{"id":1671173,"url":"https://alion.io/job/microsoft-security-research-engineer-project-perception","title":"Security Research Engineer - Project Perception","company":{"id":18,"name":"Microsoft","domain":"microsoft.com","url":"https://alion.io/company/microsoft","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Eightfold","truth_index":{"grade":"B","score":75,"open_postings":44,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-05T05:45:15Z"}},"role":"AI/ML","role_family":"AI/ML","seniority":"staff","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":119800,"max":234700,"currency":"USD","period":"year","gross":null,"usd_annual":234700},"salary_estimate":null,"experience_years_min":12,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Reinforcement Learning","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"C#","optional":true},{"name":"C++","optional":true},{"name":"GCP","optional":true},{"name":"Go","optional":true},{"name":"IAM","optional":true},{"name":"Linux","optional":true},{"name":"Python","optional":true},{"name":"TypeScript","optional":true},{"name":"Windows","optional":true}],"status":"live","first_seen_at":"2026-10-01T18:55:10Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-06T00:57:15Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"OverviewSecurity represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end-to-end, simplified solutions. The Microsoft Security organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.\nOur team turns real vulnerabilities and adversary behavior into reproducible tasks that models and agents can learn from and be evaluated against. Reliable grading and reward signals are central to this work: success must reflect a verified security outcome, not simply a convincing response.\nWe are looking for several Principal and Senior Security Research Engineers to build realistic, safely contained attack scenarios across cloud, on-premises, and hybrid environments. You will combine hands-on security research with software engineering to reproduce vulnerable conditions, construct representative multi-step attack chains, and implement checks that establish what actually happened. Your scenarios will support reinforcement learning for Microsoft’s MAI family of models and evaluation of security Perception agents and the software harnesses that run them. Working with threat researchers, AI engineers, and environment engineers, you will test whether systems can distinguish threats from benign activity, connect evidence across an attack chain, and identify effective responses. You will own scenarios from research through implementation and grading, adapting them as attacker techniques evolve. Your work will give teams trustworthy training signals and concrete evidence of whether model, agent, or harness changes improve security capabilities that matter to customers.\nCandidates residing within commuting distance of the Redmond or Reston hub are required to work on-site under a hybrid work arrangement, in accordance with Microsoft’s and the team’s in-office requirements for these designated locations.\nMicrosoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. \nResponsibilities\nTurn threat research into working scenarios, reproducing real vulnerabilities and emerging adversary techniques in cloud, on-premises, and hybrid environments.\n\nBuild realistic attack chains.\n\nConnect vulnerable applications, identity weaknesses, and misconfigurations into multi-step scenarios with verified prerequisites and observable security impact.\n\nMake outcomes verifiable.\n\nBuild automated graders and reward signals grounded in system state and telemetry, distinguishing agent success, effective defenses, and environment failures.\n\nEvaluate beyond familiar patterns.\n\nCreate attack variants, benign lookalikes, and patched controls that expose missed threats, false positives, and memorization.\n\nDeliver safe, reusable research.\n\nOwn scenario code, isolation, evidence capture and reset; partner with AI and environment engineers to turn findings into better training and evaluation.\n\nQualifications\nMinimum Qualifications:\nDoctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.\nOR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.\nOR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.\nOR equivalent experience.\nOther Requirements:\nAbility to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:\nMicrosoft Cloud Background Check:\nThis position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.\nPreferred Qualifications:\nDoctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.\nOR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.\nOR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.\nOR equivalent experience.\n5+ years of experience researching vulnerabilities, conducting authorized offensive security tests, investigating security incidents, or developing security tools.\n3+ years of experience developing and debugging security tools or scenario automation in Python, C#, Go, C/C++, or TypeScript, using version control and automated tests.\nExperience independently reproducing a vulnerability or adversary technique and documenting its prerequisites, reproduction steps, and observed security impact.\nExperience building or validating multi-step attack chains across applications, identities, or hosts, including the access requirements and evidence for each step.\nExperience assessing cloud IAM in Azure, AWS, or GCP and testing authentication, permissions, or network access in Windows or Linux environments.\nExperience confirming or rejecting security findings through source-code review, telemetry, or controlled tests, including checking whether existing safeguards prevent the claimed impact.\nExperience running authorized security tests with isolated targets, lab-only credentials, execution limits, and cleanup procedures.\nReconstructed attacks from incident evidence or threat reports for red-team, purple-team, or adversary-emulation exercises.\nReproduced attack paths across cloud and on-premises identity systems involving federation, service principals, workload identities, or directory services.\nUsed source-code analysis, debugging, or reverse engineering to identify a vulnerability's root cause and verify a fix.\nBuilt automated graders or reward functions that check system state and telemetry, including checks that distinguish scenario failures from agent failures.\nCreated attack variants, benign comparison cases, patched scenarios, or simulated user activity to test detection accuracy and false positives.\n#MSFTSecurity #Cybersecurity #SecurityResearch #AgentSecurity #AgenticEvals #Perception\nSecurity Research IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.\nCertain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:\nhttps://careers.microsoft.com/us/en/us-corporate-pay\nSecurity Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.\nCertain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:\nhttps://careers.microsoft.com/us/en/us-corporate-pay\nThis position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.\nMicrosoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.","description_format":"text","description_chars":9839,"description_truncated":false,"requirements":{"experience_years_min":12,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["Hybrid work"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Console Games","Gaming Consoles","Information Security","Developer Tools"],"lifecycle":[{"event":"open","at":"2026-10-02T06:34:06Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":3,"expected_fill_days":28,"reasons":["conf:1","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-10-05T05:45:15Z"},"pay":{"stated_usd_annual":234700,"is_top_pay":false},"html_url":"https://alion.io/job/microsoft-security-research-engineer-project-perception","json_url":"https://alion.io/job/microsoft-security-research-engineer-project-perception.json","meta":{"generated_at":"2026-10-06T02:46:31Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4176,"day_limit":5000,"remaining_today":824,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":18},"rest":"https://alion.io/mcp/rest/get_company?id=18"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fmicrosoft-security-research-engineer-project-perception"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fmicrosoft-security-research-engineer-project-perception"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fmicrosoft-security-research-engineer-project-perception"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/microsoft-security-research-engineer-project-perception\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fmicrosoft-security-research-engineer-project-perception"}]}