This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Microsoft Edge Browser Security Team is responsible for securing Edge client code. Our work broadly fits into three distinct categories: Engagement, Proactive, and Reactive security. We work closely with developers, engaging with them to ensure principals such as defence in depth and secure by default are architected into everything we do. Additionally, we perform proactive vulnerability research and analysis at scale to highlight high risk attack surfaces and identify security bugs before hackers do. Finally, we ensure that our reactive response flows are monitored and maintained, tracking reports from external finders, and working with threat intelligence teams to stop active threats to our customers. Throughout all of this, you will work with our industry partners to contribute security improvements to the Chromium project to make the web safer for everyone.
Job Responsibility:
Analyse complex issues using multiple data sources to develop insights and identify security problems and threats
Identify and perform research on critical security areas, collaborate across teams, design preventive solutions, and escalate impactful findings appropriately
Help plan and execute strategies for growing Edge’s capabilities
Drive initiatives to identify and mitigate security risk for our customers
Oversee our security response work, acting on reports from vulnerability researchers
Monitor and alert the security health of Edge and plan remedial actions
Collaborate with other security teams across Microsoft to design and develop new security mitigations and defences
Work closely with our partners in the Chromium community to improve browser security
Leverage curiosity and learn new skills to operate in a fast-paced and ever-changing environment
Interact with the external security community, researchers and security conference presenters
Requirements:
Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field
Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
equivalent experience
Experience with relevant security research along with relevant CVEs (if available) ideally in browser vulnerability discovery
Experience with writing basic exploits for native or web applications
Development and deployment of fuzz testing and/or static analysis software