Jobs · OTHR · Washington

Principal Security Engineer

Microsoft AI · Redmond, WA · 1 mo ago
OTHR$143k–$275k/yrFull-time

About the role

The Microsoft Edge Browser Security team protects the security of Microsoft Edge and helps make the web safer for billions of users worldwide. Our work spans three core areas:

  • Security Engagement: Partner closely with engineering teams, architects, and product leaders to shape the security posture of Edge from the earliest stages of design. Provide deep technical guidance, influence product architecture, and drive adoption of secure-by-default principles, defense-in-depth strategies, and resilient security controls across the browser platform.
  • Proactive Security: Identify and mitigate risk before it reaches customers through large-scale vulnerability research, security assessments, attack surface analysis, code auditing, fuzzing, exploitability analysis, and emerging threat investigations. Drive novel security research initiatives, influence long-term security roadmaps, and mentor others in advanced vulnerability discovery techniques.
  • Reactive Security: Ensure rapid detection, assessment, and response to emerging threats by collaborating with external researchers, threat intelligence teams, MSRC, and engineering organizations. Drive cross-organizational incident response, identify systemic lessons from security incidents, and influence durable security improvements.

Throughout all areas, you will engage with industry partners, security researchers, and the open-source community to improve the security of Chromium and related technologies, strengthening the broader web ecosystem.

Responsibilities

  • Evaluate the security landscape to identify emerging trends and potential exploitable vulnerabilities for Microsoft, supported, and/or competitor products.
  • Conduct high-level analysis of complex security threats with a forward-looking perspective.
  • Lead cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions.
  • Leverage artificial intelligence (AI) workflows to understand research operations and customer usage of Microsoft products, proposing solutions for comprehensive protection.
  • Develop and oversee security analysis plans that anticipate future product developments and align with long-term business objectives.
  • Serve as a subject matter expert, sharing guidance on potential security issues, tools, mitigations, and processes (e.g., architecture, failure modes, attack chain, threat modeling, vulnerabilities).
  • Maintain and share deep knowledge of industry trends, technologies, tools, securities, and advances.
  • Proactively contribute to internal and external communities through publications, white papers, seminars, or conferences, shaping understanding of threat protection.
  • Establish deployment and security configuration standards and best practices to ensure secure technology deployment across the organization.
  • Direct organization-wide security reviews, including architectural and design reviews, and synthesize findings in analysis reports.
  • Lead the implementation of best practices for security architecture, design, and development across product and feature areas.
  • Proactively evaluate and prioritize security risks and orchestrate cross-functional partnerships to remove blockers and mitigate risks.
  • Oversee monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed.
  • Solve classes of issues in technical implementation and automation of solutions related to specific security issues (e.g., security posture, signature-based detection, malware, threat analysis, reverse engineering, attack disruption, anomaly detection).
  • Lead multidisciplinary teams to innovate and implement improvements in solutions and methods.

Qualifications

Required Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Equivalent experience

Preferred Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
  • Equivalent experience
  • Significant experience in areas such as:
    • Vulnerability research and exploit analysis
    • Code auditing and secure architecture review
    • AI-assisted vulnerability research
    • Fuzzer development and crash triage
    • Browser, application, operating system, or cloud security
    • Threat modeling and attack surface analysis
    • Security automation and AI-assisted security research
    • Software engineering and computer science fundamentals

Schedule

Starting January 26, 2026, employees who live within a 50-mile commute of a designated Microsoft office in the U.S. or 25-mile commute of a non-U.S., country-specific location are expected to work from the office at least four days per week. This expectation is subject to local law and may vary by jurisdiction.

Pay

  • The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year.
  • For specific work locations within the San Francisco Bay area and New York City metropolitan area, the base pay range is USD $188,000 - $304,200 per year.
  • Certain roles may be eligible for benefits and other compensation. Additional pay information can be found here.

Similar jobs

Principal Security Engineer

Allied OneSourceOverland Park, KS· 1 mo ago
Information Technology$148k–$193k/yrapply on alliedonesource.com