Penetration Tester: Internship Opportunities
Microsoft · Redmond, WA · 1 wk ago
Hybrid$6k–$11k/moFull-time
About the role
The Microsoft Offensive Research & Security Engineering (MORSE) team is responsible for securing Microsoft's operating systems, including Windows, cloud computing platforms, and virtualization technologies. These solutions support the daily needs of over one billion customers worldwide. This team performs security design reviews, code reviews, and vulnerability research on key features of Windows and Azure to make sure they meet the highest possible security standards.
Responsibilities
- Participates in security reviews to identify and mitigate risk in Microsoft products, including design reviews, code reviews, and fuzzing
- Be the security contact for teams building new innovative products and technologies in the next version of Windows and Azure
- Identifies security vulnerabilities in a wide variety of key OS features such as network protocols, security features, and Microsoft devices
- Leverages a broad and current understanding of security to devise new protections
- Interacts with the external security community and security researchers
- Collaborates with product teams to improve security, and articulate the business value of security investments
Qualifications
- Currently pursuing a Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field, with at least one semester/term of school remaining following the completion of the internship
- OR currently pursuing a Master's Degree in Statistics, Mathematics, Computer Science, or related field, with at least one semester/term of school remaining following the completion of the internship
Preferred skills
- Currently pursuing a Master's Degree in Statistics, Mathematics, Computer Science or related field
- Participation in security competitions such as Capture the Flag (CTF)
- Experience exploiting bugs (e.g., buffer overflows, use-after-free) and bypassing security mitigations in operating systems
- Experience creating and running fuzzers (e.g., AFL, libFuzzer)
- Experience with reverse engineering and binary analysis using tools such as IDA Pro, Binary Ninja, or Ghidra
- Experience with debuggers or other dynamic analysis tools such as WinDbg, GDB, LLDB, Frida, Pin, angr, etc.
- Reliable experience in code auditing and performing static analysis to identify vulnerabilities
Pay
Base pay range: USD $5,690.00 - $11,210.00 per month. For specific work locations within the San Francisco Bay area and New York City metropolitan area, the base pay range is USD $7,410.00 - $12,250.00 per month.