Summary
Microsoft is seeking a Security Engineer II to help secure Windows products and services used by customers worldwide. The role focuses on offensive security, security engineering, vulnerability research, penetration testing, code and design reviews, and developing scalable mitigations in partnership with product engineering teams.
Responsibilities
- Build reusable agents and tools to expedite and improve the consistency and quality of security reviews
- Review deployments and code for security defects and architectural risk using agents and automated tools built by you and others
- Safely demonstrate the real-world impact of security flaws to aid in prioritization and fix validation
- Be the security contact for teams building new innovative products and services that will be deployed and used by billions
- Apply an adversary mindset to creatively bypass security controls
- Leverage a broad and current understanding of security to devise new protections
- Collaborate with engineering teams to improve security and articulate the value of security investments
Skills
- Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in security or related field
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in security or related field
- OR equivalent experience
- Ability to meet Microsoft, customer and/or government security screening requirements are required for this role
- 2+ years identifying vulnerabilities in online services, deployment misconfigurations
- 5+ years of experience in software engineering or security-related engineering
- Public track record of relevant security research, especially around vulnerability discovery
Qualifications
Must Haves
- Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in security or related field
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in security or related field
- OR equivalent experience
- Ability to meet Microsoft, customer and/or government security screening requirements are required for this role
Nice to Haves
- 2+ years identifying vulnerabilities in online services, deployment misconfigurations
- 5+ years of experience in software engineering or security-related engineering
- Public track record of relevant security research, especially around vulnerability discovery
Benefits
- Certain roles may be eligible for benefits and other compensation.