Enable job alerts via email!

Principal Penetration Testing Engineer

Microsoft

City Of London

On-site

GBP 50,000 - 90,000

Full time

19 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Microsoft seeks a penetration tester to enhance the security of their services. The role involves executing tests, assessing vulnerabilities, and conducting research on security tools. Ideal candidates will have strong coding skills and experience in cybersecurity. This position requires UK citizenship due to legal restrictions.

Qualifications

  • Strong coding skills in C#, Python, C++, Go.
  • Experience with penetration testing and cloud security.
  • Ability to learn new attack vectors quickly.

Responsibilities

  • Plan and execute testing of Microsoft’s services and infrastructure.
  • Assess existing security capabilities and document risks.
  • Stay updated with penetration testing tools and methodologies.

Skills

Identifying security vulnerabilities
Cyber security
Anomaly detection
Collaboration
Exploiting bugs
Threat intelligence

Education

Master’s degree in computer science
Certifications GPEN, GWAPT, GXPN, OSCP, OSCE

Job description

Responsibilities
  • Plan, research, and execute testing of computer systems and applications to simulate real-world attacks on Microsoft’s services and infrastructure.
  • Assess existing security capabilities to detect and respond to emerging threats.
  • Outline and document risk impacts in executive summary reports and communicate findings to relevant stakeholders.
  • Perform research to stay current with penetration testing tools, methodologies, tactics, and mitigations.
  • Participate as an infrastructure/operation specialist in overt penetration testing engagements, including Purple Team exercises where we emulate real-world adversaries.
  • Develop and maintain penetration testing procedures and methodologies.
  • Conduct research to remain updated with the latest in application security, both offensive and defensive techniques, and share findings within the Microsoft Security Community.
Qualifications
  • Experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection.
  • Experience with penetration testing/red-teaming, cloud, services, and network security.
  • Strong coding skills in languages such as C#, Python, C++, Go, PowerShell, ASP.NET, JavaScript.
  • Preferred: Master’s degree in computer science, software engineering, information security, or equivalent work experience.
  • Certifications such as GPEN, GWAPT, GXPN, OSCP, OSCE, or similar.
  • Proven ability to learn new attack vectors quickly and creatively identify threats.
  • Effective collaboration skills and ability to handle ambiguity.
  • Experience with APT emulation, purple teaming, and threat intelligence.
  • Experience exploiting bugs and bypassing security mitigations in operating systems.
Other Requirements
  • This position requires UK citizenship verification due to legal restrictions, supporting UK government agency customers.
  • Ability to meet Microsoft, customer, and government security screening requirements, including passing the Microsoft Cloud Background Check annually.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration without regard to age, ancestry, gender, or other protected characteristics. For disability accommodations, please contact us via the Accommodation request form.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Principal Penetration Testing Engineer

Microsoft

London

On-site

GBP 75,000 - 120,000

3 days ago
Be an early applicant