Azure is at the center of Microsoft's cloud services strategy, both for external customers as well as for our own services. With the expedited growth of data and the popularity of our enterprise data platforms, Azure SQL Database System is one of our most critical platforms and our goal is to ensure we have the most reliable and trustworthy data platforms in the world.
The integrity and trust that we, Microsoft, and our customers have on these services and resources are of paramount importance for confidence in bringing critical business to the cloud. To achieve these goals, the Azure Data team is looking to expand the "blue-team" tasked with providing technology, monitoring, and reducing "operational toil" in detecting and defending this massive infrastructure and services from attack.
Your role will be to enhance current detection, build and contribute to foundational tooling that detects malicious activity and intruders quickly and ejects them from the system, via leveraging (and enhancing) existing instrumentation, building levers and dials needed for rapid response, as well as assisting forensic capabilities by constructing a timeline, actions, and the path intruders and bad actors have taken to get into our system. A partner red team, the Azure Data Attack Team, is comprised of Microsoft employees who work as hackers to intrude, elevate privilege, get to and own private data or other malfeasant actions (e.g. delete or corrupt VMs). They are at work constantly to find soft spots in the system to get where they should not be.
Your team, tools and services will meet them head on and success will be that your systems can detect malfeasant or anomalous activities in minutes and be able to shut those activities down. Many of our exercise are purple team like, and require close collaboration between red, blue and service teams to ensure the best possible outcomes.
Another key element of the role is that you will own the root cause analysis and identification of repair items that are needed to harden the fleet from attackers which necessitates strong partnership and engagement with product teams. This is a huge problem space. We're talking millions of devices in production, all kinds of attack vectors, and constant threat of breach.
Deep and broad understanding of security vulnerabilities and attacks (Hardware, Firmware, Software, Network, and People), and the ability to understand new ones based on new technology being developed.
3-7 years' experience in security and software engineering are a must
Strong Development skills, with experience in C#, C++.
Cloud services experience working in IaaS, PaaS or SaaS environment.
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.
We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Scale engineering first and foremost the blue team is an engineering team and will be building at scale solutions to defend Azure DB with little (if any) human involvement. Monitoring, alerting and vulnerability discovery across entire infrastructure, building big-data and distributed computing solutions are core elements of this team.
Emerging Threat Research - being on the forefront of emerging threats which affect cloud services and infrastructure. This includes understanding the attack vectors, behaviors, and tools that are being used in the wild as well as the most modern defenses. A very high level of creativity and thirst for knowledge are a must.
Partnerships with other teams the blue-team is a partner team to other Microsoft/Azure security teams that are tasked with other aspects of security like compliance, network monitoring, SDL, and Azure's own internal red-teams. Understanding what these teams are doing, the problems they face, and working on complementary efforts is key.
Livesite response much like other SRE teams, the blue-team will engage on security events driving to remediation by taking on actions and co-ordination responsibility, and then leading postmortem and RCA activities to identify engineering investments that obviate classes of issues and eliminates toil (repeated human actions).