Description
We are a team in M365 Core called Substrate; we have the massive responsibility and charter to help ensure the security and trustworthiness of M365 product suite.
The Security Engineering team within M365 Core helps to identify threats and gaps in the infrastructure that hosts the planet’s largest, most influential organizations.
As a Penetration Testing Specialist, you will research and perform offensive security operations against M365 backed infrastructure.
Responsibilities
- Vulnerability Discovery & Exploitation: Find and validate security vulnerabilities through hands-on penetration testing, code review, and proof-of-concept exploit development.
- Tooling & Automation: Build and maintain automated and autonomous tooling to scale offensive security testing and vulnerability discovery.
- Research & Threat Analysis: Investigate emerging attack techniques, exploit classes, and AI/agentic system threats.
- Security Architecture Collaboration: Work with Security Architecture and service teams to assess design-level risks, review threat models, and inform platform hardening based on offensive findings.
- Reporting & Remediation: Write technical reports that clearly describe what’s broken, the impact, and how to fix it.
- Detection & Blue Team Partnership: Work with detection engineering and blue teams to validate coverage and close detection gaps from offensive findings.
Qualifications
Required Qualifications:
- Bachelor’s Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection.
- 3+ years of experience in security research, penetration testing, or offensive security roles.
- Hands-on experience discovering and exploiting vulnerabilities in AI systems and platforms.
- Proficiency in Python with experience in AI frameworks and security testing tools.
- Ability to read and analyze code across multiple languages and codebases.
Preferred Qualifications:
- Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in security or related field OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in security or related field OR equivalent experience.
- 5+ years of experience in penetration testing web applications, APIs, cloud infrastructure, or identity/authentication systems.
- Published security research or conference presentations on offensive security topics.
- Background in software engineering with distributed systems expertise.
- Security certifications such as OSCP, OSWE, GWAPT, or similar.
- Knowledge of service-to-service authentication, authorization models, and cloud-native architectures.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://microsoft.ai/job/penetration-tester-2/