Principal Security Research Manager

MicrosoftApplyPublished 2 hours agoFirst seen 1 hours ago
Apply
Overview

The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable. We are seeking a Principal Security Research Manager to lead the team responsible for the security research and evaluation that advance MDASH's vulnerability discovery, validation, and remediation capabilities. This team shapes how MDASH finds vulnerabilities across programming languages, vulnerability classes, and codebase types; determines whether findings are valid and actionable; and improves the quality of generated fixes. The team owns the eval-driven development and hill-climbing loop: identifying representative evaluation targets, curating trusted ground truth, analyzing failures, and turning those insights into measurable improvements in vulnerability discovery, validation, and fix quality. The ideal candidate combines deep expertise in vulnerability research and application security with demonstrated success leading highly technical teams. You will set the research and measurement strategy, develop security researchers, and partner across research, engineering, applied science, and product teams to turn evidence into measurable improvements for customers.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.


Responsibilities
  • Lead, mentor, and develop a team of security researchers responsible for MDASH vulnerability discovery, validation, fix generation, and quality measurement.
  • Define the research and quality roadmap for expanding MDASH coverage across vulnerability classes, programming languages, frameworks, codebase sizes, and real-world development patterns.
  • Establish measurable quality goals and decision criteria across recall, precision, consistency, vulnerability validation, fix correctness, and end-to-end resolution.
  • Direct the creation and curation of representative evaluation suites and trusted ground truth drawn from purpose-built vulnerable code, public benchmarks, open-source projects, internal codebases, and production feedback, ensuring the portfolio reflects real-world customer scenarios and guides measurable improvement in MDASH.
  • Lead systematic analysis of false negatives, false positives, inconsistent detections, validation failures, and ineffective or incorrect fixes; translate findings into prioritized improvements to the techniques, tools, agent behaviors, model configurations, and analysis methods that power MDASH.
  • Partner with MDASH engine, evaluation infrastructure, model, applied science, and product teams to integrate research improvements, establish release gates, and connect offline measurements with customer outcomes.
  • Communicate technical strategy, evaluation results, risks, and investment priorities to senior leaders and cross-functional partners.
  • Model Microsoft values and foster an inclusive environment in which researchers can do their best work, grow their expertise, and take accountability for customer outcomes.

Other

Embody our Culture and Values

 


Qualifications

Required/minimum qualifications

Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.

3+ years people management.

Other Requirements


Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:
- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Additional or preferred qualifications 

  • Deep knowledge of vulnerability classes and exploitation patterns, including memory safety, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws.
  • Experience with manual code review, static or dynamic analysis, fuzzing, symbolic execution, taint analysis, exploit development, or variant analysis.
  • Experience designing security benchmarks, curating ground truth, calibrating evaluators, and measuring recall, precision, false-positive rates, or fix efficacy.
  • Experience evaluating or building AI-assisted security systems, large language model applications, AI agents, automated graders, or human-in-the-loop evaluation workflows.
  • Experience working across multiple programming languages and software ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications.
  • Experience with responsible vulnerability disclosure or collaboration with open-source maintainers and product security response teams.

Security Research M6 - The typical base pay range for this role across the U.S. is USD $165,600 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.