1

Security Researcher Jobs in Seattle, WA (NOW HIRING)

We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution. You will combine deep ...

We are looking for an experienced Senior Security Researcher with a analytical background to join our team to perform threat hunts, assist with investigations, develop threat intelligence, and to ...

AI Security Researcher II

Redmond, WA · On-site

$102K - $202K/yr

Do you have research experience in AI security, adversarial machine learning, security for AI, and/or the study of agentic AI systems? Do you want to investigate how autonomous, tool-using, and multi ...

AI Security Researcher II

Redmond, WA · On-site

$102K - $202K/yr

Do you have research experience in AI security, adversarial machine learning, security for AI, and/or the study of agentic AI systems? Do you want to investigate how autonomous, tool-using, and multi ...

The Microsoft Security Research (MSecR) Purple Team sits at the intersection of offense, defense, and intelligence. AI is now everywhere: organizations and people across every industry are adopting ...

Apple's Security Engineering & Architecture organization is responsible for the security of all ... Join our extraordinary team of security researchers and help protect all Apple users. Description ...

Senior Security Researchers

Redmond, WA · On-site

$160K - $261K/yr

Responsibilities As a Senior Security Researcher, you will: * Research emerging attack vectors and techniques. * Analyze detection and prevention gaps and understand root cause. * Design and develop ...

Senior Director, Community

Seattle, WA · On-site

$210K - $302K/yr

The HackerOne Platform unites agentic AI solutions with the ingenuity of the world's largest community of security researchers to continuously discover, validate, prioritize, and remediate exposures ...

This includes conducting large-scale vulnerability research, security assessments, attack surface analysis, code auditing, fuzzing, exploitability analysis, and emerging threat investigations. We ...

next page

Showing results 1-20

Security Researcher information

See Seattle, WA salary details

$54

$58

$61

How much do security researcher jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for security researcher in Seattle, WA is $58.54, according to ZipRecruiter salary data. Most workers in this role earn between $56.63 and $60.48 per hour, depending on experience, location, and employer.

What is a security researcher?

A security researcher keeps up-to-date on all the latest developments in threats to computer software and networks. These threats include different types of malware, such as computer viruses, malicious software and scripts, and direct attacks on a network. The main duties of a security researcher are to investigate existing types of malware, analyze their capabilities, and attempt to predict new forms of malware to develop appropriate security responses. They may reverse engineer malware or test security systems.

What is the difference between Security Researcher vs Security Analyst?

AspectSecurity ResearcherSecurity Analyst
CredentialsCertifications like CISSP, CEH, OSCPCertifications like CompTIA Security+, CISSP, GIAC
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT teams
Employer & IndustryTech companies, cybersecurity firms, government agenciesFinancial institutions, healthcare, enterprise companies
Primary FocusIdentifying vulnerabilities, developing exploits, analyzing threatsMonitoring security systems, incident response, implementing security measures

While both roles focus on cybersecurity, Security Researchers primarily analyze vulnerabilities and develop exploits to understand threats better. Security Analysts focus on monitoring, detecting, and responding to security incidents within organizations. Both roles often require similar certifications and work in related environments, but their core responsibilities differ in scope and daily tasks.

What are the key skills and qualifications needed to thrive as a security researcher, and why are they important?

To thrive as a Security Researcher, you need deep expertise in computer science, networking, vulnerability assessment, and malware analysis, often supported by a degree in cybersecurity or related fields. Familiarity with tools like IDA Pro, Wireshark, Metasploit, and certifications such as OSCP or CEH is highly valued. Analytical thinking, curiosity, and strong written and verbal communication help distinguish top performers in this role. These skills are crucial for identifying emerging threats, effectively communicating risks, and developing solutions to protect organizations' digital assets.

What are some common challenges security researchers face when collaborating with development teams?

Security Researchers often encounter challenges when working with development teams, such as communicating complex vulnerabilities in a way that is actionable for developers and aligning on remediation priorities. Bridging the gap between security findings and practical implementation requires clear documentation and a collaborative mindset. Additionally, researchers must balance thorough testing with minimal disruption to production environments, ensuring security improvements integrate smoothly into development cycles.
What are the most commonly searched types of Security Researcher jobs in Seattle, WA? The most popular types of Security Researcher jobs in Seattle, WA are:
What are popular job titles related to Security Researcher jobs in Seattle, WA? For Security Researcher jobs in Seattle, WA, the most frequently searched job titles are:
What job categories do people searching Security Researcher jobs in Seattle, WA look for? The top searched job categories for Security Researcher jobs in Seattle, WA are:
Infographic showing various Security Researcher job openings in Seattle, WA as of August 2026, with employment types broken down into 86% Full Time, 6% Part Time, and 8% Contract. Highlights an 77% In-person, and 23% Remote job distribution, with an average salary of $121,768 per year, or $58.5 per hour.

Principal Security Researcher

Microsoft Corporation

Redmond, WA • On-site

Other

Re-posted 8 days ago


Microsoft rating

8.5

Company rating: 8.5 out of 10

Based on 132 frontline employees who took The Breakroom Quiz

78th of 242 rated software companies


Job description

Overview

The MDASH team is advancing how organizations discover and resolve vulnerabilities in source code. MDASH uses a multi-agent, multi-model system to analyze code, validate whether potential vulnerabilities are real and reachable, and provide developers with concrete fixes and guidance for verifying that code is no longer vulnerable. We are seeking a Principal Security Researcher to build and improve the AI-powered, agentic system at the heart of MDASH vulnerability discovery, validation, and resolution. You will combine deep vulnerability research with AI experimentation: researching vulnerability classes and language ecosystems, identifying representative evaluation targets, building and reviewing ground truth, analyzing missed and incorrect findings, and developing improvements that measurably increase recall, precision, consistency, and fix quality. We are looking for a hands-on vulnerability researcher who can read unfamiliar code, trace attacker-controlled data to security-sensitive operations, develop and use fuzzers and other analysis tools, reproduce vulnerabilities, assess exploitability and reachability, and determine whether a proposed fix addresses the underlying weakness. You will carry research from hypothesis through implementation and measurement, directly building and evaluating improvements to MDASH's agents, tools, model configurations, and analysis methods while collaborating with engineering and applied science partners.

Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures to discover and validate vulnerabilities, assess reachability and exploitability, evaluate fixes for security correctness, and identify opportunities to expand MDASH coverage.

  • Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods, and measure their impact.

  • Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation.

  • Drive MDASH's eval-driven development and hill-climbing loop by running evaluations, uncovering patterns in missed and incorrect results, and creating adversarial and regression cases that turn blind spots into measurable capability gains.

  • Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement.

  • Provide technical leadership across the MDASH security research team by shaping research direction, leading complex investigations, mentoring other researchers, and raising the quality of vulnerability research and implementation.

  • Collaborate across research, engineering, applied science, and product teams to deliver improvements, communicate results, and influence technical direction.

Other

Embody our Culture and Values

Qualifications

Required/minimum qualifications

Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.

Other Requirements

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:

  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Additional or preferred qualifications

  • Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience.

  • 8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work.

  • Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness.

  • Experience with fuzzing and at least one additional vulnerability research technique, such as manual code review, static analysis, dynamic analysis, debugging, reverse engineering, symbolic execution, taint analysis, or exploit development.

  • Proficiency developing security research tooling or automation in one or more programming languages.

  • Experience communicating complex technical findings through clear written reports, vulnerability analyses, or presentations.

  • Deep knowledge of multiple vulnerability classes and their exploitation patterns, including memory corruption, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws.

  • Experience building fuzzing harnesses, custom mutators, sanitizers, coverage-guided fuzzing workflows, or large-scale fuzzing infrastructure.

  • Experience analyzing vulnerabilities across multiple programming languages and ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications.

  • Experience constructing security benchmarks, curating ground truth, measuring recall, precision, consistency, or remediation efficacy, and translating root-cause analysis into generalized improvements.

  • Experience building and improving AI agents or agentic systems using large language models, including prompt and tool orchestration, model evaluation, automated grading, or reinforcement learning for security tasks.

  • Experience with static application security testing, software composition analysis, SARIF, secure development lifecycle practices, or developer remediation workflows.

  • Record of vulnerability disclosures, security advisories, CVEs, research publications, conference presentations, open-source security tools, or substantive contributions to the security community.

Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations. (https://careers.microsoft.com/v2/global/en/accessibility.html)


What Microsoft employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Microsoft logo

About Microsoft

Sourced by ZipRecruiter

Our infrastructure is comprised of a large global portfolio of more than 100 datacenters and 1 million servers. Our foundation is built upon and managed by a team of subject matter experts working to support services for more than 1 billion customers and 20 million businesses in over 90 countries worldwide. With environmental sustainability and optimization at the forefront of our datacenter design and operations, we continue to grow and evolve as we meet the ever-changing business demands that hold Microsoft as a world-class cloud provider.

Industry

Computer and computer peripheral equipment and software wholesalers

Company size

10,000+ Employees

Headquarters location

Redmond, WA, US

Year founded

1975

Social media