Microsoft Logo

Microsoft

Principal Security Engineer

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in MD, USA
143K-304K Annually
Senior level
In-Office or Remote
Hiring Remotely in MD, USA
143K-304K Annually
Senior level
Conduct vulnerability research across operating systems, cloud platforms, and virtualization technologies through design and code review, fuzzing, variant analysis, and reverse engineering. Develop platform mitigations, security tooling, detection capabilities, and systemic protections. Partner with engineering teams to improve secure development practices, lead complex security initiatives, track emerging attack techniques, and mentor peers.
The summary above was generated by AI
Overview

The Microsoft Offensive Research & Security Engineering (MORSE) team is looking for a Principal Security Engineer to help secure Microsoft’s products and devices.

MORSE is responsible for securing Microsoft’s operating systems and platform technologies, cloud platforms, and virtualisation technologies that support the daily needs of over a billion customers worldwide.
In this role, you will work across the discovery and mitigation of security vulnerabilities — identifying weaknesses in systems, understanding their impact, and helping drive protections that improve the security of Microsoft platforms at scale. You will partner with engineers across Windows, Azure, and platform infrastructure to architect security solutions and influence the way systems are designed and built.
This role is well suited to engineers who enjoy deep systems work, solving complex problems, and delivering high impact security outcomes.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond


Responsibilities
  • Drive identification and analysis of security vulnerabilities across operating system and platform components, including design review, code review, fuzzing, and variant analysis
  • Develop and influence mitigations and protections that reduce risk across platforms, improving resilience against entire classes of vulnerabilities
  • Advocate for security with engineering teams to integrate security into the development lifecycle, influence design decisions and improve secure engineering practices. Autonomously drive coordination and collaboration across broad groups across Microsoft. Devise and advocate for broadly applicable solutions.
  • Contribute to the development and scaling of security tooling, detection capabilities, or analysis techniques that enable broader coverage and earlier detection of vulnerabilities
  • Partner across organizations to translate security findings into systemic improvements and measurable security outcomes
  • Stay current on attacker techniques, emerging vulnerability classes, and industry trends, applying this knowledge to improve Microsoft’s security posture
  • Provide technical leadership within and across teams, contributing to direction setting, problem decomposition, and delivery of complex security initiatives. Mentor and coach peers on new approaches and best practices. Coordinate across teams and leads resolution of vulnerabilities, threat attacks, and security issues.

Qualifications
Required Qualifications:
  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field 
    • OR equivalent experience.

Other Requirements:

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: 
    • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter. 

Preferred Qualifications:

  • Public or internal track record of relevant security research
  • Understanding of operating system security fundamentals, including kernel or low level platform components
  • Experience performing vulnerability research, including code review, fuzzing, reverse engineering, or exploit development
  • Experience developing or applying mitigations, such as memory safety protections, sandboxing, or platform hardening techniques 
  • 4+ years experience in security-related elements of software engineering or in another security-related field
  • 4+ years experience with systems level programming languages such as C, C++, or Rust

Penetration Testing IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Similar Jobs

15 Days Ago
Easy Apply
Remote
United States
Easy Apply
203K-275K Annually
Expert/Leader
203K-275K Annually
Expert/Leader
Cloud • Security • Software • Cybersecurity • Automation
Owns GitLab’s global security awareness and human-risk program, including training, phishing simulations, behavior-change initiatives, security culture campaigns, multimedia content, platform administration, reporting, vendor management, policy support, audit evidence, and remediation tracking. The role requires measurable risk reduction across a globally distributed enterprise and strategic influence across technical and non-technical teams.
Top Skills: OwaspSans Security Awareness Professional (Ssap)
28 Days Ago
In-Office or Remote
United States
150K-190K Annually
Expert/Leader
150K-190K Annually
Expert/Leader
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Serves as the senior technical authority for enterprise browser data protection and security. Owns architecture, roadmap, standards, lifecycle, browser-based DLP controls, integrations, automation, and operational support. Leads complex troubleshooting, major incident response, root-cause analysis, runbook development, and continuous improvement. Partners across cybersecurity, identity, endpoint, network, cloud, risk, compliance, and vendor teams while mentoring engineers and influencing enterprise security design.
Top Skills: Active DirectoryAzure DevopsCasbChrome Enterprise PremiumCisco Secure AccessCloud PlatformsCrowdstrikeCyberarkDigital GuardianDnsEntra IdForcepoint DlpGitGitIslandJAMFMecm/SccmMenlo SecurityMicrosoft Defender XdrMicrosoft Edge For BusinessMicrosoft GraphMicrosoft IntuneMicrosoft Purview DlpMicrosoft SentinelNetskope DlpOktaPalo AltoPalo Alto Prisma BrowserPing IdentityPowershellPythonRest ApisSaseSplunkSwgSymantec DlpTaniumTerraformTls/HttpsVpnZscalerZtna
15 Hours Ago
Remote
United States
143K-304K Annually
Expert/Leader
143K-304K Annually
Expert/Leader
Software • Quantum Computing • Metaverse • Infrastructure as a Service (IaaS)
Lead end-to-end red team and adversary emulation operations across cloud, identity, network, endpoint, hardware, and operational security environments. Develop offensive tooling, implants, and AI-driven autonomous agents for reconnaissance, exploitation, and post-exploitation. Serve as a technical lead for customer engagements, brief security executives, collaborate with blue teams and threat intelligence organizations, establish operational standards, and mentor senior operators.
Top Skills: .NetActive DirectoryAi AgentsAWSAzureC#C++CbestDoraEntra IdGCPGoLarge Language ModelsLinuxMitre Att&CkMulti-Agent SystemsPowershellPythonRustTiber-EuWindows

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account