Security Engineer II

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Security Research

Security Engineer II role focused on securing the Microsoft Edge Browser client code through proactive vulnerability research, analysis, and engagement with developers. Responsibilities include identifying security issues, supporting mitigation, investigating incidents, and contributing to secure design and development practices. Requires experience in cybersecurity principles, code audit, fuzzer development, crash analysis, and web security.

What you'd actually do

  1. Identifies security issues within assigned areas and proposes mitigation steps, escalating complex or high-impact risks as needed.
  2. Supports implementation of mitigation, response, and remediation activities using established tools, guidelines, and best practices.
  3. Investigates, diagnoses, and triages security incidents with minimal guidance, following defined incident response processes.
  4. Contributes to incident management, including stakeholder communication and postmortem/root cause analysis.
  5. Participates in security reviews (e.g., architecture, design), documents findings, and collaborates on remediation plans.

Skills

Required

  • Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 1+ year(s) experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 2+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.

Nice to have

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Experience with relevant security research along with relevant CVEs (if available) ideally in browser vulnerability discovery.
  • Experience with writing basic exploits for native or web applications.
  • Development and deployment of fuzz testing and/or static analysis software.

What the JD emphasized

  • security screening requirements