Senior Security Research Engineer

Microsoft

Job details

  • HYBRID
  • FULL_TIME
  • Redmond
  • United States
  • Verified 2026-10-03
  • Source: Microsoft public Eightfold board

Original job description

Overview

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.

Our team develops realistic environments where security models and agents can learn through interaction and demonstrate their capabilities against verifiable outcomes. These environments support reinforcement learning for Microsoft's MAI models, evaluation of security perception agents, and evaluation of the software harnesses that provide agents with tools, context, and execution control. We are looking for a Senior Security Research Engineer to design and build enterprise environments spanning Azure, AWS, GCP, on-premises infrastructure, and third-party technologies. You will bring together working applications, identity systems, networks, operational activity, and security telemetry to reflect the conditions customers face. By making these environments reproducible and reliably resettable, you will enable repeated training and controlled comparisons that show whether changes to a model, agent, or harness improve security results. You will partner with security researchers and AI engineers to turn representative enterprise architectures into a reusable engineering platform. This role offers the opportunity to combine distributed systems, cloud infrastructure, and security engineering with applied AI, while owning substantial capabilities from design through delivery and operation. Your work will help close the gap between performance on isolated tests and effectiveness in real customer environments.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.



Responsibilities
  • Build realistic enterprises.
  • Connect applications, networks, identities, and third-party services across Azure, AWS, GCP, and on-premises systems, including realistic user activity and security telemetry.
  • Make environments repeatable.
  • Build reusable infrastructure, images, and self-service automation to provision, validate, reset, and retire complete environments.
  • Enable AI training and evaluation.
  • Deliver interfaces for agent actions, observations, and evidence collection so teams can reliably compare model, agent, and harness changes.
  • Engineer for safe scale.
  • Support concurrent experiments with strong isolation, synthetic data, health checks, recovery, and cost controls.
  • Own capabilities end to end.
  • Partner with security researchers and AI engineers to ship dependable systems, resolve cross-stack challenges, and mentor engineers.


Qualifications

Minimum Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

Microsoft Cloud Background Check:

  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.
  • 3+ years of experience developing software, infrastructure automation, or cloud platforms.
  • Experience shipping and maintaining software or automation in Python, Go, C#, or TypeScript, using version control, automated tests, and code review. - Experience deploying applications and configuring networks, identities, and storage in at least one of Azure, AWS, or GCP.
  • Experience connecting services across a second cloud or an on-premises environment. - Experience building infrastructure-as-code modules and CI/CD deployment pipelines using Terraform, Bicep, CloudFormation, or equivalent tools.
  • Experience diagnosing Windows or Linux application failures involving DNS, routing, authentication, or service dependencies using logs, metrics, and system tools.
  • Experience owning a platform capability from technical design through deployment and operational support, including documenting design decisions and resolving production failures.
  • Configured identity federation, certificate-based authentication, or workload identities using Active Directory, Entra ID, Okta, or another enterprise identity provider.
  • Built security labs or environment-as-a-service platforms with automated image creation, provisioning, baseline reset, and teardown.
  • Deployed Kubernetes workloads with network policies, service identities, and centralized logging.
  • Automated synthetic user or administrator activity and collected identity, endpoint, or application telemetry for security testing.
  • Integrated versioned environments into RL training or agent-evaluation pipelines, including checks for configuration drift and state left over from previous runs.
  • Designed and built capture the flag challenges or competitions.


Security Research IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Related jobs

Apply at company