Security Software Engineer

October 28, 2023

Apply for this job

Email *

Job Description

Security is foundational to all product and service offerings from Microsoft. As part of the Web Experiences (WebXT) Engineering team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape. You will also be working on revolutionary technology with the Open AI ChatGPT integration with WebXT services,<br><br>We are seeking an experienced security engineer to join our rapidly growing team. The ideal candidate will have hands-on experience with native and managed code penetration testing (code audit, writing fuzzers, finding creative ways to break assumptions) and applying those skills to an online services portfolio, a clear understanding of security fundamentals, solid computer science skills, and a passion for keeping Microsoft customers safe.<br><br>It starts with an interest in security, a strong technical background, and an appetite to explore, learn and break things to protect our customers!<br><br><strong><u>Responsibilities<br></u></strong><ul><li>Perform penetration testing activities on production and internal systems to identify unknown vulnerabilities. Define a plan for remediation and drive accountability with engineering to address. </li><li>Provide security guidance, specify app security controls, evaluate existing security controls for new services, apps, features, API’s, devices, and third-party connections. </li><li>Participate in threat hunting activities using tools and data available; make recommendations to enrich data sources for more accurate correlation. </li><li>Track sophisticated adversaries and use your technical knowledge of adversary capabilities, infrastructure, and techniques to enhance detections and provide actionable intelligence to partner teams. Identify new data sources for threat hunting to fill gaps and increase visibility </li><li>Proactively research new technologies, make technology recommendations. </li><li>Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice. </li><li>Develop and write or reuse automation tools to scale the testing quickly. </li><li>Collaborate with other security teams across Microsoft to design and develop new security mitigations and defenses, with a focus on strategy and scalability. <br></li></ul><strong><u>Qualifications<br><br></u></strong>#WebXTPlatform#<br><br><strong><u>Required Skills<br></u></strong><ul><li>3+ years of programming experience in C/C++, C# or similar language. </li><li>4+ years professional experience on penetration testing/red-teaming, good knowledge of cloud, services, and network security </li><li>Deep knowledge in common classes of software vulnerabilities such as XSS, CSRF, SQLi, OWASP Top 10, cryptographic attacks and beyond. </li><li>Penetration testing experiences and knowledge, including familiarity with Burp Suite. </li><li>Proven ability to collaborate and establish key threat intelligence partnerships to bolster information sharing and defenses.   </li><li>Bachelor’s degree in computer science or closely related discipline, or equivalent experience. <br></li></ul><strong><u>Desired Skills<br></u></strong><ul><li>Experience exploiting bugs and bypassing security mitigations in online services. </li><li>Experience managing security compliance related engineering programs. </li><li>Experience managing security infrastructure and operational security. <br></li></ul><strong>Credit Check:</strong> This position will be required to pass the Microsoft Cloud background check and credit history analysis upon hire/transfer and every year thereafter.<br><br> <br><br>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.<br><br>Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.