Penetration Tester
Top focus
Overview We are a team in M365 Core called Substrate ; we have the massive responsibility and charter to help ensure the security and trustworthiness of M365 product suite. We want to reshape and modernize security to empower every user, customer, and developer with a secure cloud that protects them with end-to-end via our solutions.
The M365 Substrate organization accelerates Microsoft’s mission via bold ambitions to ensure that our company and industry are securing digital technology platforms, devices, and clouds across our estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day.
In doing so, we create life-changing innovations that impact billions of lives around the world. The Security Engineering team within M365 Core helps to identify threats and gaps in the infrastructure that hosts the planet's largest, most influential organizations.
We are looking for individuals who are forging the pentest discip line in new and modern ways in the era of AI. The role will encompass a blend of research and testing which we will guide our collective engineering organizations to secure their products in the most uniform and durable solutions possible.
This role as a Penetration Testing Specialist will provide you the opportunity to work on global scale services unique experiences which are hard to replicate or find outside of a major SaaS provider. You will research and perform offensive security operations against M365 backed infrastructure.
As a Penetration Testing Specialist you will perform research with your team to identify and validate vulnerabilities from external research as well as proactive engagements. We want to move from reactive to proactive, translating findings to actionable code fixes within the product groups.
You'll have access to the latest AI systems and the freedom to explore creative attack scenarios while contributing to the security of millions worldwide. Along with running offensive security operations, you will develop tooling and new code leveraging AI to look for vulnerabilities in a scalable manner.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day. Responsibilities Vulnerability Discovery & Exploitation: Find and validate security vulnerabilities through hands-on penetration testing, code review, and proof-of-concept exploit development.
Tooling & Automation: Build and maintain automated and autonomous tooling to scale offensive security testing and vulnerability discovery. Research & Threat Analysis: Investigate emerging attack techniques, exploit classes, and AI/agentic system threats.
Feed findings into testing priorities and architectural improvements. Security Architecture Collaboration: Work with Security Architecture and service teams to assess design-level risks, review threat models, and inform platform hardening based on offensive findings.
Reporting & Remediation: Write technical reports that clearly describe what's broken, the impact, and how to fix it. Track findings through to resolution with service owners. Detection & Blue Team Partnership: Work with detection engineering and blue teams to validate coverage and close detection gaps from offensive findings.
Qualifications Required Qualifications: Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection. 3+ years of experience in security research, penetration testing, or offensive security roles.
Hands-on experience discovering and exploiting vulnerabilities in AI systems and platforms. Proficiency in Python with experience in AI frameworks and security testing tools. Ability to read and analyze code across multiple languages and codebases
Preferred Qualifications
- Master's Degree in Statistics, Mathematics, Computer Science
- related field AND 3+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science
- related field AND 5+ years experience in security or related field OR equivalent experience. 5+ years of experience in penetration testing web applications, APIs, cloud infrastructure
- identity/authentication systems.
- Published security research or conference presentations on offensive security topics.
- Background in software engineering with distributed systems expertise.
- Security certifications such as OSCP, OSWE, GWAPT, or similar.
- Knowledge of service-to-service authentication, authorization models
- cloud-native architectures. #SECURITYANZ This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
- Microsoft is an equal opportunity employer.
- All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation
- any other characteristic protected by applicable local laws, regulations and ordinances.
- If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.