This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for experienced and driven senior security professionals to join our STORM security research group and help shape the security posture of Microsoft Specialized Cloud systems from the ground up. As part of our mission to embed security into all the development phases, you’ll lead design reviews, threat modeling, and security assessments across a wide range of technologies - from OS internals and virtualization to cloud platforms, containerized environments, and application security. This is a high-impact role for security professionals who thrive on technical depth, cross-team collaboration, and influencing secure design at scale.
Job Responsibility:
Lead security design and architecture reviews as well as threat modeling engagements for complex systems
Identify architectural vulnerabilities and guide engineering teams towards secure design patterns
Collaborate with security teams to identify vulnerabilities and embed security early in the product lifecycle
Communicate findings clearly to both technical and non-technical stakeholders
Drive security hardenings and security-driven redesign to improve security posture
Mentor engineers and promote a culture of security-first thinking
Requirements:
Expertise structured threat modeling and architectural risk analysis
Deep knowledge in one or more of the following: Operating System internals (Windows/Linux), memory management, and secure boot
Virtualization, Cloud Architecture, and Container security
Application Security principles and secure software development practices across microservices, APIs, and distributed systems
Cloud-native services and their security implications (e.g., identity, secrets management, service mesh, serverless)
6+ years in security engineering, architecture, or related roles
Demonstrated success in leading security reviews or threat modeling for large-scale systems
Prior experience in driving and managing internal security initiatives and integrating Secure Development Lifecycle (SDLC) concepts
Track record of identifying and mitigating vulnerabilities in OS, cloud, or infrastructure components
Proficiency in secure coding and code reviews
Familiarity with fuzzing and exploitation techniques
Nice to have:
Strong sense of Responsibility and Leadership skills
Excellent communication skills - able to articulate complex security issues clearly and persuasively
Proven ability to lead cross-functional engagements and influence product teams
Analytical mindset with a “learn-it-all” attitude and strong problem-solving skills
Comfortable navigating ambiguity and organizational complexity