Senior Service Engineer - Security Focused
About the role
Help defend the network Microsoft runs on. Microsoft Digital's Network Defense Engineering (NDE) team in Redmond, Washington is hiring a Senior Security Engineer to help secure Microsoft's global network infrastructure. Microsoft Digital (MSD) builds and runs the products and services Microsoft depends on. We pursue big ideas that drive transformational advances for Microsoft and its customers, and our engineers bring deep technical expertise and large-scale, first-hand experience to every problem we solve.
Responsibilities
- Independently engineer and operate threat detection and response for Microsoft's network - detection engineering, threat hunting, security orchestration and automated response, including enforcement and containment actions - to mitigate threats.
- Define and enforce secure configuration standards, access controls, and credential management; drive vulnerability management, configuration compliance, proactive security reviews, and threat modeling to reduce the attack surface across the device lifecycle.
- Improve the development and operations of related systems and platforms - building and monitoring telemetry and analytics in Kusto (Azure Data Explorer) to surface patterns, detect anomalies, and strengthen AI-assisted detection, and delivering high-quality automation that reduces manual toil.
- Take part in the on-call (DRI) rotation for major-impact incidents - leading triage, root-cause analysis, and enforcement actions - and coordinate multiple workstreams under pressure.
- Follow prescriptive security, privacy, and compliance standards, and periodically support penetration testing, SOX compliance, and security audits.
- Collaborate within and across teams - sharing insights and best practices, resolving cross-team conflicts, influencing security policy, and mentoring other engineers.
- Embody our culture and values.
Qualifications
Required/Minimum Qualifications: Bachelor's Degree in Computer Science, Information Technology, or related field AND 3+ years technical experience in software engineering, network engineering, service engineering, or systems engineering OR equivalent experience.
- Experience in SOC, SecOps, or InfoSec environments, including threat detection and response, threat suppression, and incident response.
- Hands-on experience with network security and detection engineering - ACLs, control-plane protections, AAA, segmentation, and telemetry-driven detection using large-scale data platforms such as Kusto (Azure Data Explorer).
- Experience administering or securing enterprise network infrastructure across multi-vendor routing, switching, and firewall platforms, and familiarity with network protocols (TCP/IP, DNS, DHCP, BGP, OSPF).
- Experience with vulnerability management and configuration/security compliance in large-scale cloud or hybrid environments (e.g., Azure), including SOX and audit-readiness practices.
- Relevant industry certifications such as CCNP, CCIE, CISM, OSCP, CompTIA Security+, or SANS GCIA/GCIH.
Pay
The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.