Security Engineer
Microsoft
Security Engineer
Redmond, Washington, United States
Save
Overview
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
Are you passionate about identifying and exploiting security vulnerabilities that impact hundreds of millions of users across the world? Join the Microsoft Red Team (MRT) organization, where you will emulate real-world advanced persistent threats against Microsoft. Our mission is to ensure Microsoft is prepared to face and respond to even the most determined adversaries by exploring innovative ways to identify and prevent security flaws. MRT is seeking a talented individual focused on identifying, exploiting, and emulating real-world threats against Microsoft’s enterprise assets and services, including cloud services, on-prem systems, and corporate facilities.
We are looking for a Security Engineer to execute operations and collaborate with other experienced red teamers in identifying and exploiting vulnerabilities across all layers of services, including application, cloud, network, hardware, and operational security domains. You will work closely with developers and security personnel from multiple teams across Microsoft. Additionally, as a Security Engineer in MRT, you will be responsible for executing tactics, techniques, and procedures of potential attackers, while providing critical insights that empower our security teams to strengthen defenses and protect against the evolving landscape of digital threats.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Qualifications
Required Qualifications:
- 1+ year(s) experience in a security or software engineering-related field
- Bachelor's degree in cybersecurity, IT, computer science
- OR equivalent work experience
Penetration Testing IC2 - The typical base pay range for this role across the U.S. is USD $84,200 - $165,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $109,000 - $180,400 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications for the role until July 23rd, 2025.
#MRT, #RedTeam
Responsibilities
- Discover and exploit vulnerabilities end-to-end in order to assess the security of services
- Execute Red Team operations using real world adversarial tactics and techniques to validate a production service's ability to detect, investigate, and respond
- Advocate for security change across the company through building partnerships and clearly communicating impact of risks
- Analyze a wide array of data sources to identify potential security weaknesses and breach points within Microsoft’s infrastructure
- Prototype tools and techniques to scale and accelerate offensive emulation and vulnerability discovery
- Collaborate with Blue Teams to improve readiness and produce solutions for defenders and customers
- Analyze simulated adversary tactics and communications, enriching our defensive tactics and threat intelligence