Offensive Cybersecurity Penetration Tester

1 Month ago • 2-4 Years • Cyber Security • $98,300 PA - $208,800 PA

Job Summary

Job Description

The TrIP Offensive Cyber Security Team at Microsoft seeks an Offensive Cybersecurity Penetration Tester to enhance AI security. Responsibilities include discovering and exploiting vulnerabilities in AI systems, executing offensive operations on production systems using real-world adversarial tactics, developing tools to accelerate vulnerability discovery, collaborating on mitigation strategies, researching emerging threats (like prompt injection), and producing reports and presentations. The ideal candidate possesses solid technical skills, a passion for identifying security flaws, and experience with penetration testing tools (Kali Linux, BurpSuite, etc.). This role involves working on Microsoft's largest AI systems, impacting millions of users.
Must have:
  • Bachelor's Degree in CS or related field
  • 2+ years technical engineering experience
  • 1+ year experience identifying security vulnerabilities
  • Experience with penetration testing tools
  • Coding experience (C, C++, C#, Java, JavaScript, PowerShell, Python)
Good to have:
  • Penetration testing certifications (PNPT, GPEN/GXPN, etc.)
  • Microsoft Azure Certifications
  • Familiarity with MITRE ATLAS/OWASP top 10 LLMs

Job Details

Overview

The Trust and Integrity Protection (TrIP) team supports the company’s overall security and privacy mission by providing key security services that help protect systems, services, data.

 

Are you passionate about identifying security vulnerabilities and risks in enterprise-scale systems with specific focus on Artificial Intelligence (AI)? Do you want the challenge of conducting penetration tests against some of the world’s most cutting-edge technology implementations? Are you a red teamer and interested in AI and excited about technology like Generative Pretrained Transformer 4 (GPT4)? Do you want to find and exploit security vulnerabilities in Microsoft’s largest AI systems impacting millions of users?

 

The TrIP Offensive Cyber Security Team is an interdisciplinary group of internal penetration testing and offensive security team, tasked with identifying security flaws across the entire Microsoft Customer and Partner Solutions (MCAPS) technology estate.

 

We are looking for an Offensive Cybersecurity Penetration Tester to help make AI security better. 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Qualifications

Required Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 2+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, PowerShell or Python
    • OR equivalent experience.
  • 1+ years experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection.
  • 1+ years of experience of using common penetration testing tools; Kali Linux, Burpsuite, Nmap, Nessus, etc.

Preferred Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 4+ years  technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python 
    • OR Master's Degree in Computer Science or related technical field AND 2+ years  technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python 
    • OR equivalent experience.
  • Penetration testing qualifications; PNPT, GPEN/GXPN, GWAPT, OSCP/OSCE, CRT/CCT/CCSAS and/or equivalent.
  • Microsoft Azure Certifications; AZ-900, AZ-500, AI-900.
  • Familiarity with MITRE ATLAS/ OWASP top 10 LLMS.

Software Engineering IC3 - The typical base pay range for this role across the U.S. is USD $98,300 - $193,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $127,200 - $208,800 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until April 26, 2025.

 

 

 

#EDOTjobs

Responsibilities

  • Discover and exploit vulnerabilities end-to-end in order to assess the security of AI systems.
  • Execute offensive operations on production AI systems using real world adversarial tactics and techniques to identify failures.
  • Develop tools and techniques to scale and accelerate offensive emulation and vulnerability discovery specific for AI systems.
  • Collaborate with teams to influence measurement and mitigations of these vulnerabilities in AI systems.
  • Research new and emerging threats to inform the organization including prompt injection, improve red teaming efficacy and accuracy, and stay relevant.
  • As an AI Penetration Tester for TrIP’s Offensive Cybersecurity Team, you will discover and exploit vulnerabilities end-to-end in order to assess the security of AI systems.
  • Execute Penetration Testing operations on production AI systems using real world adversarial tactics and techniques to identify failures.
  • The candidate who is well-suited for this role will possess solid technical skills, coupled with a passion for identifying security flaws and developing innovative solutions.
  • Develop tools and techniques to scale and accelerate offensive emulation and vulnerability discovery specific for AI systems.
  • Perform research to stay current with penetration testing tools, methodologies, tactics, and mitigations.
  • Develop, operationalize and maintain penetration testing procedures and methodologies.
  • Produce high-quality papers, presentations, as well as recommendations to key stakeholders.
  • Research new and emerging threats to inform the organization, improve red teaming efficacy and accuracy, and stay relevant.
  • Team up with other Offensive Security personnel at Microsoft to leverage the latest trends, and identify good opportunities for attack.
  • Discovery of Problems/Identifying Vulnerabilities in Generative AI and AI systems.
  • Embody our and .

Similar Jobs

JustPlay - Backend Engineer

JustPlay

Berlin, Berlin, Germany (Hybrid)
1 Month ago
ION - Java Developer, Budapest

ION

Budapest, Hungary (Hybrid)
7 Months ago
Trustana - Senior Data Engineer

Trustana

Gurugram, Haryana, India (Hybrid)
7 Months ago
Google - Software Engineer II, Embedded, Pixel Power

Google

Warsaw, Masovian Voivodeship, Poland (On-Site)
1 Month ago
Applike Group - Director of Technology (f/m/d)

Applike Group

Hamburg, Hamburg, Germany (Hybrid)
7 Months ago
The Walt Disney Company - Security Specialist, Third-Party Risk Management

The Walt Disney Company

Burbank, California, United States (On-Site)
1 Month ago
Google - Security Consultant Architect

Google

Atlanta, Georgia, United States (On-Site)
1 Month ago
Crunchyroll - Principal Technical Product Manager - Application Security

Crunchyroll

San Francisco, California, United States (On-Site)
2 Months ago
GLG - Senior Security Operations Engineer

GLG

Gurugram, Haryana, India (Remote)
7 Months ago
Google - Software Engineer, Basic Input Output System (BIOS), Platforms

Google

Sunnyvale, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Limit Break - Unity UI Engineer (Japan)

Limit Break

Tokyo, Japan (On-Site)
1 Month ago
Google - Software Engineer III, Android Enterprise

Google

Bucharest, Bucharest, Romania (On-Site)
1 Month ago
ARHS - Fullstack Developer

ARHS

Liège, Wallonia, Belgium (On-Site)
7 Months ago
Netflix - Software Engineer 6 - Games Engineering

Netflix

United States (Remote)
1 Month ago
Push Gaming - Senior Game Mathematician

Push Gaming

(Remote)
1 Month ago
Microsoft - Senior DPU Software Engineer - Secure Enclave

Microsoft

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Google - Security Engineer, Detection

Google

New York, New York, United States (On-Site)
1 Month ago
Google - Software Engineer, PhD

Google

Sunnyvale, California, United States (On-Site)
1 Month ago
Google - Senior Software Engineer, Infrastructure, Core

Google

Mexico City, Mexico City, Mexico (On-Site)
1 Month ago
N-iX - Senior Data Engineer (#2327)

N-iX

Ukraine (Remote)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Nagarro - Associate Principal Consultant, Business Analyst

Nagarro

New York, New York, United States (On-Site)
7 Months ago
Aspyr Media - Head of Production

Aspyr Media

Austin, Texas, United States (On-Site)
11 Months ago
Nintendo - Bilingual Communications Coordinator

Nintendo

Redmond, Washington, United States (Hybrid)
11 Months ago
Meta - UXR Research Leader [Growth Team]

Meta

Menlo Park, California, United States (On-Site)
6 Months ago
Penumbra - Network Operations Engineer

Penumbra

Alameda, California, United States (Hybrid)
7 Months ago
Valve corporation - Economist

Valve corporation

Bellevue, Washington, United States (On-Site)
6 Months ago
Tencent - Game Publishing Manager

Tencent

Washington, United States (On-Site)
1 Month ago
ByteDance - Brand Partnership Manager

ByteDance

Austin, Texas, United States (On-Site)
1 Month ago
Canva - Revenue Operations Manager, NPI

Canva

Seattle, Washington, United States (Remote)
1 Month ago
NVIDIA - Hardware Product Quality Manager

NVIDIA

Santa Clara, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - IN-Senior Associate – D365 POS Technical-Ms Dynamics–Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Notion - Application Security Engineer

Notion

San Francisco, California, United States (On-Site)
6 Months ago
Google - Staff Software Engineer, UI

Google

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Meta - Product Security Engineer

Meta

Bellevue, Washington, United States (On-Site)
6 Months ago
Snowprint Studios - IT & Cybersecurity Lead/Manager

Snowprint Studios

Stockholm, Stockholm County, Sweden (On-Site)
2 Months ago
PwC - Senior Associate - Data Engineer - D&AT IFS

PwC

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Google - Security Engineer, Infrastructure Security, Service Hardening

Google

New York, New York, United States (On-Site)
1 Month ago
PwC - IN-Associate _Business Analyst _Citizen Services _Advisory _Chennai

PwC

Chennai, Tamil Nadu, India (On-Site)
7 Months ago
Granicus - Cloud Network Security Engineer

Granicus

Bengaluru, Karnataka, India (Hybrid)
7 Months ago
Netflix - Engineering Manager, Security Incident Response

Netflix

Poland (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Vancouver, British Columbia, Canada (On-Site)

Mountain View, California, United States (Hybrid)

Shenzhen, Guangdong Province, China (On-Site)

Noida, Uttar Pradesh, India (On-Site)

Sydney, New South Wales, Australia (Remote)

Redmond, Washington, United States (On-Site)

Paris, Île-de-France, France (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug