AI Penetration Tester - Cybersecurity Team

59 Minutes ago • 4-8 Years • Cyber Security

About the job

Job Description

The TrIP Offensive Cyber Security Team at Microsoft seeks an AI Penetration Tester to identify security flaws across their technology estate. Responsibilities include discovering and exploiting vulnerabilities in AI systems, executing offensive operations on production systems using real-world adversarial tactics, developing tools to accelerate vulnerability discovery, collaborating on mitigation strategies, researching emerging threats (prompt injection, etc.), and producing high-quality reports. The ideal candidate possesses solid technical skills, a passion for identifying security flaws, and experience with penetration testing tools (Kali Linux, Burp Suite, etc.). They will work with production AI systems impacting millions of users.
Must have:
  • 4+ years experience in security vulnerabilities and software development
  • Experience using penetration testing tools (Kali Linux, Burp Suite, etc.)
  • Coding proficiency (C, C++, C#, Java, JavaScript, PowerShell, Python)
  • Discover and exploit vulnerabilities in AI systems
  • Execute offensive operations on production AI systems
Good to have:
  • Penetration testing qualifications (PNPT, GPEN/GXPN, GWAPT, OSCP/OSCE, CRT/CCT/CCSAS)
  • Familiarity with MITRE ATLAS/OWASP top 10 LLMS
  • Experience developing novel tooling and techniques
Perks:
  • Industry leading healthcare
  • Educational resources
  • Discounts on products and services
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Opportunities to network and connect

Overview

The Trust and Integrity Protection (TrIP) team supports the company’s overall security and privacy mission by providing key security services that help protect systems, services, data 

  

Are you passionate about identifying security vulnerabilities and risks in enterprise-scale systems with specific focus on Artificial Intelligence? Do you want the challenge of conducting penetration tests against some of the world’s most cutting-edge technology implementations? Are you a red teamer and interested in Artificial intelligence (AI) and excited about technology like GPT4? Do you want to find and exploit security vulnerabilities in Microsoft’s largest AI systems impacting millions of users?  

  

The TrIP Offensive Cyber Security Team is an interdisciplinary group of  internal penetration testing and offensive security team, tasked with identifying security flaws across the entire Microsoft Customer and Partner Solutions (MCAPS) technology estate. 

  

We are looking for an AI Penetration Tester - Offensive Cybersecurity Team to help make AI security better.   

  

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

Qualifications

Required Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, PowerShell or Python
    • OR equivalent experience.
  • 4+ years experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection.
  • 4+ years of experience of using common penetration testing tools; Kali Linux, Burpsuite, Nmap, Nessus, etc.

Preferred Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python

    • OR Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python

    • OR equivalent experience.
  • Penetration testing qualifications; PNPT, GPEN/GXPN, GWAPT, OSCP/OSCE, CRT/CCT/CCSAS and/or equivalent.
  • Familiarity with MITRE ATLAS/OWASP top 10 LLMS.
  • Proficient in developing novel tooling and techniques, as well as utilizing existing methodologies, should consistently explore possibilities and persistently push the boundaries.

Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications and processes offers for these roles on an ongoing basis.

 

 

 

#EDOTjobs

Responsibilities

  • Discover and exploit vulnerabilities end-to-end in order to assess the security of AI systems 
  • Execute offensive operations on production AI systems using real world adversarial tactics and techniques to identify failures 
  • Develop tools and techniques to scale and accelerate offensive emulation and vulnerability discovery specific for AI systems 
  • Collaborate with teams to influence measurement and mitigations of these vulnerabilities in AI systems 
  • Research new and emerging threats to inform the organization including prompt injection, improve red teaming efficacy and accuracy, and stay relevant. 
  • As an AI Penetration Tester for TrIP’s Offensive Cybersecurity Team, you will discover and exploit vulnerabilities end-to-end in order to assess the security of AI systems. 
  • Execute Penetration Testing operations on production AI systems using real world adversarial tactics and techniques to identify failures. 
  • The candidate who is well-suited for this role will possess solid technical skills, coupled with a passion for identifying security flaws and developing innovative solutions. 
  • Develop tools and techniques to scale and accelerate offensive emulation and vulnerability discovery specific for AI systems. 
  • Perform research to stay current with penetration testing tools, methodologies, tactics, and mitigations. 
  • Develop, operationalize and maintain penetration testing procedures and methodologies. 
  • Produce high-quality papers, presentations, as well as recommendations to key stakeholders. 
  • Research new and emerging threats to inform the organization, improve red teaming efficacy and accuracy, and stay relevant. 
  • Team up with other Offensive Security personnel at Microsoft to leverage the latest trends, and identify good opportunities for attack. 
  • Discovery of Problems/Identifying Vulnerabilities in Generative AI and AI systems. 
  • Regularly assess security, identify and fix vulnerabilities, create threat models, review code for security flaws, and perform security tests (SAST, DAST, IAST) to uncover application vulnerabilities.
  • Embody our and . 
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect
View Full Job Description
$117.2K - $250.2K/yr (Outscal est.)
$183.7K/yr avg.
Redmond, Washington, United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

London, England, United Kingdom (On-Site)

Redmond, Washington, United States (On-Site)

Bengaluru, Karnataka, India (On-Site)

Redmond, Washington, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Similar Jobs

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Prodigy Education - Lead, Automation QA - Game

Prodigy Education, Canada (On-Site)

IGT - Systems Engineer IV

IGT, Philippines (On-Site)

Meta - Software Engineering Manager, Product

Meta, United States (Remote)

ByteDance - LLM Coding Trainer - Specialist

ByteDance, Singapore (On-Site)

Rush Street Interactive - Senior Server Engineer

Rush Street Interactive, Estonia (On-Site)

ION - Senior Java Developer - Italy

ION, Italy (On-Site)

Google - Application Engineering Manager

Google, India (On-Site)

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Sandbox VR - Retail Associate

Sandbox VR, United States (On-Site)

DraftKings - Senior Software Engineer, Android

DraftKings, United States (Remote)

The Walt Disney Company - Sr Machine Learning Engineer

The Walt Disney Company, United States (On-Site)

SMU Guildhall - Faculty - Video Game Development

SMU Guildhall, United States (On-Site)

Google - Senior Research Scientist, Google Research

Google, United States (On-Site)

Sandbox VR - Retail Associate

Sandbox VR, United States (On-Site)

Nintendo - Lighting Artist

Nintendo, United States (Remote)

Twitch - Senior Software Engineer - Mobile

Twitch, United States (On-Site)

Google - ASIC Design Engineer, Platform IP, Silicon

Google, United States (On-Site)

Get notifed when new similar jobs are uploaded