Microsoft Logo

Microsoft

Principal Security Engineer

Reposted 4 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
166K-331K Annually
Senior level
Remote
Hiring Remotely in United States
166K-331K Annually
Senior level
Lead deep technical security reviews of products and platforms, produce prioritized remediation roadmaps, build security tools and automations, integrate guardrails and automated checks, partner with product teams to implement and validate fixes, and use threat intelligence and telemetry to convert attack paths into controls and detections.
The summary above was generated by AI
Overview

Forward-Deployed Security within CISO Leadership is responsible for bootstrapping and maturing security programs and addressing threats faced by Microsoft divisions with emerging, non-traditional-enterprise technologies. We work where the problems are least standardized and the stakes are real: new products, fast-moving platforms, uneven security maturity and teams that need practical help building an architecture that works for them - not abstract guidance and frameworks. We land, understand the environment, build roadmaps, develop recon and exposure tooling, and stay involved to land security improvements until the problem space is stable and an operational team is ready to stand on its own.

We are looking for a Principal Security Engineer who combines deep, technical security expertise with a builder's mindset, end-to-end ownership, and insight into what it takes to build a platform. This role sits in the Security Assurance Family, but the work is broader than classic assurance. You will assess complex systems, develop the path to meaningful risk reduction, build defensible architectures with real tools and automation, and work directly with product-line teams to get fixes and secure patterns adopted and validated. This is a role for someone who likes ambiguous problems, learns by doing, and measures success by durable improvement rather than by findings written down.


Responsibilities

Lead deep technical security reviews of products, services, infrastructure, and emerging technologies using AI-enabled methods including architecture analysis, threat modeling, adversarial testing, source review, telemetry, and data analysis.

  • Turn review outcomes into prioritized security roadmaps with clear tradeoffs, practical milestones, and measurable risk-reduction goals.
  • Build and maintain security tools, automation, prototypes, and reusable engineering patterns that teams adopt in real workflows.
  • Partner directly with product and research teams to design, debug, implement, and validate security improvements, staying engaged through root-cause resolution rather than stopping at recommendations.
  • Integrate automated security checks, guardrails, and secure defaults into engineering systems so successful one-off work becomes scalable capability.
  • Use threat intelligence, hunting techniques, telemetry, and incident learning to identify emerging attack paths and convert them into detections, controls, and engineering priorities.

Qualifications

Required/Minimum Qualifications

  • Doctorate in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
  • OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
  • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR equivalent experience.

Additional or Preferred Qualifications 

  • Experience owning complex, multidisciplinary, multi-organization security problems from initial scoping through technical resolution and validated improvement.
  • Experience building and maintaining security tools, automation, or internal security capabilities used by real engineering teams.
  • Software engineering experience in one or more general-purpose languages, such as Python, C#, C++, Go, Java, Rust, or TypeScript, enabled by agentic software engineering practices.
  • Hands-on experience with at least multiple security assessment methods such as threat modeling, architecture review, source or configuration review, adversarial testing, attack-path analysis, detection engineering, or incident investigation.
  • Experience working directly with product or engineering teams to prioritize, implement, and validate security improvements.
  • Ability to analyze security or operational data and use evidence to make technical and prioritization decisions.
  • Securing complex cloud, distributed, identity, data, AI, or developer-platform systems.
  • Designing secure defaults, reusable engineering patterns, or automated controls that reduced the effort required for other teams to build securely.
  • Using threat intelligence, adversary simulation, hunting, or incident findings to improve preventive or detective controls at a systemic level.
  • Leading complex cross-team technical initiatives through technical credibility and influence, and mentoring other engineers or security practitioners at an industry level.

Security Assurance IC6 - The typical base pay range for this role across the U.S. is USD $165,600 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Microsoft Cambridge, Massachusetts, USA Office

255 Main Street, Cambridge, MA 02142, Cambridge, United States, 02142

Similar Jobs

3 Days Ago
Remote or Hybrid
US
172K-240K Annually
Expert/Leader
172K-240K Annually
Expert/Leader
Information Technology
Leads enterprise application security through secure code reviews, threat modeling, architecture assessments, CI/CD security controls, secure coding standards, API protections, WAF tuning, and software supply chain security. Partners with engineering, DevOps, platform, and SRE teams to remediate risks, automate controls, secure AI-enabled applications, and improve organization-wide security practices. Serves as a principal technical advisor and mentor while defining scalable guardrails, playbooks, metrics, and reference architectures.
Top Skills: AkamaiApi Security TestingAWSAzureC#Ci/CdContainer SecurityDastGCPGoInfrastructure As Code (Iac) ScanningJavaJavaScriptPolicy-As-CodePythonSastSbomScaSoftware Supply Chain SecurityTerraformTypescriptWeb Application Firewall (Waf)
6 Days Ago
In-Office or Remote
United States
150K-190K Annually
Expert/Leader
150K-190K Annually
Expert/Leader
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Serves as the senior technical authority for enterprise browser data protection and security. Owns architecture, roadmap, standards, lifecycle, browser-based DLP controls, integrations, automation, and operational support. Leads complex troubleshooting, major incident response, root-cause analysis, runbook development, and continuous improvement. Partners across cybersecurity, identity, endpoint, network, cloud, risk, compliance, and vendor teams while mentoring engineers and influencing enterprise security design.
Top Skills: Active DirectoryAzure DevopsCasbChrome Enterprise PremiumCisco Secure AccessCloud PlatformsCrowdstrikeCyberarkDigital GuardianDnsEntra IdForcepoint DlpGitGitIslandJAMFMecm/SccmMenlo SecurityMicrosoft Defender XdrMicrosoft Edge For BusinessMicrosoft GraphMicrosoft IntuneMicrosoft Purview DlpMicrosoft SentinelNetskope DlpOktaPalo AltoPalo Alto Prisma BrowserPing IdentityPowershellPythonRest ApisSaseSplunkSwgSymantec DlpTaniumTerraformTls/HttpsVpnZscalerZtna
8 Days Ago
Remote or Hybrid
221K-387K Annually
Expert/Leader
221K-387K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead architecture and implementation of internal AI security across agentic tools, LLMs, and RAG pipelines. Threat model AI surfaces, define governance and enforceable controls, partner on AI threat research, modernize cyber defense with AI, and mentor engineers to deliver production-grade security solutions.
Top Skills: Agentic Ai FrameworksCloud SecurityDetection EngineeringEndpoint SecurityIamIncident ResponseLangchainLanggraphLlmsRag Pipelines

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account