Principal Software Engineer

30 Minutes ago • 6 Years + • Cyber Security • $137,600 PA - $294,000 PA

About the job

Job Description

Microsoft's Customer Security and Trust (CST) team seeks a Principal Software Engineer to contribute to security initiatives. This role involves working with the Security and Privacy Engineering (SPE) team to improve the security posture of cloud infrastructure and services. Responsibilities include threat modeling, secure development lifecycle implementation, security architecture reviews, incident response, and promoting secure coding practices. The ideal candidate will have extensive experience with Azure services, security vulnerabilities, and secure development practices, as well as strong communication and collaboration skills. The position offers the opportunity to significantly impact the security of Microsoft's services and infrastructure, working with a dynamic team and applying cutting-edge security technologies.
Must have:
  • 6+ years technical engineering experience
  • 5+ years experience with common security vulnerabilities
  • 5+ years experience with Azure services
  • 2+ years experience with secure development lifecycle practices
  • Experience articulating business needs for security improvements
Good to have:
  • CISSP Certification
  • Understanding of cryptography
  • Experience with Containers and Azure Kubernetes
  • Experience implementing Networking Security, API management, Identity and Access management
Perks:
  • Industry leading healthcare
  • Educational resources
  • Discounts on products and services
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Opportunities to network and connect

Overview

Microsoft runs on trust.  Earning and keeping that trust has never been more important.    

In Customer Security and Trust (CST), program managers, engineers, analysts, investigators, data scientists, attorneys, and business professionals are responsible for some of the most exciting projects at Microsoft focused on protecting our customers.  

The Cybersecurity & Trust Engineering team (CSTE) in CST is the central driving force of Engineering and Cybersecurity initiatives for CST and for Microsoft Corporate, External and Legal Affairs (CELA) as a whole. The Security and Privacy Engineering (SPE) team is responsible for embedding security and privacy considerations into all facets of the organization’s operations. SPE team is instrumental in identifying critical risks, providing engineering and cybersecurity expertise to implement effective mitigations, and working closely with diverse stakeholders across the company and external organizations to safeguard information assets and ensure compliance with all relevant regulations and standards. 

We are hiring a Principal Software Engineer to join our team. This role will be part of the SPE team, contributing to security initiatives within the organization and across CELA Division with the opportunity of bigger impact. You will contribute to strategic projects and assignments to help increase the security posture of cloud infrastructure and services, assessing security and privacy risks and contribute to improvements and remediation of issues. 

This is a unique opportunity within Microsoft to work in a dynamic and collaborative team with impact across many services harvesting the power of the cloud, apply your Security and technical skills to empower analysts and investigators to keep our digital world safe for consumers and businesses across the globe. 

 

A successful candidate will be passionate about secure development practices and architecture, reliability, cloud computing and automation necessary to strengthen the resiliency and security posture of our services and infrastructure.

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

 

#CELA

Qualifications

Required/Minimum Qualifications

  • Bachelor's Degree in Computer Science, or related technical discipline AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
    • OR equivalent experience. 
  • 5+ years experience with common security vulnerabilities and associated mitigations  
  • 5+ years of experience with Azure services, including containers (AKS), App services, Azure Storage technologies, and best practices to secure these services 
  • 2+ years experience working as part of an engineering team, or as a partner of the engineering team, to implement secure development lifecycle practices  
  • 2+ years experience articulating business needs for security improvements    

 

Additional or Preferred Qualifications

  • CISSP Certification and / or SANS Security Training 
  • Understanding of cryptography 
  • Experience with Containers and Azure Kubernetes including security best practices 
  • Experience implementing Networking Security, API management, Identity and Access management 

Other Requirements:

  • Citizenship verification:
    • This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport.
    • This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide proof of citizenship, U.S. permanent residency, or other protected status (e.g., under 8 U.S.C. § 1324b(a)(3)) for assessment of eligibility to access the export-controlled information.  To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.

Software Engineering IC5 - The typical base pay range for this role across the U.S. is USD $137,600 - $267,000 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $180,400 - $294,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until January 31, 2025.

Responsibilities

  • Establish collaboration with Engineering teams in CSTE and across CELA on new features, services, and updates to the product   
  • Participate in threat model reviews and help identify security flaws early in the design phases  
  • Foster onboarding and adoption of Security Development Lifecycle (SDL)  
  • Help design implementation of Defense in Depth and Zero Trust strategies while ensuring secure by design, security by default, and secure by deployment principles  
  • Lead security architecture reviews   
  • Provide guidance and recommendations for secure development   
  • Fix security issues in code or infrastructure  
  • Participate in code reviews to evaluate security risks and improvements  
  • Lead cloud incident response activities as they occur  
  • Promote security awareness and provide training and good coding practices  
  • Supports operational security and security incidents as well as security reviews 
  • Help define, document, evolve, and evangelize secure engineering standards and best practices across multiple areas including automation  
  • Contribute to, and establish a strategic view of risk to our services and iterative and consistent security improvements  

Other

  • Embody our and

 

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect
View Full Job Description
$137.6K - $294.0K/yr (Outscal est.)
$215.8K/yr avg.
Redmond, Washington, United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Barcelona, Catalonia, Spain (On-Site)

Atlanta, Georgia, United States (Hybrid)

Redmond, Washington, United States (On-Site)

Reston, Virginia, United States (On-Site)

Redmond, Washington, United States (On-Site)

Charlotte, North Carolina, United States (On-Site)

New York, New York, United States (On-Site)

Redmond, Washington, United States (On-Site)

Redmond, Washington, United States (Remote)

Redmond, Washington, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Microsoft

Similar Jobs

Trendyol - Backend Developer

Trendyol, Türkiye (Hybrid)

Patterned Learning Career - Senior Java Developer

Patterned Learning Career, (Remote)

ION - Cyber Security Analyst, Italy

ION, Italy (On-Site)

Alight Solutions - Senior Cloud Security Engineer

Alight Solutions, India (Remote)

Electronic Arts - Security Architect

Electronic Arts, United States (Remote)

Seedify - Cyber Security Specialist

Seedify, (On-Site)

PwC - Oracle EPM - Senior Associate

PwC, India (On-Site)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Nagarro - Senior Staff Engineer, Java Developer

Nagarro, United States (On-Site)

DigitalOcean - Senior Software Engineer (Hyderabad)

DigitalOcean, India (Hybrid)

ByteDance - Mobile System Memory Optimization Architect

ByteDance, United States (On-Site)

The Walt Disney Company - Senior Software Engineer

The Walt Disney Company, United States (On-Site)

PAPAYA - R&D Group Leader

PAPAYA, Israel (On-Site)

Google - Data and Analytics Engineer

Google, India (On-Site)

Sony India Software Centre - Java Lead - Spring Boot/Microservices Architecture

Sony India Software Centre, India (On-Site)

GoTo Group - SDET - Growth

GoTo Group, India (On-Site)

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

SSC Technologies - Sr. Revenue and Receivables Analyst

SSC Technologies, United States (Hybrid)

Click Therapeutics - Senior IT Systems Administrator

Click Therapeutics, United States (On-Site)

Anavation - Senior IT Administrator

Anavation, United States (Hybrid)

Take-Two Interactive - Brand Marketing Lead

Take-Two Interactive, United States (On-Site)

Extreme Network - Director, Data Governance, Enterprise Data and Analytics

Extreme Network, United States (Remote)

Trek - Production Technician

Trek, United States (On-Site)

Axon - Head of Enterprise Marketing

Axon, United States (On-Site)

Epic Games - Gameplay Animator

Epic Games, United States (On-Site)

Duolingo - Product Designer, Thrive Intern

Duolingo, United States (On-Site)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Get notifed when new similar jobs are uploaded