Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

Microsoft Senior Security Software Engineer 
United States, Washington 
939909954

Yesterday


By applying to this Redmond, WA position, you  are required to be local to the  Seattle area and in office 3 days a week.

Required Qualifications

  • 5+ years experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection.
  • 5+ years professional experience in penetration testing/red-teaming, including familiarity with tools like Burp Suite, good knowledge of cloud, services, and network security.
  • 3+ years of programming experience in C/C++, C# or similar language.
  • Experience in common classes of software vulnerabilities such as XSS, CSRF, SQLi, OWASP Top 10, cryptographic attacks and beyond.

Other Requirements

Ability to meet Microsoft, customer and/or government security screening requirements that are required for this role. These requirements include, but are not limited to the following specialized security screenings:

This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.

Preferred Qualifications

  • Experience exploiting bugs and bypassing security mitigations in online services.
  • Experience managing security compliance related engineering programs and security infrastructure.
  • Proven ability to collaborate and establish key threat intelligence partnerships to bolster information sharing and defenses.
  • Experience with one or more of the following: Azure, AWS, GCP, or any other large cloud provider security best practices.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:Microsoft will accept applications for the role until January 29, 2025.


Responsibilities
  • Perform penetration testing activities on production and internal systems to identify unknown vulnerabilities. Define a plan for remediation and drive accountability with engineering to address.
  • Provide security guidance, specify app security controls, evaluate existing security controls for new services, apps, features, API’s, devices, and third-party connections.
  • Participate in threat hunting activities using tools and data available; make recommendations to enrich data sources for more accurate correlation.
  • Track sophisticated adversaries and use your technical knowledge of adversary capabilities, infrastructure, and techniques to enhance detections and provide actionable intelligence to partner teams. Identify new data sources for threat hunting to fill gaps and increase visibility
  • Proactively research new technologies, make technology recommendations.
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice.
  • Collaborate with other security teams across Microsoft to design and develop new security mitigations and defenses, with a focus on strategy and scalability.