Security Engineer
Job Description
Microsoft’s Windows Security team is seeking a Security Engineer to support offensive security work and security engineering focused on Windows client and server platforms. In this role, you will help uncover attack vectors, drive mitigations, and build security tooling that improves the speed and consistency of reviews across key parts of the operating system.
This position is based in the United States (onsite). The salary range for the role is USD 85,400 - 183,700 per year, with typical base pay and location-specific ranges noted below.
What you’ll do
- Build reusable agents and tools that expedite and improve the consistency and quality of security reviews.
- Review features and code for security defects and architectural risk using agents and automated tools developed by you and others.
- Act as the security contact for teams delivering new products and technologies in the next version of Windows and related devices.
- Identify vulnerabilities across a wide range of critical OS areas including network protocols, security features, and Microsoft devices.
- Apply broad, current security knowledge to design new protections for Windows.
- Engage with the external security community and security researchers.
- Collaborate with product teams to strengthen security and communicate the business value of security investments.
Required qualifications
- Bachelor's Degree in Statistics, Mathematics, Computer Science, or a related field.
- OR equivalent experience.
- Ability to meet Microsoft, customer and/or government security screening requirements for this role.
- Successful completion of the Microsoft Cloud background check upon hire or transfer, and again every two years thereafter.
Preferred qualifications
- Master's Degree in Statistics, Mathematics, Computer Science, or a related field, plus 1+ year of experience in security or a related field.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or a related field, plus 2+ years of experience in security or a related field.
- 2+ years identifying vulnerabilities in operating systems and/or native applications.
- Public track record of relevant security research, especially vulnerability discovery.
- Experience exploiting bugs and bypassing security mitigations in operating systems.
- Familiarity with Microsoft Windows architecture.
Technologies
- C/C++
Base pay ranges
- Typical base pay range across the U.S.: USD 85,400 - 168,100 per year.
- San Francisco Bay area and New York City metropolitan area base pay range: USD 111,100 - 183,700 per year.
Certain roles may be eligible for benefits and other compensation. Additional benefits and pay information: https://careers.microsoft.com/us/en/us-corporate-pay.