1

Product Security Researcher Jobs (NOW HIRING)

We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system ... Collaborate across research, engineering, applied science, and product teams to deliver ...

$125 - $150/hr

Employees, researchers, customers, and partners Win Together by fostering empowerment, inclusion, respect, and accountability. Product Security AnalystRemote Locations * - Boston, MA * - Austin ...

New

Integrate AI effectively into audit workflows and develop reusable skills, agents, prompts, scripts, and processes that improve team productivity and security coverage. * Conduct open-ended research ...

We are looking for a Product Security Engineer to join our security team to drive critical product ... You will triage and validate incoming vulnerability reports from the security researcher community ...

About This Role This role is for a Web3 security researcher who can act as a public face for CertiK ... Support the marketing and feedback collection of CertiK's products and services. Requirements * 3+ ...

... Apple products. Passionate about safeguarding our users, we lead with offence proactively ... You will join a team working with world-class offensive security researchers. The work is critical ...

Senior Security Researcher

$117K - $160K/yr

Collaborate with Product and Engineering teams to translate research findings into scalable security assessment capabilities, automated testing workflows, and platform intelligence. * Cross ...

We are looking for an experienced Security Researcher II with a Digital Forensics and Incident ... and products. Researchers will support a global team to identify and catalog new attacker TTPs ...

The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen Okta ... This is a hybrid research, offensive and software engineering role centered on leveraging AI to ...

Showing results 21-40

Product Security Researcher information

See salary details

$71.5K

$173.4K

$234K

How much do product security researcher jobs pay per year?

As of Sep 9, 2026, the average yearly pay for product security researcher in the United States is $173,361.00, according to ZipRecruiter salary data. Most workers in this role earn between $155,000.00 and $190,500.00 per year, depending on experience, location, and employer.

What are popular job titles related to Product Security Researcher jobs?

For Product Security Researcher jobs, the most frequently searched job titles are:

Infographic showing various Product Security Researcher job openings in the United States as of August 2026, with employment types broken down into 80% Full Time, 17% Part Time, 2% Contract, and 1% Nights. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $173,361 per year, or $83.3 per hour.

Principal Security Researcher

Redmond, WA • On-site

Microsoft
Computer and Computer Peripheral Equipment and Software Wholesalers • 10K+ employees

Full-time

Re-posted 21 days ago


Microsoft rating

8.6

Company rating: 8.6 out of 10

Based on 134 frontline employees who took The Breakroom Quiz

71st of 247 rated software companies


Job description

Overview
The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable. We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution. You will combine deep vulnerability research with AI experimentation: researching vulnerability classes and language ecosystems, identifying representative evaluation targets, building and reviewing ground truth, analyzing missed and incorrect findings, and developing improvements that measurably increase recall, precision, consistency, and fix quality. We are looking for a hands-on vulnerability researcher who can read unfamiliar code, trace attacker-controlled data to security-sensitive operations, develop and use fuzzers and other analysis tools, reproduce vulnerabilities, assess exploitability and reachability, and determine whether a proposed fix addresses the underlying weakness. You will carry research from hypothesis through implementation and measurement, directly building and evaluating improvements to MDASH's agents, tools, model configurations, and analysis methods while collaborating with engineering and applied science partners.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
  • Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures to discover and validate vulnerabilities, assess reachability and exploitability, evaluate fixes for security correctness, and identify opportunities to expand MDASH coverage.
  • Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods, and measure their impact.
  • Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation.
  • Drive MDASH's eval-driven development and hill-climbing loop by running evaluations, uncovering patterns in missed and incorrect results, and creating adversarial and regression cases that turn blind spots into measurable capability gains.
  • Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement.
  • Provide technical leadership across the MDASH security research team by shaping research direction, leading complex investigations, mentoring other researchers, and raising the quality of vulnerability research and implementation.
  • Collaborate across research, engineering, applied science, and product teams to deliver improvements, communicate results, and influence technical direction.

Other
Embody our Culture and Values
Qualifications
Required/minimum qualifications
Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.
Other Requirements
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:
- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Additional or preferred qualifications
  • Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience.
  • 8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work.
  • Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness.
  • Experience with fuzzing and at least one additional vulnerability research technique, such as manual code review, static analysis, dynamic analysis, debugging, reverse engineering, symbolic execution, taint analysis, or exploit development.
  • Proficiency developing security research tooling or automation in one or more programming languages.
  • Experience communicating complex technical findings through clear written reports, vulnerability analyses, or presentations.
  • Deep knowledge of multiple vulnerability classes and their exploitation patterns, including memory corruption, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws.
  • Experience building fuzzing harnesses, custom mutators, sanitizers, coverage-guided fuzzing workflows, or large-scale fuzzing infrastructure.
  • Experience analyzing vulnerabilities across multiple programming languages and ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications.
  • Experience constructing security benchmarks, curating ground truth, measuring recall, precision, consistency, or remediation efficacy, and translating root-cause analysis into generalized improvements.
  • Experience building and improving AI agents or agentic systems using large language models, including prompt and tool orchestration, model evaluation, automated grading, or reinforcement learning for security tasks.
  • Experience with static application security testing, software composition analysis, SARIF, secure development lifecycle practices, or developer remediation workflows.
  • Record of vulnerability disclosures, security advisories, CVEs, research publications, conference presentations, open-source security tools, or substantive contributions to the security community.

Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

What Microsoft employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Microsoft logo

About Microsoft

Sourced by ZipRecruiter

Our infrastructure is comprised of a large global portfolio of more than 100 datacenters and 1 million servers. Our foundation is built upon and managed by a team of subject matter experts working to support services for more than 1 billion customers and 20 million businesses in over 90 countries worldwide. With environmental sustainability and optimization at the forefront of our datacenter design and operations, we continue to grow and evolve as we meet the ever-changing business demands that hold Microsoft as a world-class cloud provider.

Industry

Computer and computer peripheral equipment and software wholesalers

Company size

10,000+ Employees

Headquarters location

Redmond, WA, US

Year founded

1975

Social media