Jobs · Analyst · Washington

Principal Security Research Manager

Microsoft · Redmond, WA · Yesterday
Analyst$166k–$296k/yrFull-time

About the role

The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable.

We are seeking a Principal Security Research Manager to lead the team responsible for the security research and evaluation that advance MDASH's vulnerability discovery, validation, and remediation capabilities. This team shapes how MDASH finds vulnerabilities across programming languages, vulnerability classes, and codebase types; determines whether findings are valid and actionable; and improves the quality of generated fixes. The team owns the eval-driven development and hill-climbing loop: identifying representative evaluation targets, curating trusted ground truth, analyzing failures, and turning those insights into measurable improvements in vulnerability discovery, validation, and fix quality.

The ideal candidate combines deep expertise in vulnerability research and application security with demonstrated success leading highly technical teams. You will set the research and measurement strategy, develop security researchers, and partner across research, engineering, applied science, and product teams to turn evidence into measurable improvements for customers.

Responsibilities

  • Lead, mentor, and develop a team of security researchers responsible for MDASH vulnerability discovery, validation, fix generation, and quality measurement.
  • Define the research and quality roadmap for expanding MDASH coverage across vulnerability classes, programming languages, frameworks, codebase sizes, and real-world development patterns.
  • Establish measurable quality goals and decision criteria across recall, precision, consistency, vulnerability validation, fix correctness, and end-to-end resolution.
  • Direct the creation and curation of representative evaluation suites and trusted ground truth drawn from purpose-built vulnerable code, public benchmarks, open-source projects, internal codebases, and production feedback, ensuring the portfolio reflects real-world customer scenarios and guides measurable improvement in MDASH.
  • Lead systematic analysis of false negatives, false positives, inconsistent detections, validation failures, and ineffective or incorrect fixes; translate findings into prioritized improvements to the techniques, tools, agent behaviors, model configurations, and analysis methods that power MDASH.
  • Partner with MDASH engine, evaluation infrastructure, model, applied science, and product teams to integrate research improvements, establish release gates, and connect offline measurements with customer outcomes.
  • Communicate technical strategy, evaluation results, risks, and investment priorities to senior leaders and cross-functional partners.
  • Model Microsoft values and foster an inclusive environment in which researchers can do their best work, grow their expertise, and take accountability for customer outcomes.

Requirements

Required/minimum qualifications:

  • Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • OR equivalent experience.
  • 3+ years people management.

Other Requirements:

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Qualifications

Additional or preferred qualifications:

  • Deep knowledge of vulnerability classes and exploitation patterns, including memory safety, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws.
  • Experience with manual code review, static or dynamic analysis, fuzzing, symbolic execution, taint analysis, exploit development, or variant analysis.
  • Experience designing security benchmarks, curating ground truth, calibrating evaluators, and measuring recall, precision, false-positive rates, or fix efficacy.
  • Experience evaluating or building AI-assisted security systems, large language model applications, AI agents, automated graders, or human-in-the-loop evaluation workflows.
  • Experience working across multiple programming languages and software ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications.
  • Experience with responsible vulnerability disclosure or collaboration with open-source maintainers and product security response teams.

Pay

Security Research M6 - The typical base pay range for this role across the U.S. is USD $165,600 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year. Certain roles may be eligible for benefits and other compensation.

Similar jobs

Principal Security Researcher

Palo Alto NetworksSan Francisco, CA· 1 mo ago
Engineering$163k–$263k/yrapply on paloaltonetworks.wd5.myworkdayjobs.com

Principal Security Researcher

Palo Alto NetworksSanta Clara, CA· 1 mo ago
Engineering$163k–$263k/yrapply on paloaltonetworks.wd5.myworkdayjobs.com

Research Security Manager

Georgia Institute of TechnologyCobb County, GA· 1 mo ago
Information Technology$106k–$180k/yrapply on careers.hprod.onehcm.usg.edu