Principal Security Engineer
Job in
Redmond, King County, Washington, 98073, USA
Listed on 2026-08-06
Listing for:
Microsoft Corporation
Full Time
position Listed on 2026-08-06
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
* Forward-Deployed Security within CISO Leadership is responsible for bootstrapping and maturing security programs and addressing threats faced by Microsoft divisions with emerging, non-traditional-enterprise technologies. We work where the problems are least standardized and the stakes are real: new products, fast-moving platforms, uneven security maturity and teams that need practical help building an architecture that works for them - not abstract guidance and frameworks.
We land, understand the environment, build roadmaps, develop recon and exposure tooling, and stay involved to land security improvements until the problem space is stable and an operational team is ready to stand on its own.
We are looking for a Principal Security Engineer who combines deep, technical security expertise with a builder's mindset, end-to-end ownership, and insight into what it takes to build a platform. This role sits in the Security Assurance Family, but the work is broader than classic assurance. You will assess complex systems, develop the path to meaningful risk reduction, build defensible architectures with real tools and automation, and work directly with product-line teams to get fixes and secure patterns adopted and validated.
This is a role for someone who likes ambiguous problems, learns by doing, and measures success by durable improvement rather than by findings written down.
** Responsibilities*
* Lead deep technical security reviews of products, services, infrastructure, and emerging technologies using AI-enabled methods including architecture analysis, threat modeling, adversarial testing, source review, telemetry, and data analysis.
+ Turn review outcomes into prioritized security roadmaps with clear tradeoffs, practical milestones, and measurable risk-reduction goals.
+ Build and maintain security tools, automation, prototypes, and reusable engineering patterns that teams adopt in real workflows.
+ Partner directly with product and research teams to design, debug, implement, and validate security improvements, staying engaged through root-cause resolution rather than stopping at recommendations.
+ Integrate automated security checks, guardrails, and secure defaults into engineering systems so successful one-off work becomes scalable capability.
+ Use threat intelligence, hunting techniques, telemetry, and incident learning to identify emerging attack paths and convert them into detections, controls, and engineering priorities.
** Qualifications*
* ** Required/Minimum Qualifications*
* + Doctorate in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
+ OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
+ OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
+ OR equivalent experience.
** Additional or
Preferred Qualifications *
* + Experience owning complex, multidisciplinary, multi-organization security problems from initial scoping through technical resolution and validated improvement.
+ Experience building and maintaining security tools, automation, or internal security capabilities used by real engineering teams.
+ Software engineering experience in one or more general-purpose languages, such as Python, C#, C++, Go, Java, Rust, or Type Script, enabled by agentic software engineering practices.
+ Hands-on experience with at least multiple security assessment methods such as threat modeling, architecture review, source or configuration review, adversarial testing, attack-path analysis, detection engineering, or incident investigation.
+ Experience working directly with product or engineering teams to prioritize, implement, and validate security improvements.
+ Ability to analyze security or operational data and use evidence to make technical and prioritization decisions.
+ Securing complex cloud, distributed, identity, data, AI, or developer-platform systems.
+ Designing secure defaults, reusable engineering patterns, or automated controls that reduced the effort required for other teams to build securely.
+ Using threat intelligence, adversary…
Position Requirements
5+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×