Principal Product Manager, AI Model Security

Microsoft

Mountain View, CA

JOB DETAILS
SALARY
$139,900–$274,800 Per Year
SKILLS
Academic Research, Analysis Skills, Artificial Intelligence (AI), Benchmarking, Blog, Computer Science, Computer Security, Data Sets, Enterprise Protection, Establish Priorities, Incident Management, Incident Response, Injections, Integrated Circuits (ICs), Legal, Machine Tool, Malware, Metrics, Microsoft Office, Microsoft Product Family, Microsoft Windows Azure, Penetration Testing, Power Amplifier, Process Improvement, Product Management, Product Testing, Regulatory Requirements, Requirements Management, Risk, Risk Management, Risk Modeling, Security Analysis, Security Attacks, Security Information and Event Management (SIEM), Security Policy, Software Development, Startup, Test Program, U.S. National Institute of Standards and Technology (NIST)
LOCATION
Mountain View, CA
POSTED
1 day ago

Microsoft Superintelligence teams mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
This role is part of Microsoft AIs Superintelligence Team. The MAIST is a startup-like team inside Microsoft AI, created to push the boundaries of AI toward Humanist Superintelligence — ultra-capable systems that remain controllable, safety-aligned, and anchored to human values. Our mission is to create AI that amplifies human potential while ensuring humanity remains firmly in control. We aim to deliver breakthroughs that benefit society — advancing science, education, and global well-being.
We are hiring a Product Manager to own AI model security — the discipline of making our frontier models resilient against adversarial attack and purpose-built for security practitioners. This role has a dual mandate: (1) harden our models against the full spectrum of LLM security threats — prompt injection, data exfiltration, jailbreaking, training data extraction, zero-day exploit generation, model poisoning, and agentic workflow exploitation — and (2) partner closely with Microsoft Security product teams (Azure Security, Security Copilot) to ensure our models deliver best-in-class capabilities for real-world security workflows.
This is not a safety role (we have one). This is security: you think like an attacker, you understand the OWASP LLM Top 10, and you bring product judgment to hard tradeoffs between model capability and attack surface. You also understand what security analysts and incident responders need from AI — and you work backwards from their workflows to define model training priorities, evaluation benchmarks, and product requirements.
You will work shoulder-to-shoulder with model researchers, engineers, and red teamers. You will personally build evaluation frameworks, define security benchmarks, and drive decisions about what to ship and what to hold. This is a small team with high ownership — you will see your work in production and be accountable for outcomes.

Responsibilities

  • Own the model security roadmap: Define and prioritize the security hardening strategy for our frontier models across the full OWASP LLM threat surface — prompt injection (direct and indirect), data exfiltration, jailbreak resistance, system prompt leakage, training data extraction, and adversarial manipulation of agentic workflows.
  • Drive zero-day and exploit defense: Work with researchers to evaluate and mitigate the risk of models being used to generate zero-day exploits, malware, or novel attack vectors. Define thresholds, build evaluation datasets, and own the decision framework for what the model should and should not be capable of in the security domain.
  • Build and scale red-teaming frameworks: Design, run, and iterate adversarial testing programs — both automated and human-driven — to continuously probe model vulnerabilities. Establish metrics (e.g., jailbreak success rate, injection bypass rate, exfiltration resistance) and drive measurable improvement over time.
  • Partner with Microsoft Security product teams: Work closely with Azure Security and Security Copilot teams to translate their product requirements into model training priorities. Ensure our models are purpose-built for threat detection, incident triage, vulnerability assessment, log analysis, and compliance reasoning.
  • Define security-specific model evaluations: Build benchmark suites and evaluation frameworks that measure real-world security usefulness — not just academic performance. Drive training data strategy to improve domain-specific model quality for security practitioners.
  • Shape security policy and launch readiness: Establish clear security criteria for model launches. Own the security dimension of go/no-go decisions, with frameworks that balance capability, risk, and deployment context.
  • Stay at the frontier: Track the rapidly evolving LLM security landscape — new attack techniques, emerging standards (OWASP, NIST AI RMF), regulatory requirements (EU AI Act), and academic research. Translate what you learn into actionable product priorities.
  • Influence model training and architecture: Partner with researchers and engineers to embed security considerations into model training, fine-tuning, RLHF, and post-training safeguards. You dont just test — you shape what gets built.

Qualifications

Required Qualifications

  • Bachelors Degree AND 5+ years experience in product management, security engineering, or software development OR equivalent experience
  • Demonstrated hands-on experience with AI/ML systems — you have personally built, evaluated, or shipped ML-powered products or security tools
  • Deep familiarity with LLM security threats: prompt injection, jailbreaking, data exfiltration, adversarial attacks on generative models — through professional experience, red-teaming, or security research
  • Experience defining product requirements and driving decisions in partnership with researchers or ML engineers
  • Track record of building evaluation systems, security benchmarks, or adversarial testing frameworks — not just consuming them
  • Ability to operate autonomously, make decisions with incomplete information, and drive projects from ambiguity to shipped outcomes

Preferred Qualifications

  • Technical background in computer science, security, or AI/ML — a postgraduate degree is a plus but not required
  • Experience in offensive security, penetration testing, or red teaming — ideally applied to AI/ML systems
  • Familiarity with security workflows and tooling (SIEM, SOAR, EDR, threat intelligence platforms) and how practitioners use them in production
  • Understanding of the model lifecycle (pre-training, fine-tuning, RLHF, deployment, monitoring) and where security interventions are most effective
  • Experience working with or within enterprise security organizations (e.g., Microsoft Security, CrowdStrike, Palo Alto Networks, or similar)
  • Published research, blog posts, or public contributions in AI security, adversarial ML, or LLM red teaming

Starting January 26, 2026, MAI employees are expected to work from a designated Microsoft office at least four days a week if they live within 50 miles (U.S.) or 25 miles (non-U.S., country-specific) of that location. This expectation is subject to local law and may vary by jurisdiction.

Product Management IC5 - The typical base pay range for this role across the U.S. is USD $139,900 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

About the Company

M

Microsoft

DO WHAT YOU LOVE
Make your mark on the world’s most used technologies. Develop the next hit mobile application. Pioneer a startup that could be the next big thing. At Microsoft, you choose your path.

Headquartered in Redmond, Washington, Microsoft is a top innovator in both the consumer and enterprise technology industry. Just a few of the many things our products do are unleash creativity, connect businesses, and make learning more fun. But our continued success is based on one thing: our employees. We hire amazing, talented people and give them the opportunities—and the tools—to succeed.

WHY MICROSOFT?
As a Microsoft employee, you’re surrounded by a diverse group of the smartest people in your field. This fosters new ideas, better business results, and creates a dynamic work environment. In the office, you’re constantly challenged and supported by your colleagues. Every day holds something new and exciting.

We also offer unparalleled depth and breadth of career opportunities. As an industry leader in multiple fields, working for Microsoft means being able to do whatever you feel passionate about—and being able to make an impact in that field. From day one, we give our employees significant responsibility. This means that you’ll know that you directly contributed to something that has a positive impact on people worldwide. Whether you choose to work in management, dive deep into the newest technology, or explore multiple professions, you’ll find everything you need at Microsoft to drive your career—and to make a difference.

WE GET IT – YOU’RE MORE THAN YOUR JOB
Everyone works differently and is motivated by different things. We also understand that there’s more to you than your job. That’s why we offer competitive pay and a wide assortment of benefits-- to help you make the most of life at work and away from it.

GET THE BALL ROLLING
COMPANY SIZE
10,000 employees or more
INDUSTRY
Computer Software
FOUNDED
1975
WEBSITE
http://www.microsoft.com