Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable local laws, regulations, and ordinances.
Security Engineer II - Windows Security (Multiple Positions)
Location
United States
Posted
52 days ago
Salary
$100K - $215K / year
Seniority
Mid Level
Job Description
Security Engineer II - Windows Security (Multiple Positions)
Microsoft
Overview The Microsoft Windows Security team is looking for a learn-it-all security engineer that will help secure Microsoft Windows products and devices, with focus on offensive security and security engineering & mitigations for Windows. The Windows Security team is responsible for securing the Windows client and server operating systems, used by billions of customers every day and in businesses worldwide. This team performs security design reviews, code reviews, penetration testing, vulnerability research and driving systematic mitigations to security risks on Windows to make sure they meet the highest possible security standards and proactively defend cybersecurity threats. This role is hands-on, technically demanding, and central to strengthening the security posture of OS platforms. In this Security Engineer II - Windows Security role, you will uncover novel attack vectors, develop proof-of-concept mitigations, and partner directly with Windows product engineering teams to design durable & scalable defense. The ideal candidate will have hands-on experience with native code (C/C++), penetration testing (code audit, writing fuzzers, finding creative ways to break assumptions), a clear understanding of OS security fundamentals, solid computer science skills, and a passion for keeping Microsoft customers safe. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. Responsibilities - Participate in security reviews to identify and mitigate risk in Microsoft products, including design reviews, code reviews, and fuzzing. - Be the security contact for teams building new innovative products and technologies in the next version of Windows and devices. - Identify security vulnerabilities in a wide variety of key OS features such as network protocols, security features, and Microsoft devices. - Leverage a broad and current understanding of security to devise new protections. - Interact with the external security community and security researchers. - Collaborate with product teams to improve security, and articulate the business value of security investments. Qualifications Required Qualifications: - Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in security or related field - OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in security or related field - OR equivalent experience. Other Requirements: Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings: - Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter. Preferred qualification: - 2+ years identifying vulnerabilities in operating systems and/or native (C/C++) applications. - 5+ years of experience in a software engineering or security-related engineering. - Public track record of relevant security research, especially around vulnerability discovery. - Experience exploiting bugs and bypassing security mitigations in operating systems. - Familiarity with Microsoft Windows architecture. #W+DJOBS Penetration Testing IC3 - The typical base pay range for this role across the U.S. is USD $100,600 - $199,000 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $131,400 - $215,400 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security Engineer
MarinerBy submitting your application, you agree to the collection and use of your personal information as described in our Employee and Applicant Privacy Notice. EOE M/F/D/V
• Engineer and operate modern security platforms. • Implement, run, and optimize enterprise-level security tooling across detection, identity, cloud, endpoint, and governance technologies. • Conduct deep-dive security assessments. • Evaluate systems, configurations, and architecture through hands-on testing and analysis—delivering actionable insights that directly influence engineering and business decisions. • Strengthen core security operations. • Support and mature processes such as: - Malware response and remediation - Vulnerability management and patch governance - SIEM log analysis, correlation, and monitoring - Incident documentation, reporting, and lifecycle management • Improve systems by design—not by accident. • Embed security into applications, infrastructure, and business initiatives from the outset, partnering with IT and engineering teams to identify risks and drive effective mitigations. • Contribute through data, insights, and experimentation. • Analyze trends, surface patterns, and help refine the firm’s Information Security Program through continuous improvement and cross-functional engagement.
Principal Information Security Engineer
UnitedHealth GroupUnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together. You will enjoy the flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges. Primary Responsibilities: - Serve as the functional subject matter expert for the Palo Alto Networks firewall and firewall policies - Making critical decisions on enterprise security policies - Utilizing the security monitoring tools to support audits (Ex: AlgoSec, Firemon) - Reporting and reviewing the compliance status and taking remediation actions - Determine the severity and complexity of issues pertaining to the security and protection of systems data, (autonomously or as part of a team) to ensure the protection, conservation and accountability of proprietary, personal, or privileged electronic data - Collaborate with directors, managers, and other technical personnel to ensure mitigation of security risks pertaining to the company - Evaluates and develops secure solutions, based on approved security architectures and standards - Promote continued integration of technological advances to further enhance security and reduce risks - Consults on various projects regarding secure design standards and security information management - Develop and direct implementation of security standards and best practices for the organization - Evaluates analysis of suggested solutions and innovative approaches to complex issues, as well as complex conceptual analysis, ensuring implementation - Plans, conducts, and responds to internal and external cyber security audits and questionnaires; interprets and documents audit results; recommends and implements corrective actions - Participate with cyber security analysts and architects, providing guidance and expertise in incident/issue response and resolution methodology - Defines, implements, audits, and maintains firewall security policies - Promote the development of innovative approaches and solutions to complex problems and issues - Works on highly complex projects and tasks that require in-depth knowledge of one or more specialized architecture areas such as security, applications, information, solution and business - Serve in a supervisory capacity, provide lead direction, ensuring the formulation and implementation of procedures and systems You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - Associate’s degree - 7+ years of experience with Palo Alto Firewall - 5+ years of Cloud Security experience - 5+ years of Security Architect experience - 5+ years of Firewall rule/policy compliance and governance experience - 5+ years of Firewall rule analysis and remediation experience - 5+ years of communication skills with team and customer engagement Preferred Qualifications: - Splunk experience - AlgoSec experience - Leadership skills - Basic coding capabilities Soft Skills: - Team player *All Telecommuters will be required to adhere to UnitedHealth Group’s Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 to $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location, and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment. #RPO #GREEN
Senior Corporate Security Engineer
NexthinkUnparalleled Visibility Into Issue Detection, Diagnosis, and Remediation
• As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. • You will be architecting the security fabric that enables our rapid growth. • Working in close partnership with IT, business teams and partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. • You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment. • Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles. • Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems. • Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf). • Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans. • Lead incident response activities for corporate security events (phishing, malware, lost devices).
Senior Corporate Security Engineer
NexthinkUnparalleled Visibility Into Issue Detection, Diagnosis, and Remediation
• Identity-Centric Security Architecture: Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles. • Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems. • Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability. • Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf). • Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS). • Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments & vulnerability scans. • Lead incident response activities for corporate security events (phishing, malware, lost devices). • Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions.


