Senior Security Engineer
Microsoft
Senior Security Engineer
Redmond, Washington, United States
Save
Overview
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
Microsoft Azure is at the center of Microsoft’s cloud services strategy. Azure brings together virtualization, compute, storage, authentication, authorization, artificial intelligence and machine learning, media and more to enable anyone to bring their business in the cloud.
We are seeking a diligent, insightful, and creative Senior Security Engineer to discover, diagnose, analyze, quantify, characterize and help drive solutions for the most challenging security problems in Azure through variant hunting. Variant hunting is an inductive investigation technique, going from the specific to the general, which explicitly recognizes that vulnerabilities occur in patterns. Using newly discovered vulnerabilities as a jumping-off point, you will conduct detailed research looking for additional and similar vulnerabilities, generalize the learnings into patterns, and then partner with engineering, governance, and policy teams to develop holistic and sustainable defenses.
In this role, you will advance security by working with other Security Engineers, Program and Product Managers, and Developers, as well as business leaders throughout Microsoft to turn individual findings and vulnerabilities into patterns and insights that can be measured and managed through engineering, automation, and other appropriate mitigations. You will identify the most demanding security problems through original research and data analysis and help design and deliver practical solutions at scale for select products and services. This role is not confined to any particular area of technology; rather, you will work up and down the stack, across platforms, operating systems, languages, and frameworks, using your broad security skills to solve problems in unfamiliar domains.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Qualifications
Required/Minimum Qualifications
- 5+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
- OR Master's Degree in Statistics, Mathematics, Computer Science or related field.
- Detailed understanding of common classes of vulnerabilities, including but not necessarily limited to one or more of the following: authentication and authorization failures, memory corruption, SQL injection, cryptographic failures, cross-site scripting, networking failures, and the OWASP top 10
Other Requirements:
- Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- 10+ years experience in software development, large scale computing, modeling, or cyber security
- OR Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field OR equivalent experience.
- One or more acknowledged CVEs accredited to your name
- Data analytics and/or AI/ML skills
- Sound judgement, integrity, accountability, and the ability to work in a very fast paced environment.
- Effective written and verbal communication skills
- Demonstrated growth mindset, the ability to learn quickly, and apply old lessons to new situations
Security Research IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications for the role until March 17, 2025.
#DevSec #MSFTSecurity
Responsibilities
- Analyze and categorize newly discovered vulnerabilities to understand contributing causes
- Using insights gained from the analysis, develop ways to discover similar vulnerabilities at scale in other Azure products and services
- Partner with engineering teams to develop appropriate solutions and tools
- Partner with policy and governance orgs to develop the right policies, metrics, and systems to ensure solutions and tools are adopted and applied broadly