Security Software Development Engineer II, Trustworthy Computing Security Job
Job Field: Legal Jobs
Location: REDMOND, WA
Salary: $-
Job Type: Part Time
JOB SUMMARY:
</tr>
</table>
<table border="0" bgColor="#F5F5F5" cellpadding="5" cellspacing="0" style="border-collapse: collapse" width="100%">
<tr>
<td align="left"><font style="font-size: 100%;">Job Category:Software Engineering: Development<BR>Location:Redmond, WA, US<BR>Job ID:805970-91980<BR>Division:Corporate Research & Development<BR><BR>Would you enjoy helping to protect Microsoft''s biggest customers from security vulnerabilities? Would you enjoy being an important component of the MSRC security vulnerability servicing cycle? Do you like learning how different types of vulnerabilities work, down to the assembly level? Can you accurately describe deep technical concepts in ways that other engineers can understand? If so, the MSRC Engineering Defense team might be a good fit for you.<BR><BR>We have an immediate opening for a Security Software Engineer with the following duties:<BR><BR>(1) Research reported vulnerabilities to understand the factors that lead to the vulnerable code being hit.<BR>(2) Identify factors present in the default configuration that might help mitigate the vulnerability.<BR>(3) Find workarounds that customers can use to be safe, even at the cost of reduced functionality.<BR>(4) Build a way to reproduce the vulnerability.<BR>(5) Describe precisely what out-of-bounds data causes the vulnerability from reviewing the code and interacting with the affected product group.<BR>(6) Gather and summarize technical investigation notes created by other engineers in such a way that external partners understand the vulnerability.<BR><BR>Candidates need to have knowledge of Windows architecture or other in-depth knowledge of a product, security-mindedness and the ability to spot security ramifications of an error condition, and solid debugging and coding skills in C/C++.<BR><BR>Other traits that would make a candidate more attractive include experience triaging crashes for exploitability, experience with understanding assembly and exploits / malware, creativity in finding mitigations and workarounds that customer will be able to use, penetration testing experience, experience with common hacking / network tools, and the ability to reproduce vulnerabilities given incomplete reports.<BR><BR><BR>Join the TwC Security Team!<BR><BR><BR>CR:TWC </font></td>
</tr>
</table>
<table border="0" bgColor="#F5F5F5" cellpadding="0" cellspacing="0" style="border-collapse: collapse" width="100%">
<tr>