Penetration Tester

Microsoft Microsoft · Big Tech · Sydney, NSW, Australia +2 · Penetration Testing

Penetration Tester for M365 Core Substrate team, focusing on identifying and exploiting vulnerabilities in AI systems and platforms. The role involves research, offensive security operations, developing AI-powered tooling for vulnerability discovery, and collaborating with engineering teams to improve security. Requires experience in security research, penetration testing, and hands-on experience with AI systems.

What you'd actually do

  1. Vulnerability Discovery & Exploitation: Find and validate security vulnerabilities through hands-on penetration testing, code review, and proof-of-concept exploit development.
  2. Tooling & Automation: Build and maintain automated and autonomous tooling to scale offensive security testing and vulnerability discovery.
  3. Research & Threat Analysis: Investigate emerging attack techniques, exploit classes, and AI/agentic system threats. Feed findings into testing priorities and architectural improvements.
  4. Security Architecture Collaboration: Work with Security Architecture and service teams to assess design-level risks, review threat models, and inform platform hardening based on offensive findings.
  5. Reporting & Remediation: Write technical reports that clearly describe what's broken, the impact, and how to fix it. Track findings through to resolution with service owners.

Skills

Required

  • security research
  • penetration testing
  • offensive security
  • AI systems
  • Python
  • AI frameworks
  • security testing tools
  • code review
  • exploit development

Nice to have

  • web applications
  • APIs
  • cloud infrastructure
  • identity/authentication systems
  • published security research
  • conference presentations
  • software engineering
  • distributed systems
  • OSC
  • OSWE
  • GWAPT
  • service-to-service authentication
  • authorization models
  • cloud-native architectures

What the JD emphasized

  • Hands-on experience discovering and exploiting vulnerabilities in AI systems and platforms.
  • Proficiency in Python with experience in AI frameworks and security testing tools.

Other signals

  • AI/agentic system threats
  • AI systems and platforms
  • AI frameworks
  • AI to look for vulnerabilities