17 hours ago
Base Salary
$143k - $304k/yr
Responsibilities
- Define and drive a multi-team technical strategy, roadmap, architecture, and adoption plan for Copilot security.
- Design and implement detection and defense systems for prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic workflow abuse.
- Build reusable security services, classifiers, evaluation frameworks, telemetry pipelines, and risk assessment capabilities.
- Define security effectiveness measures and release criteria, and validate defenses using adversarial evaluations and production telemetry.
- Lead threat modeling, architectural security reviews, red teaming, adversarial testing, and cross-team security investigations.
- Own production readiness, observability, rollout and rollback practices, on-call participation, incident response, and durable remediation.
- Influence technical decisions across teams without direct authority and communicate risks, tradeoffs, progress, and outcomes.
- Provide technical mentorship and contribute directly through design reviews, code reviews, and production implementations.
Requirements
- Bachelor's degree in Computer Science or a related technical field and 6+ years of technical engineering experience with coding, or equivalent experience.
- Coding experience in C, C++, C#, Java, JavaScript, or Python.
- Ability to meet Microsoft, customer, and/or government security screening requirements, including the Microsoft Cloud Background Check.
- Preferred: master's degree with 8+ years of experience, or bachelor's degree with 12+ years of experience, or equivalent experience.
- Preferred: 5+ years designing, building, and operating production software systems.
- Experience owning ambiguous technical problems from strategy and architecture through implementation, rollout, operation, and cross-team adoption.
- Experience mitigating production security risks and understanding prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic system risks.
- Experience building security detection, anomaly detection, threat intelligence, abuse prevention, Trust & Safety, or related systems and measuring improvements with evaluation data and production telemetry.
- Experience with large language models, AI systems, machine learning infrastructure, or evaluation frameworks, plus familiarity with AI safety and security research.
- Experience with threat modeling, security reviews, red teaming, adversarial testing, incident response, and translating findings into reusable defenses.
- Ability to communicate complex technical tradeoffs and security risks and mentor engineers across teams.
- Preferred contributions to security tooling, patents, publications, open-source projects, or recognized technical leadership in security.
Benefits
- The role is based in Redmond, Washington and requires working in the office at least 3 days per week.
- Eligible roles may receive benefits and other compensation; additional benefits and pay information is available through Microsoft Careers.
Tech Stack
Categories
About Microsoft
Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.
