1 day ago
Base Salary
$120k - $261k/yr
Responsibilities
- Design, develop, test, deploy, and operate software services, automation, tools, integrations, APIs, queries, pipelines, and workflows supporting security and compliance programs.
- Build continuous capabilities to identify vulnerabilities, insecure configurations, control gaps, attack paths, recurring weaknesses, and emerging security risks across Microsoft Marketing services.
- Develop AI-enabled security automation and agents for evidence collection, threat identification, risk analysis, finding generation, remediation guidance, and security-program workflows.
- Automate the collection, normalization, correlation, and analysis of security signals from cloud resources, applications, identities, networks, data platforms, code-security systems, service metadata, and security tooling.
- Perform threat modeling and technical security reviews covering architectures, data flows, trust boundaries, identities, privileged access, network exposure, logging, data classifications, and security controls.
- Build compliance automation for control validation, evidence collection, gap identification, exception management, remediation tracking, and continuous assurance.
- Validate automated and AI-generated findings, improve detection quality, reduce false positives, and measure security posture, compliance assurance, remediation progress, and recurring risk patterns.
- Partner with service engineers, architects, security, privacy, Responsible AI, and program teams; support tenant migrations, platform modernization, and AI adoption.
- Develop reusable security patterns, libraries, templates, and engineering guidance, contribute to architecture decisions, mentor engineers and security practitioners, and communicate risks and remediation strategies.
Requirements
- Bachelor's degree in Computer Science or a related technical field and 4+ years of technical engineering experience coding in languages including C, C++, C#, Java, JavaScript, or Python, or equivalent experience.
- Preferred qualifications include a master's degree and 6+ years of experience, or a bachelor's degree and 8+ years of experience, or equivalent experience.
- Professional software development experience with one or more general-purpose programming languages and experience designing, developing, testing, deploying, and operating production software, automation, services, or engineering tools.
- Experience with APIs, data pipelines, cloud services, automation frameworks, distributed systems, Microsoft Azure or another major cloud platform, and cloud-native software development.
- Experience with cybersecurity principles, vulnerability identification, security platforms, developer-security tooling, compliance automation, security analytics, vulnerability management, or continuous assurance.
- Experience applying AI, machine learning, large language models, agents, or other AI technologies to security engineering, automation, or operational workflows.
- Experience with threat-modeling methodologies, attack-path analysis, data-flow diagrams, trust boundaries, secure architecture reviews, Azure DevOps, CI/CD systems, code-security platforms, cloud-security posture management, or data-classification tooling.
Benefits
- Certain roles may be eligible for benefits and other compensation; additional benefits and pay information is available through Microsoft's careers website.
- The position will remain open for a minimum of 5 days, with applications accepted on an ongoing basis until filled.
About Microsoft
Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.
