Security Engineer II

Microsoft
San Francisco, CA, United States
13 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$102,100.0 - $202,200.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Microsoft Online Services C++ (Programming Language) Code Review Network Protocols Software Engineering Cyber Threat Analysis Information Technology Windows Security Operating System Security Server Operating Systems & Platforms
+2 more
Windows Client Vulnerability Analysis

Job description

The Windows Security team is responsible for securing the Windows client and server operating systems, used by billions of customers every day and in businesses worldwide. This team performs security design reviews, code reviews, penetration testing, vulnerability research and driving systematic mitigations to security risks on Windows to make sure they meet the highest possible security standards and proactively defend cybersecurity threats. This role is hands-on, technically demanding, and central to strengthening the security posture of OS platforms. In this Security Engineer II - Windows Security role, you will uncover novel attack vectors, develop proof-of-concept mitigations, and partner directly with Windows product engineering teams to design durable & scalable defense. The candidate will have hands-on experience with native code (C/C++), penetration testing (code audit, writing fuzzers, finding creative ways to break assumptions), a clear understanding of OS security fundamentals, solid computer science skills, and a passion for keeping Microsoft customers safe. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Build reusable agents and tools to expedite and improve the consistency and quality of security reviews.
  • Review features and code for security defects and architectural risk using agents and automated tools built by you and others.
  • Be the security contact for teams building new innovative products and technologies in the next version of Windows and devices.
  • Identify security vulnerabilities in a wide variety of key OS features such as network protocols, security features, and Microsoft devices Leverage a broad and current understanding of security to devise new protections.
  • Interact with the external security community and security researchers.
  • Collaborate with product teams to improve security, and articulate the business value of security investments.

Requirements

  • Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in security or related field.
  • OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in security or related field.
  • OR equivalent experience.

Additional or preferred qualifications

Other Requirements:Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings:

  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter., * 2+ years identifying vulnerabilities in operating systems and/or native (C/C++) applications.
  • 5+ years of experience in a software engineering or security-related engineering.
  • Public track record of relevant security research, especially around vulnerability discovery.
  • Experience exploiting bugs and bypassing security mitigations inoperatingsystems.
  • Familiarity with Microsoft Windows architecture.

W+DJOBS

WARP

Penetration Testing IC3 - The typical base pay range for this role across the U.S. is USD $102,100 - $202,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $133,800 - $219,200 per year.

About the company

The Microsoft Windows Security team is looking for a learn-it-all security engineer that will help secure Microsoft Windows products and devices, with focus on offensive security and security engineering & mitigations for Windows.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

3:24 min

Transitioning static data fetching to real-time live queries

Noam Honig · LIVE

4:19 min

Prompt engineering techniques and security vulnerabilities

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:23 min

Mitigating social engineering and identifying technical security resources

Vandana Verma · LIVE

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

Videos

See all

Related articles

See all