Expoint - all jobs in one place
המקום בו המומחים והחברות הטובות ביותר נפגשים
Limitless High-tech career opportunities - Expoint

Microsoft Principal Security Researcher – Purple Team Lead 
Taiwan, Taoyuan City 
534829115

21.05.2025

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.

We are seeking a Principal Security Researcher to lead offensive security and purple team initiatives within Microsoft’s Threat Protection organization. This role is ideal for a seasoned security expert who thrives at the intersection of red and blue teaming, and who is passionate about using adversary simulation, detection engineering, and AI-driven insights to protect billions of users. You will play a key role in building and scaling a Purple Team hub, driving high-impact engagements that test and improve Microsoft Defender’s detection and response capabilities.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Required Qualifications

  • years experiencein software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
    • OR Doctorate in Statistics, Mathematics, ComputerScienceor related field.
  • 8+ years in cybersecurity, with deep experience in red teaming, detection engineering, or threat research.
  • Proven leadership in offensive security or purple team operations and proficient knowledge of MITRE ATT&CK, adversary TTPs, and detection frameworks.
  • Experience in scripting (Python, PowerShell) and familiarity with attack simulation tools (e.g., Caldera, Atomic Red Team).
  • Experience with SIEM/EDR platforms (Microsoft Sentinel, Defender, etc.).

Other Requirements

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:
    - This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.


Additional or Preferred Qualifications

  • years experiencein software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
    • OR Doctorate in Statistics, Mathematics, ComputerScienceor related

Security Research IC5 - The typical base pay range for this role across the U.S. is USD $137,600 - $267,000 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $180,400 - $294,000 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until May 28, 2025.

Responsibilities
  • Lead the design and execution of advanced adversary emulation campaigns.
  • Build and mentor a high-performing purple team focused on offensive testing and detection validation.
  • Collaborate with red teams, detection engineers, and threat intelligence teams to identify and close detection gaps.
  • Apply generative AI and LLMs to simulate attacker behavior and enhance detection logic.
  • Translate offensive findings into actionable improvements across Microsoft Defender and Sentinel.
  • Contribute to internal tooling, automation, and knowledge sharing across the security organization.
  • Embody our and