Microsoft

Microsoft

Posted via Microsoft Careers

Senior Security Researcher

Posted Oct 8, 2026

Role at a glance

Job function
Software Engineering & IT Cybersecurity
Salary
$160.2K – $261K/yr
Location
Redmond, Washington, United States
Work arrangement
On-site
Employment
Full-time
Education
Bachelor's, Master's, PhD

Spotted an issue?

We’ll check it against the original posting.

Log in to report

About the role

Original posting provided by Microsoft

View original
Overview

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.

The Cloud Apps and Identity Research (CAIR) team researches and builds protections against advanced attacks targeting identities and cloud applications. Our work spans threat research, detection, investigation, risk, and disruption, with an increasing focus on protecting identities across third-party identity providers and SaaS applications such as Okta and Salesforce. We are expanding how we do security research through AI and agentic systems, building RAG-based and coding agents that help researchers discover coverage gaps, analyze attacks, author and validate detections, and investigate threats at scale. As a Senior Security Researcher, you will combine deep security research and threat hunting expertise with hands-on experience in AI agents, evaluation, and quality validation, helping turn emerging attack techniques into scalable protection for customers.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.



Responsibilities
  • Research third-party identity and SaaS attacks: Research attacker tradecraft and emerging threats targeting identities, applications, authentication flows, sessions, privileges, and data across third-party identity providers and SaaS platforms, including Okta and Salesforce.
  • Translate threat research into protection: Convert security research, incidents, customer reports, and threat-landscape intelligence into clear attack scenarios, telemetry requirements, detection opportunities, investigation logic, and durable protection strategies.
  • Build AI agents for security research: Design and develop RAG-based agents that retrieve and reason over product documentation, schemas, threat intelligence, prior research, code, telemetry, and operational knowledge to support security-research workflows.
  • Develop coding and detection-authoring agents: Build coding agents that help generate, review, refine, and maintain security analytics, KQL queries, detection logic, test cases, and related research artifacts with appropriate human oversight.
  • Create evaluation frameworks: Define representative datasets, scenarios, benchmarks, and scoring methods to evaluate agent accuracy, completeness, groundedness, robustness, and security-research usefulness.


Qualifications

Minimum Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

Microsoft Cloud Background Check:

  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.
  • Background in the modern attacker kill-chain and MITRE ATT&CK.
  • Experience researching hybrid attacks involving third-party identity providers and SaaS applications, such as Okta and Salesforce, and attacks against cloud services.
  • Threat hunting and data-analysis skills.
  • Experience with AI agents, RAG-based systems, agent evaluation, LLM-as-a-judge techniques, and quality validation.
  • Programming skills in Python or a similar language, with experience building production-quality research or automation tools.
  • Experience designing evaluation frameworks and quality-validation methods for AI systems, including measuring accuracy, groundedness, reliability, and regressions.


Security Research IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Microsoft

About the company

Microsoft

Large Enterprise

Microsoft is a global technology leader that empowers individuals and organizations to achieve more through innovative software, services, and devices. Founded in 1975, the company is best known for its flagship products like the Windows operating system and Microsoft Office suite. In addition to personal computing, Microsoft is a leader in cloud computing with its Azure platform, providing a range of solutions for businesses to enhance productivity and efficiency. With a strong commitment to sustainability and accessibility, Microsoft continues to drive technological advancements that shape the future of work and learning.