Specialized Cloud Security Researcher - MSC STORM at Microsoft
Herzliya, Tel-Aviv District, Israel -
Full Time


Start Date

Immediate

Expiry Date

19 Feb, 26

Salary

0.0

Posted On

21 Nov, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Cloud Security, Kubernetes Security, Container Security, Virtualization, VM Isolation, IoT Security, AI Security, Offensive Security Research, Vulnerability Discovery, Exploitation Techniques, Penetration Testing, Programming Languages, Scripting Languages, Incident Response, Defensive Security, Mentoring

Industry

Software Development

Description
Research and discover zero-day vulnerabilities in cloud and on-prem environments and associated technologies. Develop and implement proof-of-concept exploits to demonstrate potential risks and work closely with engineering teams to address findings. Design mitigations at scale for found vulnerabilities and work with engineering teams to integrate these mitigations. Collaborate with cross-functional teams to assess the impact of identified threats and propose mitigation strategies. Provide detailed reports outlining vulnerabilities, exploitation techniques, and recommended remediation steps. Create and maintain cutting-edge vulnerability discovery, exploitation, and penetration testing tools. Stay abreast of the latest security research and integrate innovative techniques into the offensive security toolkit. Collaborate with internal security teams to enhance overall security posture, including incident response and defensive security. Participate in knowledge-sharing initiatives, mentor junior team members, and contribute to the security community. Proven track record of discovering and responsibly disclosing security vulnerabilities. Expertise in any of the following domains: Cloud security: Azure, AWS, GCP. Kubernetes and container security Virtualization and VM isolation IOT security AI security SENIOR: 6+ years of hands-on experience in offensive security research, with 2+ years of focus on cloud environments. SWE II: 4+ years of hands-on experience in offensive security research, with 2+ years of focus on cloud environments. Proficiency in multiple programming and scripting languages. Bachelor's degree or equivalent in Computer Science, Information Security, or related field. Advanced degrees are a plus. Strong written and verbal communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences.
Responsibilities
Research and discover zero-day vulnerabilities in cloud and on-prem environments. Develop proof-of-concept exploits and collaborate with engineering teams to design and integrate mitigations.
Loading...