Role at a glance
- Job function
-
Software Engineering & IT Cybersecurity
- Salary
- $188K – $304.2K/yr
- Location
- Redmond, Washington, United States
- Work arrangement
- On-site
- Employment
- Full-time
- Experience
- Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience...
- Education
- Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience...
Spotted an issue?
We’ll check it against the original posting.
Role Summary
The Principal Security Engineer works with Microsoft Azure service teams to evaluate security posture and risks across cloud-hosted service ecosystems. The role develops systemic mitigations and security improvements, and uses AI and automation to scale assessments across product portfolios.
What You'll Do
- Perform security reviews and deep dives for cloud-hosted service ecosystems in Microsoft Azure, assessing security posture and risks to...
- Develop security guidance, reference architectures, and remediation strategies to address systemic security challenges and architectural...
- Work with engineers, architects, and product leaders to prioritize risks and advance security improvements across Microsoft services.
- Use AI and automation capabilities to scale security assessments, improve risk identification, and increase security coverage.
- Mentor engineering teams, enable self-service security capabilities, and foster secure development practices.
Generated from the employer's posting. Verify important details before applying.
View full postingQualifications
Required qualifications include a master's degree in a listed or related field and 4+ years of relevant experience, or a bachelor's degree in a listed or related field and 6+ years of relevant experience, or equivalent experience. Security expertise in at least one core area: virtualization, memory safety (C/C++), networking protocols, cloud security, or kernel security.
Preferred
- Demonstrated hands-on experience identifying and exploiting security vulnerabilities across cloud (Azure/AWS/GCP), identity (Entra ID /...
- Experience in customer-facing or consulting roles delivering security outcomes to executive audiences, with ability to move between deep...
- 5+ years experience performing security assessments and penetration testing.
- 5+ years experience securing cloud computing environments across one of the known Cloud providers (Azure/AWS/GCP).
- 5+ years of experience with coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, Rust, or other comparable...
Original job description
Content provided by the employer
Original job description
Content provided by the employer
The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.
Are you ready to take your career to another level at Microsoft? The Azure Security DevSec team is looking for a Principal Security Engineer to join us in securing services in the Microsoft Cloud. We work with service teams across Microsoft to evaluate and improve their security posture in the cloud, continuously moving the needle across multiple dimensions of their design, development and deployment security. In this role, you will collaborate with teams across Microsoft Azure to dive deep and evaluate the Security promises and risk posed by and to service ecosystems, recommend systemic mitigations, innovate on remediations for new issue The Azure Security DevSec team is looking for a Principal Security Engineer to join us in securing services in the Microsoft Cloud. We work with service teams across Microsoft to evaluate and improve their security posture in the cloud, continuously moving the needle across multiple dimensions of their design, development and deployment security. In this role, you will collaborate with teams across Microsoft Azure to dive deep and evaluate the Security promises and risk posed by and to service ecosystems, recommend systemic mitigations, innovate on remediations for new issue ecosystems, recommend systemic mitigations, innovate on remediations for new issue classes, contributing to the feedback loop that can help achieve these outcomes at scale.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
- Perform security reviews and deep dives for on cloud-hosted service ecosystems in Microsoft Azure, helping understand the security promise posture, risks to the target ecosystem and broader Azure.
- Security expertise in at least one of the following Core areas: virtualization, memory safety (C/C++), Networking protocols, Cloud security, Kernel security, etc.
- Drive secure-by-design improvements by developing security guidance, reference architectures, and practical remediation strategies that help teams address systemic security challenges and architectural anti-patterns.
- Bring a growth mindset to tackle new and challenging problems every day, in an inclusive team environment Innovate new approaches to solving security at cloud scale.
- Ability to be a strong technical communicator, lead stakeholder discussions and drive long-term partnerships across Azure organizations.
- Influence security outcomes across high-impact Microsoft services by working directly with engineers, architects, and product leaders to prioritize risks and accelerate security improvements.
- Leverage AI and automation capabilities to scale security assessments, improve risk identification, and increase security coverage across complex product portfolios.
- Champion security excellence by mentoring engineering teams, enabling self-service security capabilities, and fostering secure development practices across the organization.
Qualifications
Required Qualifications:
- Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
- OR equivalent experience.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
- This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- Demonstrated hands-on experience with identifying and exploiting security vulnerabilities across cloud (Azure/AWS/GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network.
- Experience in customer-facing or consulting roles delivering security outcomes to executive audiences; ability to move fluently between deep technical detail and business impact.
- 5+ years experience performing security assessments and penetration testing.
- 5+ years experience securing cloud computing environments across known across one of the known Cloud providers (Azure/AWS/GCP).
- 5+ years of experience with coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, Rust, or other comparable programming languages, including building and maintaining security tooling.
#MSSecurity #CISOOrg #CloudSecurity #AzureSecurity
Security Assurance IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
About the company
Microsoft
Large Enterprise
Microsoft is a global technology leader that empowers individuals and organizations to achieve more through innovative software, services, and devices. Founded in 1975, the company is best known for its flagship products like the Windows operating system and Microsoft Office suite. In addition to personal computing, Microsoft is a leader in cloud computing with its Azure platform, providing a range of solutions for businesses to enhance productivity and efficiency. With a strong commitment to sustainability and accessibility, Microsoft continues to drive technological advancements that shape the future of work and learning.