We are a team in M365 Core called Substrate; we have the massive responsibility and charter to help ensure the security and trustworthiness of M365 product suite. We want to reshape and modernize security to empower every user, customer, and developer with a secure cloud that protects them with end-to-end via our solutions. The M365 Substrate organization accelerates Microsoft’s mission via bold ambitions to ensure that our company and industry are securing digital technology platforms, devices, and clouds across our estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
The Security Engineering team within M365 Core helps to identify threats and gaps in the infrastructure that hosts the planet's largest, most influential organizations. We are looking for individuals who are forging the pentest discipline in new and modern ways in the era of AI. The role will encompass a blend of research and testing which we will guide our collective engineering organizations to secure their products in the most uniform and durable solutions possible.
This role as a Penetration Testing Specialist will provide you the opportunity to work on global scale services unique experiences which are hard to replicate or find outside of a major SaaS provider. You will research and perform offensive security operations against M365 backed infrastructure. As a Penetration Testing Specialist you will perform research with your team to identify and validate vulnerabilities from external research as well as proactive engagements. We want to move from reactive to proactive, translating findings to actionable code fixes within the product groups. You'll have access to the latest AI systems and the freedom to explore creative attack scenarios while contributing to the security of millions worldwide. Along with running offensive security operations, you will develop tooling and new code leveraging AI to look for vulnerabilities in a scalable manner.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
- Vulnerability Discovery & Exploitation: Find and validate security vulnerabilities through hands-on penetration testing, code review, and proof-of-concept exploit development.
- Tooling & Automation: Build and maintain automated and autonomous tooling to scale offensive security testing and vulnerability discovery.
- Research & Threat Analysis: Investigate emerging attack techniques, exploit classes, and AI/agentic system threats. Feed findings into testing priorities and architectural improvements.
- Security Architecture Collaboration: Work with Security Architecture and service teams to assess design-level risks, review threat models, and inform platform hardening based on offensive findings.
- Reporting & Remediation: Write technical reports that clearly describe what's broken, the impact, and how to fix it. Track findings through to resolution with service owners.
- Detection & Blue Team Partnership: Work with detection engineering and blue teams to validate coverage and close detection gaps from offensive findings.
Qualifications
Required Qualifications:
- Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection.
- 3+ years of experience in security research, penetration testing, or offensive security roles.
- Hands-on experience discovering and exploiting vulnerabilities in AI systems and platforms.
- Proficiency in Python with experience in AI frameworks and security testing tools.
- Ability to read and analyze code across multiple languages and codebases.
- Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in security or related field OR equivalent experience.
- 5+ years of experience in penetration testing web applications, APIs, cloud infrastructure, or identity/authentication systems.
- Published security research or conference presentations on offensive security topics.
- Background in software engineering with distributed systems expertise.
- Security certifications such as OSCP, OSWE, GWAPT, or similar.
- Knowledge of service-to-service authentication, authorization models, and cloud-native architectures.
#SECURITYANZ
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection.
- 3+ years of experience in security research, penetration testing, or offensive security roles.
- Hands-on experience discovering and exploiting vulnerabilities in AI systems and platforms.
- Proficiency in Python with experience in AI frameworks and security testing tools.
- Ability to read and analyze code across multiple languages and codebases.
- Master's Degree in related field OR additional years of security experience, published security research, distributed systems software engineering background, security certifications (OSCP, OSWE, GWAPT), and knowledge of service-to-service authentication, authorization models, and cloud-native architectures.
- 5+ years of experience in penetration testing web applications, APIs, cloud infrastructure, or identity/authentication systems.
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.








