- Experience
- 3+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Education
- Bachelor's degree in Statistics, Mathematics, Computer Science, or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
This role is part of the M365 Core Substrate team, tasked with ensuring the security and trustworthiness of Microsoft's M365 product suite. The team aims to modernize security across cloud services, empowering users, customers, and developers with end-to-end protection through innovative solutions. The culture emphasizes a growth mindset, excellence, and collaboration, driving impactful innovations worldwide.
The Security Engineering team identifies infrastructure threats for large global organizations. This position blends research and penetration testing methods, focusing on advancing offensive security using AI. It offers unique opportunities to work on global-scale services within a major SaaS provider environment.
Responsibilities
- Discover and validate security vulnerabilities via penetration testing, code review, and exploit creation.
- Develop and maintain automated tools to scale offensive security testing and vulnerability identification.
- Conduct research into emerging attack strategies, AI threats, and exploit types to inform testing and architecture enhancements.
- Collaborate with security architecture and service teams to assess design risks, review threat models, and support platform hardening based on offensive findings.
- Produce clear technical reports describing vulnerabilities, impacts, and remediation strategies; monitor fixes with service owners.
- Partner with detection engineering and blue teams to verify detection capabilities and close gaps revealed through offensive operations.
Qualifications and Requirements
Minimum qualifications include a Bachelor's degree in a relevant discipline or equivalent experience, along with over three years in cybersecurity or software development roles related to security research or offensive security. Candidates must have hands-on experience with AI system vulnerabilities, proficiency in Python and AI frameworks, and the ability to analyze multi-language codebases.
Preferred qualifications include a Master’s degree or extended professional experience in security, a history of penetration testing cloud and web infrastructures, published research, software engineering knowledge in distributed systems, recognized security certifications (e.g., OSCP, OSWE), and familiarity with authentication models and cloud-native designs.
Additional Information
This position will remain open for at least five days and accepts applications continuously until filled. Microsoft fosters an inclusive, equal opportunity workplace where all qualified applicants receive consideration regardless of diverse personal characteristics. Accommodations for disabilities and religious practices are available upon request.
Minimum education
Bachelor's Degree