Offensive Cybersecurity Penetration Tester

43 Minutes ago • 2-4 Years • Cyber Security • $98,300 PA - $208,800 PA

Job Summary

Job Description

The TrIP Offensive Cyber Security Team at Microsoft seeks an Offensive Cybersecurity Penetration Tester to enhance AI security. Responsibilities include discovering and exploiting vulnerabilities in AI systems, executing offensive operations on production systems using real-world adversarial tactics, developing tools to accelerate vulnerability discovery, collaborating on mitigation strategies, researching emerging threats (like prompt injection), and producing reports and presentations. The ideal candidate possesses solid technical skills, a passion for identifying security flaws, and experience with penetration testing tools (Kali Linux, BurpSuite, etc.). This role involves working on Microsoft's largest AI systems, impacting millions of users.
Must have:
  • Bachelor's Degree in CS or related field
  • 2+ years technical engineering experience
  • 1+ year experience identifying security vulnerabilities
  • Experience with penetration testing tools
  • Coding experience (C, C++, C#, Java, JavaScript, PowerShell, Python)
Good to have:
  • Penetration testing certifications (PNPT, GPEN/GXPN, etc.)
  • Microsoft Azure Certifications
  • Familiarity with MITRE ATLAS/OWASP top 10 LLMs

Job Details

Overview

The Trust and Integrity Protection (TrIP) team supports the company’s overall security and privacy mission by providing key security services that help protect systems, services, data.

 

Are you passionate about identifying security vulnerabilities and risks in enterprise-scale systems with specific focus on Artificial Intelligence (AI)? Do you want the challenge of conducting penetration tests against some of the world’s most cutting-edge technology implementations? Are you a red teamer and interested in AI and excited about technology like Generative Pretrained Transformer 4 (GPT4)? Do you want to find and exploit security vulnerabilities in Microsoft’s largest AI systems impacting millions of users?

 

The TrIP Offensive Cyber Security Team is an interdisciplinary group of internal penetration testing and offensive security team, tasked with identifying security flaws across the entire Microsoft Customer and Partner Solutions (MCAPS) technology estate.

 

We are looking for an Offensive Cybersecurity Penetration Tester to help make AI security better. 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Qualifications

Required Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 2+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, PowerShell or Python
    • OR equivalent experience.
  • 1+ years experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection.
  • 1+ years of experience of using common penetration testing tools; Kali Linux, Burpsuite, Nmap, Nessus, etc.

Preferred Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 4+ years  technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python 
    • OR Master's Degree in Computer Science or related technical field AND 2+ years  technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python 
    • OR equivalent experience.
  • Penetration testing qualifications; PNPT, GPEN/GXPN, GWAPT, OSCP/OSCE, CRT/CCT/CCSAS and/or equivalent.
  • Microsoft Azure Certifications; AZ-900, AZ-500, AI-900.
  • Familiarity with MITRE ATLAS/ OWASP top 10 LLMS.

Software Engineering IC3 - The typical base pay range for this role across the U.S. is USD $98,300 - $193,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $127,200 - $208,800 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until April 26, 2025.

 

 

 

#EDOTjobs

Responsibilities

  • Discover and exploit vulnerabilities end-to-end in order to assess the security of AI systems.
  • Execute offensive operations on production AI systems using real world adversarial tactics and techniques to identify failures.
  • Develop tools and techniques to scale and accelerate offensive emulation and vulnerability discovery specific for AI systems.
  • Collaborate with teams to influence measurement and mitigations of these vulnerabilities in AI systems.
  • Research new and emerging threats to inform the organization including prompt injection, improve red teaming efficacy and accuracy, and stay relevant.
  • As an AI Penetration Tester for TrIP’s Offensive Cybersecurity Team, you will discover and exploit vulnerabilities end-to-end in order to assess the security of AI systems.
  • Execute Penetration Testing operations on production AI systems using real world adversarial tactics and techniques to identify failures.
  • The candidate who is well-suited for this role will possess solid technical skills, coupled with a passion for identifying security flaws and developing innovative solutions.
  • Develop tools and techniques to scale and accelerate offensive emulation and vulnerability discovery specific for AI systems.
  • Perform research to stay current with penetration testing tools, methodologies, tactics, and mitigations.
  • Develop, operationalize and maintain penetration testing procedures and methodologies.
  • Produce high-quality papers, presentations, as well as recommendations to key stakeholders.
  • Research new and emerging threats to inform the organization, improve red teaming efficacy and accuracy, and stay relevant.
  • Team up with other Offensive Security personnel at Microsoft to leverage the latest trends, and identify good opportunities for attack.
  • Discovery of Problems/Identifying Vulnerabilities in Generative AI and AI systems.
  • Embody our and .

Similar Jobs

Reframe - Android Engineer

Reframe

United States (Remote)
9 Months ago
Netflix - Senior Software Engineer — Testing Tools & Infrastructure

Netflix

Warsaw, Masovian Voivodeship, Poland (On-Site)
2 Months ago
ByteDance - Software Engineer

ByteDance

San Jose, California, United States (On-Site)
1 Day ago
GoTo Group - Senior Data Warehouse Engineer (India)

GoTo Group

Gurugram, Haryana, India (On-Site)
6 Months ago
Meta - Software Engineer, Infrastructure

Meta

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
5 Months ago
PwC - Risk Services - Communication and Marketing Specialist

PwC

Singapore (On-Site)
6 Months ago
PwC - IT Audit Senior Manager

PwC

Bangkok, Bangkok, Thailand (On-Site)
6 Months ago
Axinous - Customer Success Engineer

Axinous

Tokyo, Japan (Remote)
5 Months ago
ByteDance - Red Team Engineer, Security Assurance

ByteDance

Singapore (On-Site)
5 Months ago
PwC - IN_Associate_Internal Audit_Internal Audit Services_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Virtusa - Ab Initio Tester

Virtusa

Chennai, Tamil Nadu, India (On-Site)
8 Months ago
Axinous - Principal Software Engineer (ZDX Platform Engineering)

Axinous

San Jose, California, United States (Hybrid)
4 Months ago
ByteDance - Software Development Engineer - Distributed NoSQL Database Systems

ByteDance

Seattle, Washington, United States (On-Site)
3 Months ago
Google - Software Engineer, PhD, Early Career, Campus, Systems and Infrastructure, 2025 Start

Google

Atlanta, Georgia, United States (On-Site)
5 Months ago
N-iX - Senior QA Engineer

N-iX

Poland (Remote)
2 Months ago
Hashlist - Data Scientist

Hashlist

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
Hashlist - Senior Data Engineer

Hashlist

Pune, Maharashtra, India (Hybrid)
5 Months ago
NVIDIA - Senior SRE Software Engineer, Storage and Data

NVIDIA

Taipei City, Taiwan (On-Site)
2 Months ago
NVIDIA - Senior Software Video Engineer

NVIDIA

Yokne'am Illit, North District, Israel (On-Site)
3 Weeks ago
ByteDance - Software Engineer - Low-code Platform

ByteDance

Singapore (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Epic Games - Gameplay Animator

Epic Games

Cary, North Carolina, United States (On-Site)
3 Months ago
Nintendo - Recruiting Coordinator

Nintendo

Redmond, Washington, United States (Hybrid)
2 Months ago
Onward Search - Inside Sales Representative

Onward Search

Cranbury, New Jersey, United States (On-Site)
3 Weeks ago
Inworld AI - People Ops/HR Lead

Inworld AI

Mountain View, California, United States (Hybrid)
3 Weeks ago
ByteDance - Backend Software Engineer - CapCut - San Jose

ByteDance

San Jose, California, United States (On-Site)
4 Months ago
Aristocrat Gaming - Senior Accountant Revenue

Aristocrat Gaming

Las Vegas, Nevada, United States (Hybrid)
1 Month ago
Next Level Business Services - Bigdata / Hadoop Architect

Next Level Business Services

Oldsmar, Florida, United States (On-Site)
6 Months ago
Nissan - Warehouse Operator - Memphis

Nissan

Memphis, Tennessee, United States (On-Site)
6 Months ago
KingsIsle Entertainment - Senior Community Manager

KingsIsle Entertainment

Round Rock, Texas, United States (Hybrid)
3 Weeks ago
Dentsu - Manager, Media Technology

Dentsu

New York, New York, United States (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Epic Games - Senior Vulnerability Manager

Epic Games

(On-Site)
3 Weeks ago
PwC - Assurance Technology Risk & Quality Manager

PwC

Dublin, County Dublin, Ireland (On-Site)
6 Months ago
PwC - Cloud Security Engineering - Senior Manager

PwC

Prague, Prague, Czechia (On-Site)
6 Months ago
The Walt Disney Company - Senior Security Specialist, Third-Party Risk Management

The Walt Disney Company

New York, New York, United States (On-Site)
3 Weeks ago
ByteDance - Site Reliability Engineer Lead, Security Engineering

ByteDance

Singapore (On-Site)
5 Months ago
Axinous - Customer Success Manager, Spain

Axinous

(Remote)
2 Months ago
ION - Network Security Engineer

ION

Castellazzo Bormida, Piedmont, Italy (Hybrid)
6 Months ago
Plarium - SecOps Team Lead

Plarium

Herzliya, Tel Aviv District, Israel (On-Site)
2 Months ago
The Walt Disney Company - Security Specialist, Compliance

The Walt Disney Company

Burbank, California, United States (On-Site)
2 Days ago
Mattel  Inc  - Manager GRC

Mattel Inc

California, United States (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Redmond, Washington, United States (Hybrid)

New York, New York, United States (On-Site)

Redmond, Washington, United States (On-Site)

Beijing, Beijing, China (On-Site)

Hyderabad, Telangana, India (On-Site)

Barcelona, Catalonia, Spain (On-Site)

Prague, Prague, Czechia (Hybrid)

Prague, Prague, Czechia (Hybrid)

São Paulo, State Of São Paulo, Brazil (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug