Senior Security Engineer

Microsoft
Cambridge, UK
7 days ago
Apply on jobs.theguardian.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£74,700.0 - £122,600.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Microsoft Azure Microsoft Online Services C++ (Programming Language) Code Review Fuzz Testing Intrusion Detection and Prevention Reverse Engineering Software Engineering Operating System Security Vulnerability Analysis

Job description

In this role, you will work across the discovery and mitigation of security vulnerabilities - identifying weaknesses in systems, understanding their impact, and helping drive protections that improve the security of Microsoft platforms at scale. You will partner with engineers across Windows, Azure, and platform infrastructure to deliver security improvements and influence the way systems are designed and built.

This role is well suited to engineers who enjoy deep systems work, solving complex problems, and delivering high impact security outcomes.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond

Responsibilities

  • Drive identification and analysis of security vulnerabilities across operating system and platform components, including design review, code review, fuzzing, and variant analysis
  • Develop and influence mitigations and protections that reduce risk across platforms, improving resilience against entire classes of vulnerabilities
  • Collaborate with engineering teams to integrate security into the development lifecycle, influencing design decisions and improving secure engineering practices
  • Contribute to the development and scaling of security tooling, detection capabilities, or analysis techniques that enable broader coverage and earlier detection of vulnerabilities
  • Partner across organisations to translate security findings into systemic improvements and measurable security outcomes
  • Stay current on attacker techniques, emerging vulnerability classes, and industry trends, applying this knowledge to improve Microsoft’s security posture
  • Provide technical leadership within and across teams, contributing to direction setting, problem decomposition, and delivery of complex security initiatives

Requirements

  • Significant experience in security-related elements of software engineering or in another security-related field.
  • Hands on experience with systems level programming languages such as C, C++, or Rust.

Other Requirements:

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter., * Public or internal track record of relevant security research
  • Understanding of operating system security fundamentals, including kernel or low level platform components
  • Experience performing vulnerability research, including code review, fuzzing, reverse engineering, or exploit development
  • Experience developing or applying mitigations, such as memory safety protections, sandboxing, or platform hardening techniques

Penetration Testing IC4 - The typical base pay range for this role across United Kingdom is £ 74,700.00 - £ 122,600.00 per year. Certain roles may be eligible for benefits and other compensation.

About the company

The Microsoft Offensive Research & Security Engineering (MORSE) team is looking for a Senior Security Engineer to help secure Microsoft’s products and devices.MORSE is responsible for securing Microsoft’s operating systems and platform technologies, cloud platforms, and virtualisation technologies that support the daily needs of over a billion customers worldwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.theguardian.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

3:40 min

Integrating mutation testing and fuzzing into software workflows

Michael Contento · World Congress 2023

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all