Principal Security Researcher - Purple Team Lead
Microsoft
This job is no longer accepting applications
See open jobs at Microsoft.See open jobs similar to "Principal Security Researcher - Purple Team Lead" Tech:NYC.Principal Security Researcher – Purple Team Lead
Multiple Locations, United States
Save
Overview
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
We are seeking a Principal Security Researcher to lead offensive security and purple team initiatives within Microsoft’s Threat Protection organization. This role is ideal for a seasoned security expert who thrives at the intersection of red and blue teaming, and who is passionate about using adversary simulation, detection engineering, and AI-driven insights to protect billions of users. You will play a key role in building and scaling a Purple Team hub, driving high-impact engagements that test and improve Microsoft Defender’s detection and response capabilities.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Qualifications
Required/Minimum Qualifications:
- 7+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
- OR Doctorate in Statistics, Mathematics, Computer Science or related field.
- 7+ years in cybersecurity, with deep experience in red teaming, detection engineering, or threat research.
- Proven leadership in offensive security or purple team operations and proficient knowledge of MITRE ATT&CK, adversary TTPs, and detection frameworks.
- Experience in scripting (Python, PowerShell) and familiarity with attack simulation tools (e.g., Caldera, Atomic Red Team).
- Experience with SIEM/EDR platforms (Microsoft Sentinel, Defender, etc.).
Other Requirements:
- Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Additional or Preferred Qualifications:
- 8+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
- OR Doctorate in Statistics, Mathematics, Computer Science or related field
Security Research IC5 - The typical base pay range for this role across the U.S. is USD $139,900 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications for the role until June 9, 2025.
#MSFTSecurity #OffensiveSecurity #PurpleTeam #SecurityResearch #CyberThreats #AdversaryEmulation
Responsibilities
- Lead the design and execution of advanced adversary emulation campaigns.
- Build and mentor a high-performing purple team focused on offensive testing and detection validation.
- Collaborate with red teams, detection engineers, and threat intelligence teams to identify and close detection gaps.
- Apply generative AI and LLMs to simulate attacker behavior and enhance detection logic.
- Translate offensive findings into actionable improvements across Microsoft Defender and Sentinel.
- Contribute to internal tooling, automation, and knowledge sharing across the security organization.
This job is no longer accepting applications
See open jobs at Microsoft.See open jobs similar to "Principal Security Researcher - Purple Team Lead" Tech:NYC.