Senior Security Engineer

MicrosoftRedmond, WA

About The Position

Security is a critical priority for customers facing digital threats, regulatory scrutiny, and complex estates. Microsoft Security aims to make the world safer by reshaping security and empowering users, customers, and developers with an end-to-end, simplified security cloud. The Microsoft Security organization drives the company's mission to secure digital technology platforms, devices, and clouds in heterogeneous environments, and ensures the security of Microsoft's internal estate. The culture emphasizes a growth mindset, inspiring excellence, and encouraging teams to innovate daily. The Identity Security (IDSEC) Breach Preventions team is responsible for preventing repeat security incidents across Microsoft’s Identity platform. This is achieved by building scalable, engineering-driven security controls that eliminate entire classes of vulnerabilities before exploitation. The team operates at the intersection of software engineering and security research to design and deploy platform-level countermeasures across Microsoft’s Identity and Network Access (IDNA) services. Their focus includes proactively identifying authentication and authorization attack paths, translating breach learnings into reusable preventative mechanisms, and automating security enforcement across hundreds of production services. The goal is to move beyond reactive vulnerability mitigation by harmonizing engineering and security systems to automate reusable protections across the identity technology stack. Microsoft's mission is to empower every person and every organization on the planet to achieve more, fostering a culture of inclusion, respect, integrity, and accountability.

Requirements

  • Doctorate in Statistics, Mathematics, Computer Science, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR equivalent experience.
  • 3+ years of deep understanding of identity and access technologies, such as authentication and authorization protocols (OAuth, OIDC, SAML), tokens, certificates/PKI, and MFA
  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Nice To Haves

  • Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.
  • CISSP CISA CISM SANS OSCP Security+

Responsibilities

  • Translating breach learnings and threat actor behaviors into deterministic engineering controls that prevent recurrence across multiple services.
  • Designing platform level enforcement mechanisms that eliminate classes of vulnerabilities without requiring service by service remediation.
  • Developing reusable prevention frameworks and paved path security standards.
  • Partnering with engineering teams to integrate preventative controls into production environments while maintaining service reliability.
  • Contributing to scalable automation and analysis across signals from vulnerability research, threat intelligence, and security risk posture monitoring.
  • Enabling rapid deployment of security countermeasures across Microsoft’s identity fleet to proactively strengthen defenses against emerging threats.
  • Embody our Culture and Values
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service