Microsoft Senior Security Researcher

New job, posted less than a week ago!

Job Details

Posted date: May 13, 2026

There have been 56 jobs posted with the title of Senior Security Researcher all time at Microsoft.

Category: Security Research

Location: Redmond, WA

Estimated salary: $188,900
Range: $119,800 - $258,000

Employment type: Full-Time

Work location type: 3 days / week in-office

Role: Individual Contributor


Description

Overview

Security is one of the most critical priorities for our customers in a world of growing digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world safer by empowering every user, customer, and developer with a security cloud that delivers end-to-end, simplified protection. The Microsoft Security organization advances this mission by helping secure digital technology platforms, devices, and clouds across customers’ heterogeneous environments, while also protecting Microsoft’s internal estate. Our culture is grounded in a growth mindset, inspiring excellence, and enabling teams and leaders to bring their full potential each day.

The Microsoft Threat Protection Research (MTP-R) Purple Team sits at the intersection of offense, defense, and intelligence, working across Microsoft Defender technologies to ensure telemetry, detections, and protections are effective against real-world cyberattacks. We are looking for a senior-level red team security researcher with experience in adversary emulation, offensive tooling, and malware development to design and execute realistic attack simulations in an AI-first environment. This role will use agentic systems and LLM-driven workflows to scale attack development, automation, and simulation fidelity, while helping shape how AI-enabled offensive research is used to emulate modern adversaries in controlled, high-impact ways.

Responsibilities

As a Senior Security Researcher on the MTP Research Purple Team, you will:

· Design and execute adversary simulations that emulate real-world threat actors across endpoint, identity, cloud, and SaaS environments.

· Develop and modify offensive tooling, including custom payloads, loaders, and command-and-control (C2) frameworks.

· Conduct malware development and tradecraft research to replicate modern attacker techniques such as evasion, persistence, and lateral movement.

· Leverage threat intelligence to inform adversary emulation scenarios, including campaign design, TTP selection, and operational sequencing.

· Apply threat modeling frameworks such as MITRE ATT&CK to emulate realistic attack paths and identify defensive gaps.

· Utilize AI-enabled and agentic systems to generate attack variations, automate tradecraft execution, and scale simulation coverage.

· Partner with blue team and detection engineering teams to validate detections and improve defensive capabilities.

· Analyze telemetry generated from simulations to assess detection coverage and identify opportunities for improvement.

· Contribute to simulation reports, technical documentation, and internal knowledge sharing.

· Collaborate across teams to improve offensive tooling, methodologies, and research practices.

Qualifications

Minimum Qualifications:

Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field.OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.OR equivalent experience.Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

Microsoft Cloud Background Check:

This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.This position requires verification of U.S. citizenship due to citizenship‑based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship‑based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified via a valid passport.Preferred Qualifications:

Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.OR equivalent experience.3+ years of experience with coding. 2+ years of experience in red team operations, adversary emulation, or offensive security research.1+ years of experience with large language models or machine learning. Experience in classical and deep learning machine learning methods. 1+ years of experience performing threat intelligence research.Security related certifications such as OSCP, OSWE, GPEN, GREM, GCPN.#MSFTSecurity

Security Research IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $158,400 - $258,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.



Email job link for Senior Security Researcher at Microsoft

Provide your email address to receive a message with the job link and details.

Check out other jobs at Microsoft.