Yammer logo

Senior Security Researcher

Yammer

Redmond, WAJobPosted 1 day agoStill listed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Redmond, WA
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Senior Security Researcher researches attacks targeting third-party identity providers and SaaS platforms, then translates findings into detection and protection strategies. The role also builds RAG-based AI agents and coding agents for security research and detection authoring, and creates evaluation frameworks to assess agent quality and usefulness.

Skills & qualifications

RequiredNice to have

Skills

Threat AnalysisThreat ModelingCybersecurityVulnerability ResearchAnomaly DetectionMITRE ATT&CKThreat HuntingData AnalysisAI AgentsRAG SystemsAgent EvaluationLLM-as-a-JudgeQuality ValidationPythonProduction Tool DevelopmentEvaluation FrameworksAccuracy MeasurementGroundedness MeasurementReliability MeasurementRegression Testing

Qualifications

Doctorate or Master's+3 or Bachelor's+4 or EquivalentDoctorate+3 or Master's+6 or Bachelor's+8 or Equivalent3+ Years Experience6+ Years Experience8+ Years Experience

Full job description

Research third-party identity and SaaS attacks: Research attacker tradecraft and emerging threats targeting identities, applications, authentication flows, sessions, privileges, and data across third-party identity providers and SaaS platforms, including Okta and Salesforce. Translate threat research into protection: Convert security research, incidents, customer reports, and threat-landscape intelligence into clear attack scenarios, telemetry requirements, detection opportunities, investigation logic, and durable protection strategies. Build AI agents for security research: Design and develop RAG-based agents that retrieve and reason over product documentation, schemas, threat intelligence, prior research, code, telemetry, and operational knowledge to support security-research workflows. Develop coding and detection-authoring agents: Build coding agents that help generate, review, refine, and maintain security analytics, KQL queries, detection logic, test cases, and related research artifacts with appropriate human oversight. Create evaluation frameworks: Define representative datasets, scenarios, benchmarks, and scoring methods to evaluate agent accuracy, completeness, groundedness, robustness, and security-research usefulness. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. These requirements include, but are not limited to the following specialized security screenings: Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. OR equivalent experience. Background in the modern attacker kill-chain and MITRE ATT&CK. Experience researching hybrid attacks involving third-party identity providers and SaaS applications, such as Okta and Salesforce, and attacks against cloud services. Threat hunting and data-analysis skills. Experience with AI agents, RAG-based systems, agent evaluation, LLM-as-a-judge techniques, and quality validation. Programming skills in Python or a similar language, with experience building production-quality research or automation tools. Experience designing evaluation frameworks and quality-validation methods for AI systems, including measuring accuracy, groundedness, reliability, and regressions.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.