Security Researcher
CurrentMicrosoft Azure is at the center of Microsoft’s cloud services strategy. Azure brings together virtualization, compute, storage, authentication, authorization, media and more to enable anyone to bring their business in the cloud. The Azure Development Security Engineering organization focuses on ensuring that Azure is the most secure platform in the world for developers and a secure experience for millions of users worldwide.Responsibilities (C+AI Security):• Perform end-to-end deep security and architecture analysis across multiple solutions/applications and recommend potential mitigation strategies.• Conduct threat modeling and architecture reviews to identify and address vulnerabilities and weaknesses, guiding teams on implementation.• Exhibits subject matter expertise in class or set of security issues, tools, mitigations, and processes.• Identify and respond to customer and partner security issues in a timely manner.• Understand connections between identified issues and up- and down-stream processes.• Identify and prioritize viable attack vectors.• Prioritize and schedule work, taking into consideration dependencies, and makes compromises to meet deadlines.• Design and deliver security solutions, collaborating with service teams for rapid adoption and threat mitigation.• Develop security guidelines to address weaknesses and establish best practices.• Review documentation and specifications to uncover potential security vulnerabilities and their impact.• Vulnerability discovery and variant hunting. Use the best available and most appropriate methodologies, including threat modeling, penetration testing, security design analysis, fuzzing, SAST and DAST, etc., looking for vulnerabilities and weaknesses, perform variant hunting looking for larger patterns, conduct qualitative and quantitative analysis over those patterns, and drive solutions upstream in a data-driven, shift-left fashion.• Support security research of Microsoft & competitor products.