Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
- Conduct cutting-edge security research to discover, validate, and analyze vulnerabilities across Microsoft products, cloud services, and strategic open-source ecosystems.
- Design and develop scalable automation, AI-driven systems, and research tooling that accelerate vulnerability discovery, triage, and remediation workflows.
- Collaborate closely with engineering, product, and security teams to drive vulnerability mitigation, improve security posture, and reduce customer risk.
- Lead or contribute to offensive security assessments that identify emerging threat patterns, novel attack techniques, and systemic security weaknesses.
- Publish high-quality technical findings, influence in open source projects or large-scale software systems.
Qualifications
Required Qualifications:
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR equivalent experience.
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR equivalent experience.
- Demonstrated experience in vulnerability research, vulnerability discovery, exploit development, reverse engineering, or offensive security research, including publicly disclosed CVEs or security advisories.
- Participation in recognized security competitions or research programs, such as Capture The Flag (CTF), DARPA AI Cyber Challenge (AIxCC), Pwn2Own, or similar offensive security initiatives.
#MSFTSecurity #AIxCC #FORGE
Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or a related field plus 3 or more years of experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, or anomaly detection
- Master's degree in Statistics, Mathematics, Computer Science, Computer Security, or a related field plus 4 or more years of relevant experience
- Bachelor's degree in Statistics, Mathematics, Computer Science, Computer Security, or a related field plus 6 or more years of relevant experience
- Equivalent experience may substitute for the stated education and experience combinations
- Ability to meet Microsoft, customer, and/or government security screening requirements
- Doctorate in a relevant field plus 5 or more years of relevant experience
- Master's degree in a relevant field plus 8 or more years of relevant experience
- Bachelor's degree in a relevant field plus 12 or more years of relevant experience
- Demonstrated experience in vulnerability research, vulnerability discovery, exploit development, reverse engineering, or offensive security research, including publicly disclosed CVEs or security advisories
- Participation in recognized security competitions or research programs such as CTF, DARPA AI Cyber Challenge, or Pwn2Own
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.







