OverviewWe’re looking for an experienced and driven Senior Security Engineer to join our STORM security research group and help shape the security posture of Microsoft Specialized Cloud systems from the ground up.
As part of our mission to embed security throughout the development lifecycle, you’ll lead security design reviews, threat modeling, and architectural security assessments across a wide range of technologies, from OS internals and virtualization to cloud platforms, containerized environments, application security, and AI-enabled systems.
This role combines deep security engineering and architecture expertise with a forward-looking approach to AI-assisted security engineering. You’ll be expected to reason deeply about complex systems and review designs hands-on, while also using and building AI-powered capabilities that make security analysis more effective, scalable, and repeatable.
This is a high-impact role for security engineers who thrive on technical depth, enjoy building, and want to influence secure design at scale.
ResponsibilitiesAnalyze systems and architectures to identify trust-boundary violations, architectural vulnerabilities, unsafe assumptions, and opportunities for security-driven redesign.
Design, prototype, and build AI-assisted security capabilities that augment design review, threat modeling, architecture analysis, vulnerability discovery, and other security engineering workflows.
Experiment with new approaches for combining security expertise, automation, and AI to improve the scale, depth, and consistency of security reviews.
QualificationsOperating system internals, including Windows/Linux, memory management, boot security, or platform security.
Cloud-native security, including identity, secrets management, isolation, and service-to-service trust.
🌟 Preferred Qualifications
Experience integrating LLMs or AI agents with existing engineering workflows, tools, data sources, or analysis pipelines.
Experience applying AI to security problems such as threat modeling, design analysis, code analysis, vulnerability discovery, or security automation.
Experience with scalable security analysis techniques, including static analysis, dynamic analysis, code analysis, or custom security automation.
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.