Microsoft-posted 3 months ago
$117,200 - $229,200/Yr
Full-time • Senior
Hybrid • Redmond, WA
5,001-10,000 employees
Publishing Industries

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft Azure is at the center of Microsoft's cloud services strategy and the future of Microsoft. Azure brings together virtualization, compute, storage, authentication, authorization, artificial intelligence and machine learning, media and more to enable anyone to bring their business into the cloud. Azure DevSec, a part of the Microsoft Security organization, ensures Azure is the most secure platform in the world and delivers a secure experience for millions of users worldwide. The DevSec team is looking for a motivated Senior Security Software Engineer, to work on proactive security assessments and mitigation of vulnerabilities in Azure services.

  • Take a lead role in driving security reviews involving a combination of architecture reviews, threat modeling and penetration testing
  • Effective collaboration with cross-functional teams to identify and help mitigate vulnerabilities in Azure core services.
  • Act as a subject matter expert to provide consultation for security incidents as required and mentor other members of the team.
  • Exercise technical curiosity and partner across security disciplines to help address security issues, patterns, and trends.
  • Contribute to new and existing security tooling and automation to scale vulnerability discovery and mitigate classes of attacks.
  • 5+ years experience identifying security vulnerabilities, software development lifecycle, large-scale computing, threat modeling and security architecture
  • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field
  • OR equivalent experience.
  • 3+ years experience regarding multiple classes of vulnerabilities, including cross-site scripting, buffer overflows, SQL injection, TOCTOU (Time of Check Time Of Use) vulnerabilities, cryptographic weaknesses, insecure direct object references, and others, and the ability to communicate about them to technical and non-technical audiences.
  • 3+ years experience reviewing code across common programming languages (C#, Rust, Python, Java, Go, C++) to identify vulnerabilities and provide mitigations.
  • Leadership, empathy, interpersonal and communication skills
  • 3+ years experience writing code across common programming languages (C#, Rust, Python, Java, Go, C++) building automation to mitigate vulnerabilities
  • 6+ years experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection
  • OR Master's/PhD Degree in Statistics, Mathematics, Computer Science or related field.
  • Relocation support will be provided
  • Eligible for hybrid or remote work, up to 50%
  • Base pay range for this role across the U.S. is USD $117,200 - $229,200 per year
  • Different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service