Principal Security Software Engineer
MicrosoftAbout the role
As a Security Software Engineer on the Copilot Security Team, you will serve as a Principal level technical leader responsible for designing, building, and governing security‑critical software systems that protect Microsoft’s agentic and autonomous AI experiences at scale.
You will operate across the full Copilot security lifecycle—threat discovery → architectural design → mitigation engineering → production integration → continuous validation—delivering durable, reusable security defenses rather than one‑off fixes. This role combines deep hands‑on engineering with system‑level security thinking, enabling the team’s mission to deliver secure‑by‑design architecture for Copilot across products and integrations.
Success in this role is measured by measurable risk reduction, improved platform resilience, and the long‑term sustainability of Copilot’s security posture—not by isolated vulnerability closures.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
Security Engineering & Technical Leadership
- Act as a technical authority for security engineering decisions across Copilot services, shared platforms, and integrations.
- Lead threat modeling for complex, distributed, and agentic systems, identifying systemic risks rather than isolated flaws.
- Drive vulnerability research, exploit analysis, and red‑team collaboration to surface novel and emerging attack classes.
- Participate in and lead aspects of incident response, post‑incident analysis, and translation of incidents into durable mitigations.
Architecture & Defensive Systems Engineering
- Design and ship security defenses in production, including enforcement layers, guardrails, monitoring, detection, and evaluation tooling.
- Build reusable security modules and services that can be adopted broadly across Copilot components (BizChat, Office Apps and agents).
- Define and review security architecture patterns, influencing both new feature design and remediation of legacy systems when incremental fixes are insufficient.
Risk Management, Governance & Measurement
- Establish and operate risk management frameworks, including maintaining and prioritizing entries in a central risk registry.
- Translate threats into measurable security requirements, metrics, and dashboards that demonstrate real‑world risk reduction.
- Drive continuous validation through telemetry, monitoring, and evaluation pipelines, closing the loop from discovery to evidence.
Cross‑Functional Influence & Mentorship
- Partner deeply with adversarial testing, applied science and evaluation, and embedded engineering squads to deliver end‑to‑end security outcomes.
- Mentor senior and mid‑level engineers through design reviews, threat‑model coaching, and architectural guidance.
- Communicate complex security tradeoffs clearly to engineering leadership, PM/TPM, and executive stakeholders.
Qualifications
Required Qualifications:
- Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
- Master's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR Bachelor's Degree in Computer Science or related technical field AND 15+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR equivalent experience.
- Experience serving as a technical lead or architectural reviewer for security‑sensitive systems across multiple services or teams.
- Experience conducting vulnerability research, red teaming, or adversarial testing, including identifying novel or emerging attack classes.
- Experi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s