Penetration Tester, SERPENT: Internship Opportunities
Microsoft (Eightfold Apply)
- Location
- United States, Washington, Redmond
- Employment
- Internship
- Work model
- On-Site
- Level
- Intern
- Posted
- 2h ago
Skills
About this role
Overview
Come build community, explore your passions and do your best work at Microsoft with thousands of University interns from every corner of the world. This opportunity will allow you to bring your aspirations, talent, potential—and excitement for the journey ahead. SERPENT (Services Pentest) is looking for a learn-it-all engineer excited to secure Microsoft products and devices through real-world penetration testing, research, and security innovation. Are you looking for a challenge that puts you at the center of the Microsoft Specialized Clouds strategy? Are you passionate about solving the security challenges of critical, large-scale online services? Do you want to learn how Microsoft defends some of the world’s most important cloud and device ecosystems? If you’re passionate about penetration testing, variant research, and reliable security, this role is for you. Microsoft’s Specialized Clouds organization is responsible for securing some of Microsoft’s largest and most influential online services across the Adaptive Cloud and Windows + Devices (W+D) organization. The EPSF Services Pentest (SERPENT) team is expanding and looking for interns who want to grow their offensive security skills while helping increase our business partners’ security posture. EPSF Security has a world-class penetration testing team that helps ensure a safe, resilient experience for millions of users worldwide. We focus heavily on offensive security, application security, variant discovery, and collaborating with defensive teams to enhance detection and operational awareness. At Microsoft, Interns work on real-world projects in collaboration with teams across the world, while having fun along the way. You’ll be empowered to build community, explore your passions and achieve your goals. This is your chance to bring your solutions and ideas to life while working on cutting-edge technology. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. #EiP Responsibilities • Participates in penetration tests, security reviews, and variant-hunting exercises for Microsoft products and services—including design reviews, code reviews, and exploit proof-of-concept development • Supports analysis of emerging threats and contribute to improving the security of next-generation Windows, Azure, and specialized cloud services • Applies a current and evolving understanding of offensive security techniques to propose new protections and reinforce secure design • Engages with internal and external security researchers, contributing to a culture of curiosity and continuous learning • Collaborates with product teams to improve security posture and articulate the business value of security insights • Participates in the SERPENT OODA Loop (Observe → Orient → Decide → Act) to scale offensive insights across Microsoft Qualifications Required Qualifications: Currently pursuing a Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field, or related field with at least one semester/term of school remaining following the completion of the internship OR Currently pursuing a Master's Degree in Statistics, Mathematics, Computer Science, or related field, or related field with at least one semester/term of school remaining following the completion of the internship. Other Requirements: Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This