The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable. We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution. You will combine deep vulnerability research with AI experimentation: researching vulnerability classes and language ecosystems, identifying representative evaluation targets, building and reviewing ground truth, analyzing missed and incorrect findings, and developing improvements that measurably increase recall, precision, consistency, and fix quality. We are looking for a hands-on vulnerability researcher who can read unfamiliar code, trace attacker-controlled data to security-sensitive operations, develop and use fuzzers and other analysis tools, reproduce vulnerabilities, assess exploitability and reachability, and determine whether a proposed fix addresses the underlying weakness. You will carry research from hypothesis through implementation and measurement, directly building and evaluating improvements to MDASH's agents, tools, model configurations, and analysis methods while collaborating with engineering and applied science partners. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Principal