Senior Security Design Engineer

MicrosoftIsraelOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

<b>Overview</b><br><div><p><span>We’re looking for an experienced and driven Senior Security Engineer to join our STORM security research group and help shape the security posture of Microsoft Specialized Cloud systems from the ground up.</span><span> </span></p></div><div><p><span>As part of our mission to embed security throughout the development lifecycle, you’ll lead security design reviews, threat modeling, and architectural security assessments across a wide range of technologies, from OS internals and virtualization to cloud platforms, containerized environments, application security, and AI-enabled systems.</span><span> </span></p></div><div><p><span>This role combines </span><span>deep security engineering and architecture expertise with a forward-looking approach to AI-assisted security engineering</span><span>. You’ll be expected to reason deeply about complex systems and review designs hands-on, while also using and building AI-powered capabilities that make security analysis more effective, scalable, and repeatable.</span><span> </span></p></div><div><p><span>This is a high-impact role for security engineers who thrive on technical depth, enjoy building, and want to influence secure design at scale.</span><span> </span></p></div><br><br><b>Responsibilities</b><br><div><p><span>🔍</span><span> What You’ll Do</span><span> </span></p></div><div><ul style="list-style-type: disc;"><li><p><span>Lead security design and architecture reviews and structured threat modeling engagements for complex systems. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Analyze systems and architectures to identify trust-boundary violations, architectural vulnerabilities, unsafe assumptions, and opportunities for security-driven redesign. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Partner closely with engineering and security teams to influence architecture early in the product lifecycle and guide teams toward secure design patterns. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Perform security analysis using a combination of deep manual investigation and AI-augmented workflows, applying engineering judgment to validate findings and challenge assumptions. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Design, prototype, and build AI-assisted security capabilities that augment design review, threat modeling, architecture analysis, vulnerability discovery, and other security engineering workflows. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Experiment with new approaches for combining security expertise, automation, and AI to improve the scale, depth, and consistency of security reviews. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Communicate security findings, design tradeoffs, and recommended mitigations clearly to both technical and non-technical stakeholders. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Drive security hardening and security-driven redesign efforts that address systemic weaknesses rather than individual vulnerabilities. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Help evolve our security engineering methodology, tooling, and practices as AI changes how both products and security analysis are built. </span><span> </span></p></li></ul></div><br><br><b>Qualifications</b><br><div><div><ul style="list-style-type: disc;"><li><p><span>Strong experience in security engineering, security architecture, or related technical security roles. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Deep technical knowledge in one or more of the following areas: </span><span> </span></p></li></ul></div><div><ul style="list-style-type: circle;"><li><p><span>Operating system internals, including Windows/Linux, memory management, boot security, or platform security. </span><span> </span></p></li></ul></div></div><div><div><ul style="list-style-type: circle;"><li><p><span>Virtualization, confidential computing, cloud architecture, or container security. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: circle;"><li><p><span>Containerized environments incl. Kubernetes and AKS</span><span> </span></p></li></ul></div><div><ul style="list-style-type: circle;"><li><p><span>Application security and secure software development across services, APIs, and distributed systems. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: circle;"><li><p><span>Cloud-native security, including identity, secrets management, isolation, and service-to-service trust. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Experience building with modern AI technologies to solve real engineering or security problems and designing workflows where AI augments expert analysis</span><span> </span></p></li></ul><p><span><span>🌟</span><span> Preferred Qualifications</span>  <br><br></span></p><div><ul style="list-style-type: disc;"><li><p><span>Expertise in structured threat modeling, architectural risk analysis, and reasoning about complex systems and trust boundaries. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Ability to prototype and build tools rather than only consume existing security tooling. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Experience integrating LLMs or AI agents with existing engineering workflows, tools, data sources, or analysis pipelines. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Experience applying AI to security problems such as threat modeling, design analysis, code analysis, vulnerability discovery, or security automation. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Understanding of security challenges introduced by AI-enabled systems and the ability to threat-model systems incorporating AI components. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Experience with scalable security analysis techniques, including static analysis, dynamic analysis, code analysis, or custom security automation. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Prior expertise and experience with Azure-based solutions and services</span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Strong understanding of secure coding and code review principles.</span><span> <br></span></p><div><div><p><span><br>🤝</span><span> Leadership &amp; Collaboration</span><span> </span></p></div><div><ul style="list-style-type: disc;"><li><p><span>Strong sense of ownership and responsibility. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Excellent communication skills, with the ability to articulate complex security issues and design tradeoffs clearly and persuasively. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Proven ability to lead cross-functional technical engagements and influence engineering teams without direct authority. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Analytical and curious mindset with a strong drive to understand how systems actually work. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Comfortable navigating ambiguity and working on problems where neither the security answer nor the engineering solution is predetermined. </span><span> </span></p></li></ul></div></div><div><div><ul style="list-style-type: disc;"><li><p><span>Builder mindset: willing to experiment, prototype, iterate, and turn promising ideas into capabilities that other security engineers can use. </span><span> </span></p></li></ul></div><div><p><span><br>📈</span><span> Experience &amp; Impact</span><span> </span></p></div><div><ul style="list-style-type: disc;"><li><p><span>6+ years of experience in security engineering, architecture, software engineering, or related roles. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Demonstrated success leading security design reviews, threat modeling, or architectural security assessments for complex systems. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Track record of identifying and helping mitigate significant architectural or system-level security weaknesses. </span><span> </span></p></li></ul></div><div><ul style="list-style-type: disc;"><li><p><span>Experience influencing engineering decisions and driving security improvements across organizational boundaries. </span><span> </span></p></li></ul></div></div><p> </p></li></ul></div></div></div> <br><p>This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.</p><br><hr><br><p>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about <a href="https://careers.microsoft.com/v2/global/en/accessibility.html"><b><u>requesting accommodations.</u></b></a></p>