Principal Applied Scientist

Microsoft — Redmond, WA, US | Mountain View, CA, US

Apply on employer website
Overview
The Online Forensics team sits within the Microsoft AI Experiences organization, where we protect the monetization network that funds the products people use every day. Because attackers adapt quickly, effective defense must anticipate emerging abuse—not just respond to incidents. You will establish authoritative ground truth on fraud, surface evolving tactics, identify vulnerabilities before they are exploited at scale, and produce the signals, datasets, and test scenarios partner defense teams need.
As a Principal Applied Scientist on the Online Forensics team, you will shape the scientific strategy for protecting Microsoft’s monetization network. You will assess threats in monetization and advertising flows and LLM-native systems, track adversary behavior and infrastructure, design safe adversarial simulations, and develop test harnesses and investigation platforms that expose blind spots early. When material incidents occur, you will lead rigorous reconstruction and convert validated findings into labeled ground truth, candidate signals, and regression scenarios that partner defense teams can use to strengthen defenses.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.  
Starting January 26, 2026, Microsoft AI MAI employees who live within a 50- mile commute of a designated Microsoft office in the U.S. or 25-mile commute of a non-U.S., country-specific location are expected to work from the office at least four days per week. This expectation is subject to local law and may vary by jurisdiction.

Responsibilities
- Identify emerging fraud tactics, adversary infrastructure, and evasion patterns across monetization flows and LLM-native systems through threat modeling, behavioral, graph-based, temporal, and cross-surface big data analysis.
- Assess high-risk assumptions and attack paths by forming explicit threat hypotheses, identifying observable signals, and validating risk through structured modeling, targeted experiments, and quantitative measurement.
- Design safe adversarial simulations that expose blind spots, then convert the results into test harnesses, monitored indicators, and reproducible regression scenarios for sister defense teams.
- Establish authoritative ground truth by correlating evidence across accounts, traffic, transactions, providers, devices, and infrastructure; reconstruct attack chains and document their provenance, confidence, scale, and economic exposure.
- Develop shared investigation infrastructure, agent-assisted services, and reusable libraries for telemetry analysis, entity resolution, attack-sequence reconstruction, and reproducible case analysis and convert into act




Looking for a job?

Visit Careersaas to find millions of new and unfilled roles, including thousands of remote and hybrid positions.