Senior Security Engineer and Principal Security Engineer (multiple Positions)

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Penetration Testing

This role focuses on offensive security and security engineering for Microsoft Windows products. Responsibilities include security design reviews, code reviews, penetration testing, vulnerability research, and developing mitigations to enhance the security posture of OS platforms. The ideal candidate will have hands-on experience with native code, penetration testing, and a strong understanding of OS security fundamentals.

What you'd actually do

  1. Participate in security reviews to identify and mitigate risk in Microsoft products, including design reviews, code reviews, and fuzzing
  2. Be the security contact for teams building new innovative products and technologies in the next version of Windows and devices
  3. Identify security vulnerabilities in a wide variety of key OS features such as network protocols, security features, and Microsoft devices Leverage a broad and current understanding of security to devise new protections
  4. Interact with the external security community and security researchers
  5. Collaborate with product teams to improve security, and articulate the business value of security investments

Skills

Required

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field
  • Ability to meet Microsoft, customer and/or government security screening requirements

Nice to have

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
  • 2+ years identifying vulnerabilities in operating systems and/or native (C/C++) applications
  • 5+ years of experience in a software engineering or security-related engineering
  • Demanstrated experience in security research, especially around vulnerability discovery
  • Experience exploiting bugs and bypassing security mitigations in operating systems
  • Familiarity with Microsoft Windows architecture

What the JD emphasized

  • security screening requirements