mentality. We show up cheering on others, knowing their success doesn't diminish our own. We show up every day open to learning our own biases, changing our behavior, and inviting…
Company
MicrosoftJob Posted
4 days ago
Employment Type
Full Time
Work mode
Hybrid
Salary
US$119,800–234,700 · Negotiable
Experience Level
Senior
Locations
Redmond, United States
Reston, United States
Qualification
Applicants
Be an early applicant
