This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role focuses on advancing state-of-the-art vulnerability research through a combination of deep systems expertise and AI-driven innovation. The position drives the development of scalable approaches for vulnerability discovery, validation, and exploitation, enabling high-impact security outcomes across Microsoft’s products and the broader open-source ecosystem. Operating at the intersection of security and AI, the role emphasizes translating cutting-edge research into practical, end-to-end systems that deliver measurable improvements in security coverage, speed, and reliability.
Job Responsibility
Technical Leadership in Vulnerability Research
Leads advanced vulnerability research across diverse software systems
Designs and develops scalable security analysis methodologies
Drives systematic identification, validation, and root-cause understanding of vulnerabilities
Shapes research direction and technical strategy for the team
Mentors engineers and elevates overall technical rigor
Translates research findings into real-world security impact across Microsoft and open-source ecosystems
AI-Driven Bug Finding and Exploit Generation
Develops AI-powered systems for automated bug discovery and validation
Improves precision, coverage, and reliability of vulnerability detection
Drives exploit generation and proof-of-concept (PoC) validation
Ensures findings are actionable, reproducible, and security-impacting
Builds end-to-end pipelines from detection to confirmed vulnerabilities
Advances scalable security analysis at the intersection of AI and systems security
Requirements
Proven expertise in vulnerability research, including identifying, analyzing, and validating complex software vulnerabilities
Strong systems background (e.g., OS internals, compilers, networking, or distributed systems)
Experience with exploit development and proof-of-concept validation
Demonstrated experience building or applying AI/ML techniques to security problems (e.g., bug finding, program analysis, fuzzing)
Ability to design and implement scalable security analysis systems or pipelines
Strong programming skills (e.g., C/C++, Python, Rust, or similar)
Track record of impactful security contributions (e.g., CVEs, research publications, or production systems)
Ability to translate research ideas into practical tools or product-ready capabilities
Strong collaboration and leadership skills, including mentoring and cross-team influence