Security Engineer
Job Description
Contribute to Microsoft Identity Security (IDSEC) Breach Preventions by building scalable engineering controls that stop repeat incidents across Microsoft Identity and Network Access services.
Responsibilities
- Convert breach learnings and threat actor behaviors into deterministic engineering controls that reduce the likelihood of recurrence across multiple services
- Design platform-level enforcement mechanisms to remove entire vulnerability classes without requiring service-by-service remediation
- Create reusable prevention frameworks and contribute to paved path security standards
- Work with engineering teams to integrate preventative controls into production environments while maintaining service reliability
- Support rapid deployment of security countermeasures across Microsoft’s identity fleet to strengthen defenses against emerging threats
- Translate breach and threat intelligence into platform-level countermeasures and integrate them into production
Requirements
- Master’s Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 1+ years experience across software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 2+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR equivalent experience
- Ability to meet Microsoft, customer and/or government security screening requirements, including the Microsoft Cloud Background Check
- Must pass Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter
- Additional education/experience paths include:
- Doctorate in the stated fields, OR Master’s degree in the stated fields AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Bachelor’s degree in the stated fields AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- 3+ years experience in Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), IT, or operations incident response
- Knowledge of identity and access technologies including OAuth, OIDC, SAML, tokens, certificates/PKI, and MFA
Technologies
- OAuth
- OIDC
- SAML
- SIEM
- PKI
- MFA
Security Research IC3 - Pay Ranges (U.S.)
- Typical base pay range: USD 102,100 - 202,200 per year
- Different base pay range applies to specific locations:
- San Francisco Bay area and New York City metropolitan area: USD 133,800 - 219,200 per year