Senior Security Software Engineer | Redmond, WA

Detailed Information

  • Location: Redmond, WA

  • Company: Microsoft

experience for millions of users worldwide. The Azure Security Assurance team is seeking a Senior Security Software Engineer with demonstrated experience in software development, and network, platform and application layer security. As part of the Devsec team, you will develop tools to help internal and external customers design and build secure systems.

You will take knowledge developed by you and your peers from threat modeling, penetration testing, and vulnerability analysis and bring those insights to life through tooling. We are looking for a Senior Security Software Engineer with the ability to work independently and collaboratively working on leading edge security challenges. You

will play a key role in advancing security by working with other Security Engineers, Program Managers, and Developers throughout the Azure organization to instill an 'Assume Breach' security mindset and culture through the creation of design-time security tools.

You will also participate in the broader Microsoft and industry-wide security community to advance the state of the art. Qualifications: Required Qualifications: Bachelor's Degree in Computer Science, or related technical discipline AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, Java Script, or Python OR equivalent experience. Other Requirements Ability to

meet Microsoft, customer and/or government security screening requirements are required for this role.

These requirements include but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter. Preferred Qualifications: Knowledge of one or more high-level programming languages, CI/CD pipelines, development and architectural patterns, and software engineering techniques Knowledge in multiple classes of vulnerabilities, including cross-site scripting, server side request forgery, buffer overflows, command injection, time of use - time of check vulnerabilities, cryptographic weaknesses, and others Knowledge of services, security and engineering and development skillset.

Software Engineering IC4 - The typical base pay range for this role across the U. S. is USD $112,000 - $218,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $145,800 - $238,600 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: careers.

/us/en/us-corporate-pay Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, interaction (including pregnancy), interactionual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.

We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form. Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work. #Azure Sec CSS#Azure Sec Open Responsibilities: Penetration testing: examine chosen target systems in detail, looking for scenarios to discover and exploit vulnerabilities and weaknesses, and, in collaboration with other penetration testing and red teams around the company, demonstrate the value of an " assume breach" mentality.

Development of tools and techniques to help internal and external customers build secure systems from the ground up. Emerging Threat and Vulnerability Research: Be on the forefront of emerging threats which affect cloud services through collaboration, independent study, and original research, including proactive security research on the technologies that Azure and our customers utilize and depend on. A very high level of creativity and thirst for knowledge are a must.

Security backssments: Parlaying research and knowledge into threat models and security backssments of Azure services, platforms, and infrastructure. You have a goal to prioritize areas of security risk while identifying and addressing risks that affect Azure's ability to protect, detect, investigate, and recover from security vulnerabilities and targeted attacks. Security Code Reviews: Prioritize Azure's highest risk features and review source code for security defects. File bugs on security defects that help remove potentially exploitable bugs from code and improve the security of Azure services.

To thrive in this position, you will need to be a security software engineer with a deep technical understanding of a broad technology set and the ability to learn new information at a rapid pace. Previous experience in security consulting, penetration testing, and bug bounty research are important, but a desire to take on big challenges and help improve the overall service engineering process is equally vital. Requisition #: 1582553pca3lyuhf

View Jobs by Category >>

Related Jobs