Software Engineering IC3
As a member of the Security Engineering team, you will have an opportunity to contribute your deep technical and problem-solving skills directly to the security of many Microsoft products used by millions of customers, including Office 365, OneDrive, SharePoint, Microsoft Teams, Skype, and Cortana. You will work on securing production code and infrastructure, as well as our engineering systems against malicious outsider and insider attacks.
Responsibilities
- Design and implementation of security engineering and security automation projects, working with a variety of stakeholders.
- Develop and test code with top-notch quality, reliability, maintainability, and user experience focus.
- Collaborate with your team, as well as stakeholders in peer teams and organizations to deliver production-grade solutions that scale and work across multiple products.
- Communicate progress and issues effectively and early, proactively seeking help when stuck.
Required
- 3-5 years of development experience in an object-oriented programming language (C#, Java, etc.)
- A Bachelor’s degree in Computer Science or equivalent experience
- Experience in designing, coding, debugging and testing cloud services
- Solid understanding of software design and development techniques
- Knowledge of common security vulnerabilities/mitigations
- Able to work independently and also collaborating with peer team members
- Able to communicate effectively with different audiences
- Able to deal with ambiguity, multi-task and deliver features against tight deadlines
- Motivated, proactive, and results-driven
- Proficient with a cloud computing environment like Azure, GCP or AWS.
- Experience with CICD pipelines/automation, agile/scrum processes
- Ability to reason about security challenges and propose practical solutions
- Knowledge of Security Development Lifecycle, security standards and frameworks like NIST, OWASP, etc.
- Experience implementing security features/automated mitigations for common security issues.
- Experience with security tools/techniques such as SAST, DAST, fuzzing, pen-testing, etc.
- Exposure to security protocols and infrastructure components such as OAuth, OIDC, PKI, IRM, A/AD, etc.
- Experience with reporting technologies/frameworks such as PowerBI.
- Experience with Kusto or other big data stores