Search jobs > Redmond, WA > Senior security engineer

Senior Security Engineer

Microsoft
Redmond, Washington, United States
$117.2K-$229.2K a year
Full-time

Overview

Microsoft Azure is at the center of Microsoft’s cloud services strategy. Azure brings together virtualization, compute, storage, authentication, authorization, artificial intelligence and machine learning, media and more to enable anyone to bring their business in the cloud.

We are seeking a Senior Security Engineer to join our team and contribute to the discovery, diagnosis, analysis, quantification, characterization, and solution-driving for the most challenging security issues within Azure through variant hunting.

Variant hunting is an inductive investigation technique, going from the specific to the general, which explicitly recognizes that vulnerabilities occur in patterns.

Using newly discovered vulnerabilities as a jumping-off point, you will conduct detailed research looking for additional and similar vulnerabilities, generalize the learnings into patterns, and then partner with engineering, governance, and policy teams to develop holistic and sustainable defenses.

In this role, you will advance security by working with other Security Engineers, Program and Product Managers, and Developers, as well as business leaders throughout Microsoft to turn individual findings and vulnerabilities into patterns and insights that can be measured and managed through engineering, automation, and other appropriate mitigations.

You will identify the most demanding security problems through original research and data analysis and help design and deliver practical solutions at scale for select products and services.

This role is not confined to any particular area of technology; rather, you will work up and down the stack, across platforms, operating systems, languages, and frameworks, using your broad security skills to solve problems in unfamiliar domains.

Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day.

In doing so, we create life-changing innovations that impact billions of lives around the world.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals.

Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.

Qualifications

Required / Minimum Qualifications

5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations incident responseOR Bachelor's Degree in Statistics, Mathematics, Computer Science or related field.

Additional or Preferred Qualifications

7+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detectionOR Master's Degree or Doctorate in Statistics, Mathematics, Computer Science or related field.

Other Qualifications :

  • Data analytics and / or AI / ML skills - Sound judgement, integrity, accountability, and the ability to work in a very fast paced environment.
  • Excellent written and verbal communication skills- A demonstrated growth mindset, the ability to learn quickly, apply old lessons to new situations
  • Have a detailed understanding of common classes of vulnerabilities, including but not necessarily limited to one or more of the following : authentication and authorization failures, memory corruption, SQL injection, cryptographic failures, cross-site scripting, networking failures, and the OWASP top 10.

Penetration Testing IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here : Microsoft will accept applications for the role until June 22 2024.

MSFTSecurity #DevSec #AzureSecurity #VariantHunting #PenTesting #SecurityAssurance #InfoSecJobs

Responsibilities

  • Analyze and categorize newly discovered vulnerabilities to understand contributing causes
  • Using insights gained from the analysis, develop ways to discover similar vulnerabilities at scale in other Azure products and services
  • Partner with engineering teams to develop appropriate solutions and tools
  • Partner with policy and governance orgs to develop the right policies, metrics, and systems to ensure solutions and tools are adopted and applied broadly

Other

Embody our and

Benefits / perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.

Industry leading healthcareEducational resourcesDiscounts on products and servicesSavings and investmentsMaternity and paternity leaveGenerous time awayGiving programsOpportunities to network and connect

30+ days ago
Related jobs
Promoted
BrickRed Systems
Redmond, Washington

Senior Security Software Engineer. The Software Engineer will be responsible for designing, developing, implementing, testing, and maintaining business and computer applications software or specialized utility programs, including mainframe and client/server applications, and major enhancements of ex...

Promoted
Salesforce
Bellevue, Washington

Are you a security professional passionate about translating technical risks into balanced guidance for a diverse workforce? Are you inspired by innovating pragmatic solutions for security challenges across a broad range of enterprise infrastructure platforms and products? Do you get excited about e...

Promoted
Snowflake
Bellevue, Washington

Our Quality Engineering team is actively seeking a Senior Software Engineer in Test to the Database Security team to join our fast-growing organization. Features in this area include identity and access management, key management and encryption, secrets management, network security, and security for...

Promoted
Gemini, Inc.
Seattle, Washington

Gemini is looking for a Senior Security Engineer, Threat Detection & Response to join our growing information security team. From security architecture and engineering to maintenance of cold storage systems and data centers to cybersecurity and litigation support, our team ensures that our customers...

Amazon Development Center U.S., Inc.
Seattle, Washington

Security engineers are expected to develop elegant solutions to complex business problems and apply appropriate technologies while following security engineering best practices. Application Security Engineer to help validate that our services, applications, and websites are designed and implemented ...

Snowflake
Bellevue, Washington

The Product Security team builds fundamental security systems that empower Snowflake engineers to bring the most secure Data Cloud to our customers. Partner with security, engineering and product teams to define and set the strategy for internal security practices and processes. We solve the hard se...

CIRCLE
Seattle, Washington

The security team leads the company’s programs for information security, insider risk and cybersecurity. As a member of this team, you’ll lead projects and be responsible for the upkeep of the team’s technology stack as well as creation of log pipelines that feed our SIEM, SOAR, TIP and other securi...

Amazon Development Center U.S., Inc.
Seattle, Washington

Do you relish the challenge of threat modeling, fortifying the defenses of artificial intelligence and cloud systems? Does identifying customer security expectations for AI systems and influencing builders to embrace secure-by-default practices, making the secure path the easy path for our customers...

Amazon.com Services LLC
Seattle, Washington

Senior Security Engineers act as the senior technical resource delivering security support for Healthcare business lines and large initiatives. Deliver bar-raising security services both independently and in a team lead capacity, such as design and implementation reviews, security testing, operation...

Branch Metrics
Remote - Washington, US
Remote

At least 5+ years experience as a Security Engineer focusing on application security, infrastructure security, or security operations. We are seeking an experienced, Senior Application Security Engineer reporting directly to the Head of Security. This important role will help develop and implement t...