Security Researcher

Microsoft
U.S. / San Francisco Bay area / New York City metropolitan area2026-08-06onsite

About the job

Are you a red teamer who is looking to break into the AI field? Do you want to find AI failures in Microsoft’s largest AI systems and models impacting millions of users? Join Microsoft’s AI Red Team where you'll emulate work alongside security experts to test for security and safety failures. We are looking for a Security Researcher with demonstrated cybersecurity and agents testing experience for our team. Our mission is to innovate cutting edge AI testing techniques while stress testing the highest risk AI models, products, and systems. We help our customers, AI makers, expand and strengthen AI security defenses by red teaming prior to launch, coaching developers on how to mitigate when we find in testing environments to make AI safer for all. This work is sprint based, working with AI Safety, Security, and Product Development teams, to run operations that aim to find safety and security risks that inform internal key business decisions. In this role, you will red team AI frontier and foundational models plus applications across Microsoft’s AI portfolio including Bing Copilot, Security Copilot, Github Copilot, Office Copilot and Windows Copilot. Our team is an interdisciplinary group of red teamers, adversarial Machine Learning (ML) researchers, Safety & Responsible AI experts and software developers. Our scope is high visibility, with customers ranging from the Office of the CTO to lead AI model builders. We look for creative problem solvers, customer-obsessed coaches, high adaptability, task oriented applied researchers, who like to explore AI question with hands on experimentation.

Responsibilities

Discover and exploit GenAI security vulnerabilities end-to-end in order to assess AI systems and models

Manage product group stakeholders as priority recipients and collaborators for operational sprints

Drive clarity on communication and reporting for red teaming peers when working with product groups

Develop methodologies and techniques to scale and accelerate AI Red Teaming in new and emerging threat areas

Work alongside traditional offensive security engineers, adversarial ML experts, developers to land responsible AI operations

Embody our culture and values

Qualifications

Minimum

Bachelor's Degree in Statistics, Econometrics, Computer Science, Electrical or Computer Engineering, or related field AND 2+ years related experience (e.g., statistics, predictive analytics, research) OR Master's Degree in Statistics, Econometrics, Computer Science, Electrical or Computer Engineering, or related field AND 1+ year(s) related experience (e.g., statistics, predictive analytics, research) OR Doctorate in Statistics, Econometrics, Computer Science, Electrical or Computer Engineering, or related field OR equivalent experience.

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:

- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred

Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.

Penetration testing qualifications; GPEN/GXPN, GWAPT, OSCP/OSCE, CRT/CCT/CCSAS

Participation in bug bounties/CTFs

Experience of using common penetration testing tools; Kali Linux, Burpsuite, Nmap, Nessus, etc

Familiarity with one or more programming languages from: Python, C#, C/C++, PowerShell

Prior knowledge of Generative AI not required, though experience testing agents is preferred, while basic familiarity with AI or willingness to learn is desired