Connecting people I'd hire with companies I'd work at

Matt Wallaert
35
companies
9,541
Jobs

Senior Cloud Security Researcher - Enterprise and Security ILDC

Microsoft

Microsoft

Posted on Dec 13, 2024

Senior Cloud Security Researcher – EPSF IL

Herzliya, Tel Aviv, Israel

Save

Share job

Date posted
Oct 30, 2024
Job number
1776947
Work site
Up to 50% work from home
Travel
0-25 %
Role type
Individual Contributor
Profession
Security Engineering
Discipline
Security Research
Employment type
Full-Time

Overview

Our team is engaged in proactive vulnerability research across the Azure platform services, with focus on the Adaptive Cloud domain. We are dedicated to uncovering novel classes of vulnerabilities and pioneering exploitation techniques to effectively pre-empt cyber threats.

Handling the task of extending Azure into on-prem environments, Microsoft Adaptive Cloud poses complex challenges, requiring vulnerability research skills in a broad spectrum of fields: operating systems and client-side code, containers and Kubernetes, and Cloud environments.

We are seeking a versatile and experienced Senior Researcher to join our offensive security team at Microsoft.

In this role you will lead vulnerability research engagements by cooperating with the development teams, tutor and mentor promising early-in-career employees and develop tooling to carry vulnerability research at scale, integrating with existing SSDL processes. You’ll play a pivotal role in identifying and addressing potential security vulnerabilities within Microsoft's cloud services and adaptive cloud domain, ensuring the highest levels of security for our customers and their data.

Qualifications

  • 8+ years of hands-on experience in offensive security research, with 2+ years focus on containers, Kubernetes or cloud environments
  • Proven track record of discovering and responsibly disclosing security vulnerabilities
  • Proficiency in reading and finding vulnerabilities in code - multiple programming and scripting languages
  • Experience in writing code to complement and improve vulnerability research at scale

Preferred qualifications:

  • Proven experience in working with development teams, according to industry standards for Secure Software Development Lifecycles (SDL)
  • Deep understanding of networking, container environments, Kubernetes and operating systems security mechanisms
  • Bachelor's degree or equivalent in Computer Science, Information Security, or a related field. Advanced degrees are a plus
  • Strong written and verbal communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences

Responsibilities

Responsibilities:

    • Research and discover zero-day vulnerabilities in cloud environments and associated technologies. Develop and implement proof-of-concept exploits to demonstrate potential risks and work closely with engineering teams to address findings.
    • Conduct in-depth threat modeling exercises to identify security risks and vulnerabilities in Microsoft's cloud infrastructure. Collaborate with cross-functional teams to assess the impact of identified threats and propose mitigation strategies.
    • Design and execute sophisticated penetration tests against Microsoft's cloud services, simulating real-world attack scenarios. Provide detailed reports outlining vulnerabilities, exploitation techniques, and recommended remediation steps.
    • Create and maintain cutting-edge vulnerability discovery, exploitation, and penetration testing tools in cloud environments. Stay abreast of the latest security research and integrate innovative techniques into the offensive security toolkit.
    • Collaborate with internal security teams to enhance overall security posture, including incident response and defensive security. Participate in knowledge-sharing initiatives, mentor junior team members, and contribute to the security community.

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.