1 day ago
Redmond, WA, USAMid Level
H1B sponsor
Base Salary
$102k - $219k/yr
Responsibilities
- Execute security assurance reviews, threat-modeling engagements, Secure Development Lifecycle assessments, and automated security-analysis workflows.
- Analyze service architectures, data flows, trust boundaries, cloud resources, identities, endpoints, network configurations, privileged access, code-security signals, and data-protection signals.
- Build scripts, queries, APIs, and automation to collect evidence, analyze security signals, assess configurations, and reduce manual review effort.
- Validate automated and AI-generated findings, investigate false positives, confirm affected scope, and gather supporting evidence.
- Document findings, track remediation, review closure evidence, and collaborate with service owners and developers on mitigation.
- Create monitoring, reports, reusable security checks, review templates, documentation, guidance, and automated workflows to improve review coverage and program health.
Requirements
- Bachelor's degree in Computer Science or a related technical field and 2+ years of technical engineering experience with coding, or equivalent experience.
- Coding experience with languages such as C, C++, C#, Java, JavaScript, or Python.
- Foundational experience with security assessments, threat modeling, vulnerability management, application security, cloud security, or secure software development.
- Understanding of authentication, authorization, least privilege, encryption, network security, secrets management, logging, and data protection.
- Experience analyzing technical information, documenting findings, collaborating with engineering or security stakeholders, and tracking remediation.
- Experience using programming, scripting, or query languages such as C#, Python, SQL, PowerShell, or Kusto Query Language for security analysis or automation.
- Experience with Microsoft Azure or another major cloud platform.
- Preferred qualifications include a master's degree with 3+ years of experience, or a bachelor's degree with 5+ years of experience, plus experience with identity and access management, Azure DevOps, GitHub, security compliance, audit readiness, APIs, automated workflows, and security certifications such as Security+, Azure Security Engineer Associate, or SSCP.
Benefits
- Certain roles may be eligible for benefits and other compensation; additional benefits and pay information is available through Microsoft's careers site.
- The position is open for at least five days and accepts applications on an ongoing basis until filled.
About Microsoft
Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.
