Microsoft

Conseiller(ère) principal(e) en sécurité / Senior Security Engineer

Microsoft • $114K — $203K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Master's in Statistics, Mathematics, Computer Science, or related field AND 3+ years of security experience OR Bachelor's in similar field AND 4+ years of security experience OR equivalent experience.
  • Hands-on offensive security experience, including penetration testing and vulnerability research.
  • Experience identifying vulnerabilities in operating systems and/or C/C++ applications.
  • 5+ years of experience in software engineering or a related technical field (preferred).
  • Familiarity with Microsoft Windows architecture and operating system internals (preferred).

Responsibilities

  • Conduct vulnerability research and offensive security assessments using various techniques.
  • Engage with security communities to track emerging vulnerabilities and attack techniques.
  • Review product architecture and native code to identify security vulnerabilities and risks.
  • Develop proof-of-concept exploits and scalable mitigations for identified vulnerabilities.
  • Design reusable security tools and automation to improve security evaluations.
  • Collaborate with Windows product teams to integrate security into product design.

Benefits

  • Work with a leading technology company in the cybersecurity field.
  • Opportunity to contribute to enterprise-level security for widely-used operating systems.
  • Chance to collaborate with expert teams and security communities.
  • Exposure to cutting-edge security technologies and practices.
  • Potential for career growth within a large, global organization.
Full Job Description
Overview

(English will follow)

L'équipe de sécurité Microsoft Windows est à la recherche d'un Conseiller(ère) principal(e) en sécurité pour contribuer à protéger les produits et appareils Windows grâce à des techniques de sécurité offensive, à la recherche de vulnérabilités et au développement de mesures d'atténuation de sécurité évolutives.

L'équipe de sécurité Windows contribue à protéger les systèmes d'exploitation Windows pour clients et serveurs utilisés par des particuliers et des entreprises partout dans le monde. L'équipe réalise des revues de conception et de code axées sur la sécurité, des tests d'intrusion et des recherches sur les vulnérabilités, tout en développant des mécanismes de défense visant à renforcer Windows face à l'évolution des menaces de cybersécurité.

Dans ce rôle, vous identifierez et analyserez des vulnérabilités de sécurité complexes ainsi que de nouveaux vecteurs d'attaque dans Windows. Vous développerez des preuves de concept d'exploitation et concevrez des mesures d'atténuation durables visant aussi bien des vulnérabilités individuelles que des catégories plus larges de problèmes de sécurité. Vous mettrez à profit votre connaissance approfondie du code natif, de la sécurité des systèmes d'exploitation, de la recherche de vulnérabilités et des techniques de sécurité offensive, tout en collaborant avec les équipes de développement Windows afin d'intégrer la sécurité à l'architecture et à la conception des produits.

The Microsoft Windows Security team is looking for a Senior Security Engineer to help secure Windows products and devices through offensive security, vulnerability research, and the development of scalable security mitigations.

The Windows Security team helps protect Windows client and server operating systems used by customers and businesses worldwide. The team performs security design and code reviews, penetration testing, and vulnerability research while developing defenses that strengthen Windows against evolving cybersecurity threats.

In this role, you will identify and investigate complex security vulnerabilities and novel attack vectors across Windows, develop proof-of-concept exploits, and design durable mitigations for individual vulnerabilities and broader classes of security issues. You will apply deep knowledge of native code, operating system security, vulnerability research, and offensive security techniques while partnering with Windows engineering teams to incorporate security into product architecture and design.

Responsibilities
  • Mener des recherches sur les vulnérabilités et des évaluations de sécurité offensive dans Windows, en utilisant notamment l'audit de code, le fuzzing, les tests d'intrusion et l'exploitation de vulnérabilités afin d'identifier des failles, de nouveaux vecteurs d'attaque et des risques de sécurité complexes, puis de développer des mécanismes de défense durables.
  • Collaborer avec les communautés de sécurité internes et externes afin de suivre l'évolution des vulnérabilités et des techniques d'attaque, et d'identifier des occasions de renforcer la sécurité de Windows.
  • Examiner l'architecture des produits, les fonctionnalités et le code natif afin d'identifier les vulnérabilités et les risques architecturaux à l'aide de techniques d'analyse de sécurité manuelles et automatisées.
  • Développer des preuves de concept d'exploitation et des mesures d'atténuation évolutives permettant de corriger les vulnérabilités identifiées ainsi que des catégories plus larges de problèmes de sécurité.
  • Concevoir et développer des outils de sécurité réutilisables et des solutions d'automatisation afin d'améliorer l'efficacité, la cohérence et la qualité des évaluations de sécurité et de la découverte de vulnérabilités.
  • Collaborer avec les équipes de développement de produits Windows afin d'intégrer la sécurité à la conception des produits et de résoudre les vulnérabilités et les risques de sécurité identifiés.


  • Conduct vulnerability research and offensive security assessments across Windows, using techniques such as code auditing, fuzzing, penetration testing, and exploitation to identify vulnerabilities and no
  • complex security risks, and develop durable defenses.
  • Engage with internal and external security communities to understand emerging vulnerabilities, attack techniques, and opportunities to strengthen Windows securityvel attack vectors.
  • Review product architecture, features, and native code to identify security vulnerabilities and architectural risks using manual and automated security analysis techniques.
  • Develop proof-of-concept exploits and scalable mitigations that address identified vulnerabilities and broader classes of security issues.
  • Design and build reusable security tools and automation that improve the efficiency, consistency, and quality of security reviews and vulnerability discovery.
  • Partner with Windows product engineering teams to incorporate security into product design, resolve


Qualifications

Qualifications requises/minimales
  • Maîtrise en statistique, en mathématiques, en informatique ou dans un domaine connexe ET au moins 3 ans d'expérience en sécurité ou dans un domaine connexe, OU baccalauréat en statistique, en mathématiques, en informatique ou dans un domaine connexe ET au moins 4 ans d'expérience en sécurité ou dans un domaine connexe, OU expérience équivalente.
  • Expérience pratique des techniques de sécurité offensive, notamment les tests d'intrusion, la recherche de vulnérabilités, le développement d'exploits ou le contournement des mécanismes de protection des systèmes d'exploitation.
  • Expérience dans l'identification de vulnérabilités dans les systèmes d'exploitation et/ou les applications natives (C/C++).

Qualifications supplémentaires ou souhaitées
  • Maîtrise en statistique, en mathématiques, en informatique ou dans un domaine connexe ET au moins 6 ans d'expérience en sécurité ou dans un domaine connexe, OU baccalauréat en statistique, en mathématiques, en informatique ou dans un domaine connexe ET au moins 8 ans d'expérience en sécurité ou dans un domaine connexe, OU expérience équivalente.
  • Au moins 5 ans d'expérience en développement logiciel, en sécurité ou dans un domaine technique connexe.
  • Expérience démontrée en recherche en sécurité, particulièrement dans la découverte de vulnérabilités.
  • Expérience dans l'exploitation de vulnérabilités et le contournement des mécanismes de protection des systèmes d'exploitation.
  • Bonne connaissance de l'architecture de Microsoft Windows et des composants internes des systèmes d'exploitation.


Required/minimum qualifications

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field OR equivalent experience.
  • Hands-on experience with offensive security techniques such as penetration testing, vulnerability research, exploit development, or bypassing operating-system security mitigations
  • Experience identifying vulnerabilities in operating systems and/or native (C/C++) applications.


Additional or preferred qualifications

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field OR equivalent experience.
  • 5+ years of experience in software engineering, security engineering, or a related technical field.
  • Demonstrated experience in security research, particularly vulnerability discovery.
  • Experience exploiting vulnerabilities and bypassing security mitigations in operating systems.
  • Familiarity with Microsoft Windows architecture and operating system internals.


#W+DJOBS

#WARP

Penetration Testing IC4 - The typical base pay range for this role across Canada is CAD $114,400 - CAD $203,900 per year.

Find additional pay information here:
https://careers.microsoft.com/v2/global/en/canada-pay-information.html

Penetration Testing IC4 - L'échelle salariale de base typique pour ce rôle dans l'ensemble du Canada est de 114,400 $ CAD à 203,900 $ CAD par année.

Pour plus d'information au sujet de la rémunération, veuillez cliquer ici:
https://careers.microsoft.com/v2/global/en/canada-pay-information.html

Ce poste sera ouvert pendant au moins cinq jours et les candidatures seront acceptées de façon continue jusqu'à ce que le poste soit pourvu.

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

About Microsoft

Microsoft is an American multinational corporation that develops, manufactures, licenses, supports, and sells a range of software products and services. Microsoft’s devices and consumer (D&C) licensing segment licenses the Windows operating system and related software, Microsoft Office for consumers, and the Windows Phone operating system. The company’s computing and gaming hardware segment provides Xbox gaming and entertainment consoles and accessories, second-party and third-party video games, and Xbox Live subscriptions; surface devices and accessories; and Microsoft PC accessories. Its phone hardware segment offers Lumia smartphones and other non-Lumia phones. Its D&C segment provides Windows Store, Xbox Live transactions, and Windows phone store; search advertising; display advertising; Office 365 Home and Office 365 Personal; first-party video games; and other consumer products and services as well as operating retail stores. Microsoft’s commercial licensing segments license server products, including Windows Server, Microsoft SQL Server, Visual Studio, System Center, and related Client Access Licenses (CALs); Windows Embedded; Windows operating system; Microsoft Office for business, including Office, Exchange, SharePoint, Lync, and related CALs; Microsoft Dynamics business solutions; and Skype. Its commercial segment offers enterprise services, including premier support services and Microsoft consulting services; commercial cloud comprising Office 365 Commercial, other Microsoft Office online offerings, Dynamics CRM Online, and Microsoft Azure; and other commercial products and online services. The company markets and distributes its products through original equipment manufacturers, distributors, and resellers, as well as online.

Microsoft Careers

Join Microsoft today and be part of a company that values innovation, leadership, and diversity in its workforce. As a global leader in technology and digital transformation, Microsoft offers unparalleled job opportunities that propel your career to new heights.

Explore Career Opportunities at Microsoft

Whether you're a seasoned professional looking for your next challenge or a recent graduate eager to start your career, Microsoft has a position that suits your skills and ambitions. We are committed to fostering a culture of growth and learning, where every team member is supported in expanding their horizons.

Internship Programs

Kickstart your career with a Microsoft internship. Our internships provide invaluable workplace experience and networking opportunities in a supportive and dynamic environment. You'll work on real projects, learn from industry leaders, and gain the skills necessary for a successful career in technology.

Employment Benefits

Choosing a career at Microsoft means more than just a job. Our employees enjoy a range of benefits designed to empower them both professionally and personally. These include comprehensive health benefits, flexible working conditions, and opportunities for career advancement through professional development and diversity training.

Inclusive Culture and Diversity

At Microsoft, we believe that innovation comes from diversity of thought and inclusion. We are committed to a workplace where everyone feels valued and inspired. Our leadership is dedicated to fostering an environment where diverse perspectives lead to breakthrough innovations and a competitive edge.

Grow with Us

Career growth at Microsoft is about more than climbing the corporate ladder; it's about continuous learning, expanding your skills, and improving your capabilities. With access to various leadership and training programs, you can evolve as a professional and make a significant impact within the company and on the global stage.

Hiring Process

Our hiring process is designed to identify true potential. Starting with a review of your resume, followed by interviews that assess your problem-solving abilities and cultural fit, we ensure that all candidates have a fair chance to demonstrate their strengths and potential to contribute to our team.

Networking and Professional Development

Microsoft is a place where you can build a professional network that spans the globe. Our employees benefit from connections with top-tier professionals and industry leaders, which opens doors to innovative projects and collaborative opportunities that are second to none.

Join Our Team

If you're ready to take on exciting challenges and make a difference in the world of technology, explore the job opportunities at Microsoft. Search for open positions that match your skills and interests, and prepare to embark on a rewarding career path filled with innovation and opportunities for personal and professional growth.

Stay Connected

Keep up to date with the latest at Microsoft Careers by subscribing to our job alert emails. Get tailored content that aligns with your career preferences and discover the exciting and rewarding opportunities that await at Microsoft.

SEARCH MICROSOFT JOBS

At Microsoft, your future is limitless. Join us in our mission to empower every person and every organization on the planet to achieve more. Your journey with Microsoft starts here.
Learn more about Microsoft
Size
181,000 employees
Market Cap
$1,762.4 billion
Industry
Net Income
$51.3 billion
Founded
1975
5 Year Trend
+15.5%
Revenue
$153.2 billion
NASDAQ

Similar Jobs

More Jobs at Microsoft

More Information Technology Jobs

Find similar Conseiller(ère) principal(e) en sécurité / Senior Security Engineer jobs: