hero

The #1 Source for
In-Person NYC Tech Jobs

Build your future in the capital of everything.
Obviously New York.
companies
Jobs

Principal Security Researcher - Purple Team Lead

Microsoft

Microsoft

USD 139,900-274,800 / year
Posted on Jun 5, 2025

Principal Security Researcher – Purple Team Lead

Multiple Locations, United States

Save

Share job

Date posted
Jun 04, 2025
Job number
1828285
Work site
Up to 100% work from home
Travel
0-25 %
Role type
Individual Contributor
Profession
Security Engineering
Discipline
Security Research
Employment type
Full-Time

Overview

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.

We are seeking a Principal Security Researcher to lead offensive security and purple team initiatives within Microsoft’s Threat Protection organization. This role is ideal for a seasoned security expert who thrives at the intersection of red and blue teaming, and who is passionate about using adversary simulation, detection engineering, and AI-driven insights to protect billions of users. You will play a key role in building and scaling a Purple Team hub, driving high-impact engagements that test and improve Microsoft Defender’s detection and response capabilities.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Qualifications

Required/Minimum Qualifications:

  • 7+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
    • OR Doctorate in Statistics, Mathematics, Computer Science or related field.
  • 7+ years in cybersecurity, with deep experience in red teaming, detection engineering, or threat research.
  • Proven leadership in offensive security or purple team operations and proficient knowledge of MITRE ATT&CK, adversary TTPs, and detection frameworks.
  • Experience in scripting (Python, PowerShell) and familiarity with attack simulation tools (e.g., Caldera, Atomic Red Team).
  • Experience with SIEM/EDR platforms (Microsoft Sentinel, Defender, etc.).

Other Requirements:

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Additional or Preferred Qualifications:

  • 8+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
    • OR Doctorate in Statistics, Mathematics, Computer Science or related field

Security Research IC5 - The typical base pay range for this role across the U.S. is USD $139,900 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

Microsoft will accept applications for the role until June 9, 2025.

#MSFTSecurity #OffensiveSecurity #PurpleTeam #SecurityResearch #CyberThreats #AdversaryEmulation

Responsibilities

  • Lead the design and execution of advanced adversary emulation campaigns.
  • Build and mentor a high-performing purple team focused on offensive testing and detection validation.
  • Collaborate with red teams, detection engineers, and threat intelligence teams to identify and close detection gaps.
  • Apply generative AI and LLMs to simulate attacker behavior and enhance detection logic.
  • Translate offensive findings into actionable improvements across Microsoft Defender and Sentinel.
  • Contribute to internal tooling, automation, and knowledge sharing across the security organization.
  • Embody our culture and values


Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.