MNC InsiderMNC Insider
Microsoft logo

Principal Security Research Manager

Microsoft

Principal Security Research Manager

full-timePosted: Aug 4, 2026Updated: Aug 27, 2026Redmond, WA, US

Job Description

OverviewThe MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable. We are seeking a Principal Security Research Manager to lead the team responsible for the security research and evaluation that advance MDASH's vulnerability discovery, validation, and remediation capabilities. This team shapes how MDASH finds vulnerabilities across programming languages, vulnerability classes, and codebase types; determines whether findings are valid and actionable; and improves the quality of generated fixes. The team owns the eval-driven development and hill-climbing loop: identifying representative evaluation targets, curating trusted ground truth, analyzing failures, and turning those insights into measurable improvements in vulnerability discovery, validation, and fix quality. The ideal candidate combines deep expertise in vulnerability research and application security with demonstrated success leading highly technical teams. You will set the research and measurement strategy, develop security researchers, and partner across research, engineering, applied science, and product teams to turn evidence into measurable improvements for customers. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.ResponsibilitiesLead, mentor, and develop a team of security researchers responsible for MDASH vulnerability discovery, validation, fix generation, and quality measurement. Define the research and quality roadmap for expanding MDASH coverage across vulnerability classes, programming languages, frameworks, codebase sizes, and real-world development patterns.Establish measurable quality goals and decision criteria across recall, precision, consistency, vulnerability validation, fix correctness, and end-to-end resolution. Direct the creation and curation of representative evaluation suites and trusted ground truth drawn from purpose-built vulnerable code, public benchmarks, open-source projects, internal codebases, and production feedback, ensuring the portfolio reflects real-world customer scenarios and guides measurable improvement in MDASH. Lead systematic analysis of false negatives, false positives, inconsistent detections, validation failures, and ineffective or incorrect fixes; translate findings into prioritized improvements to the techniques, tools, agent behaviors, model configurations, and analysis methods that power MDASH. Partner with MDASH engine, evaluation infrastructure, model, applied science, and product teams to integrate research improvements, establish release gates, and connect offline measurements with customer outcomes. Communicate technical strategy, evaluation results, risks, and investment priorities to senior leaders and cross-functional partners. Model Microsoft values and foster an inclusive environment in which researchers can do their best work, grow their expertise, and take accountability for customer outcomes.OtherEmbody our Culture and Values QualificationsRequired/minimum qualificationsMaster's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.3+ years people management.Other RequirementsAbility to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.Additional or preferred qualifications Deep knowledge of vulnerability classes and exploitation patterns, including memory safety, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws. Experience with manual code review, static or dynamic analysis, fuzzing, symbolic execution, taint analysis, exploit development, or variant analysis. Experience designing security benchmarks, curating ground truth, calibrating evaluators, and measuring recall, precision, false-positive rates, or fix efficacy. Experience evaluating or building AI-assisted security systems, large language model applications, AI agents, automated graders, or human-in-the-loop evaluation workflows. Experience working across multiple programming languages and software ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications. Experience with responsible vulnerability disclosure or collaboration with open-source maintainers and product security response teams. Security Research M6 - The typical base pay range for this role across the U.S. is USD $165,600 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:https://careers.microsoft.com/us/en/us-corporate-payThis position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Locations

  • Redmond, WA, US

Salary

165,600 - 296,400 USD / yearly

Skills Required

  • vulnerability classesintermediate
  • manual code reviewintermediate
  • responsible vulnerability disclosureintermediate

Required Qualifications

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter. (experience)

Preferred Qualifications

  • Deep knowledge of vulnerability classes and exploitation patterns, including memory safety, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws. (experience)
  • Experience with manual code review, static or dynamic analysis, fuzzing, symbolic execution, taint analysis, exploit development, or variant analysis. (experience)
  • Experience designing security benchmarks, curating ground truth, calibrating evaluators, and measuring recall, precision, false-positive rates, or fix efficacy. (experience)
  • Experience evaluating or building AI-assisted security systems, large language model applications, AI agents, automated graders, or human-in-the-loop evaluation workflows. (experience)
  • Experience working across multiple programming languages and software ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications. (experience)
  • Experience with responsible vulnerability disclosure or collaboration with open-source maintainers and product security response teams. (experience)
  • Security Research M6 - The typical base pay range for this role across the U.S. is USD $165,600 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year. (experience)
  • Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:https://careers.microsoft.com/us/en/us-corporate-pay (experience)
  • This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. (experience)

Responsibilities

  • Lead, mentor, and develop a team of security researchers responsible for MDASH vulnerability discovery, validation, fix generation, and quality measurement.
  • Define the research and quality roadmap for expanding MDASH coverage across vulnerability classes, programming languages, frameworks, codebase sizes, and real-world development patterns.
  • Establish measurable quality goals and decision criteria across recall, precision, consistency, vulnerability validation, fix correctness, and end-to-end resolution.
  • Direct the creation and curation of representative evaluation suites and trusted ground truth drawn from purpose-built vulnerable code, public benchmarks, open-source projects, internal codebases, and production feedback, ensuring the portfolio reflects real-world customer scenarios and guides measurable improvement in MDASH.
  • Lead systematic analysis of false negatives, false positives, inconsistent detections, validation failures, and ineffective or incorrect fixes; translate findings into prioritized improvements to the techniques, tools, agent behaviors, model configurations, and analysis methods that power MDASH.
  • Partner with MDASH engine, evaluation infrastructure, model, applied science, and product teams to integrate research improvements, establish release gates, and connect offline measurements with customer outcomes.
  • Communicate technical strategy, evaluation results, risks, and investment priorities to senior leaders and cross-functional partners.
  • Model Microsoft values and foster an inclusive environment in which researchers can do their best work, grow their expertise, and take accountability for customer outcomes.
  • Embody our Culture and Values

Benefits

  • general: Flexibility: Balance what matters—your work, your life, and your team—through trust, autonomy, and shared accountability
  • general: Growth: Stretch your skills, expand your impact, and grow with support that meets you where you are
  • general: Wellbeing: Support for your body, mind, and financial future—so you can stay energized and do your best work
  • general: Community PCS: Find your people, build your network, and feel supported every step of the way

Travel Requirements

Less than 25%

Target Your Resume for "Principal Security Research Manager" , Microsoft

Get personalized recommendations to optimize your resume specifically for Principal Security Research Manager. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Principal Security Research Manager" , Microsoft

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

Security ResearchSecurity EngineeringSecurity ResearchSecurity Engineering

Answer 10 quick questions to check your fit for Principal Security Research Manager @ Microsoft.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.