Specialized Cloud Security Researcher - MSC STORM
Microsoft
Specialized Cloud Security Researcher – MSC STORM
Herzliya, Tel Aviv, Israel
Save
Overview
Microsoft Specialized Cloud organization is responsible for tailoring cloud infrastructure to customer needs, addressing sovereignty, privacy and security requirements, across Azure cloud and Edge solutions. STORM security research group is responsible for making sure these products meet the highest security bar customers expect from us.
We are searching for exceptional individuals with a profound passion for security and Cloud technologies. If you are deeply committed to unraveling intricate challenges, harbor a keen fascination for vulnerability research, and strongly desire to contribute to performing cutting-edge security research. We invite you to unite with us on our mission. By doing so, you will play a pivotal role in safeguarding countless users across the global landscape. Your expertise and dedication will be instrumental in fortifying our collective digital defenses.
In this role, you will lead vulnerability research engagements in Microsoft Specialized Clouds organization, play a pivotal role in identifying and addressing potential security vulnerabilities within Microsoft's cloud and edge services, ensuring the highest levels of security for our customers and their data.
Qualifications
Required Qualifications
- Proven track record of discovering and responsibly disclosing security vulnerabilities.
 
- Expertise in any of the following domains:
 
- Cloud security: Azure, AWS, GCP.
 
- Kubernetes and container security
 
- Virtualization and VM isolation
 
- IOT security
 
- AI security
 
Other Requirements:
- SENIOR: 6+ years of hands-on experience in offensive security research, with 2+ years of focus on cloud environments.
 
- SWE II: 4+ years of hands-on experience in offensive security research, with 2+ years of focus on cloud environments.
 
- Proficiency in multiple programming and scripting languages.
 
- Bachelor's degree or equivalent in Computer Science, Information Security, or related field. Advanced degrees are a plus.
 
- Strong written and verbal communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences.
 
#MSCIL
Responsibilities
- Research and discover zero-day vulnerabilities in cloud and on-prem environments and associated technologies. Develop and implement proof-of-concept exploits to demonstrate potential risks and work closely with engineering teams to address findings.
 
- Design mitigations at scale for found vulnerabilities and work with engineering teams to integrate these mitigations.
 
- Conduct in-depth threat modeling exercises to identify security risks and vulnerabilities in Microsoft's ‘Specialized Cloud’ infrastructure. Collaborate with cross-functional teams to assess the impact of identified threats and propose mitigation strategies.
 
- Design and execute sophisticated penetration tests against Microsoft's cloud services, simulating real-world attack scenarios. Provide detailed reports outlining vulnerabilities, exploitation techniques, and recommended remediation steps.
 
- Create and maintain cutting-edge vulnerability discovery, exploitation, and penetration testing tools. Stay abreast of the latest security research and integrate innovative techniques into the offensive security toolkit.
 
- Collaborate with internal security teams to enhance overall security posture, including incident response and defensive security. Participate in knowledge-sharing initiatives, mentor junior team members, and contribute to the security community.