Overview
Working with threat researchers, AI engineers, and environment engineers, you will test whether systems can distinguish threats from benign activity, connect evidence across an attack chain, and identify effective responses. Turn threat research into working scenarios, reproducing real vulnerabilities and emerging adversary techniques in cloud, on-premises, and hybrid environments. Build realistic attack chains. Connect vulnerable applications, identity weaknesses, and misconfigurations into multi-step scenarios with verified prerequisites and observable security impact. Make outcomes verifiable. Build automated graders and reward signals grounded in system state and telemetry, distinguishing agent success, effective defenses, and environment failures. Evaluate beyond familiar patterns. Create attack variants, benign lookalikes, and patched controls that expose missed threats, false posi
Full job description
Full Job Description
Working with threat researchers, AI engineers, and environment engineers, you will test whether systems can distinguish threats from benign activity, connect evidence across an attack chain, and identify effective responses. Turn threat research into working scenarios, reproducing real vulnerabilities and emerging adversary techniques in cloud, on-premises, and hybrid environments. Build realistic attack chains. Connect vulnerable applications, identity weaknesses, and misconfigurations into multi-step scenarios with verified prerequisites and observable security impact. Make outcomes verifiable. Build automated graders and reward signals grounded in system state and telemetry, distinguishing agent success, effective defenses, and environment failures. Evaluate beyond familiar patterns. Create attack variants, benign lookalikes, and patched controls that expose missed threats, false positives, and memorization. Deliver safe, reusable research. Own scenario code, isolation, evidence capture and reset; partner with AI and environment engineers to turn findings into better training and evaluation. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. These requirements include, but are not limited to the following specialized security screenings: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR equivalent experience. 5+ years of experience researching vulnerabilities, conducting authorized offensive security tests, investigating security incidents, or developing security tools. 3+ years of experience developing and debugging security tools or scenario automation in Python, C#, Go, C/C++, or TypeScript, using version control and automated tests. Experience independently reproducing a vulnerability or adversary technique and documenting its prerequisites, reproduction steps, and observed security impact. Experience building or validating multi-step attack chains across applications, identities, or hosts, including the access requirements and evidence for each step. Experience assessing cloud IAM in Azure, AWS, or GCP and testing authentication, permissions, or network access in Windows or Linux environments. Experience confirming or rejecting security findings through source-code review, telemetry, or controlled tests, including checking whether existing safeguards prevent the claimed impact. Experience running authorized security tests with isolated targets, lab-only credentials, execution limits, and cleanup procedures. Reconstructed attacks from incident evidence or threat reports for red-team, purple-team, or adversary-emulation exercises. Reproduced attack paths across cloud and on-premises identity systems involving federation, service principals, workload identities, or directory services. Used source-code analysis, debugging, or reverse engineering to identify a vulnerability's root cause and verify a fix. Built automated graders or reward functions that check system state and telemetry, including checks that distinguish scenario failures from agent failures. Created attack variants, benign comparison cases, patched scenarios, or simulated user activity to test detection accuracy and false positives.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Careers →