Microsoft Azure is at the center of Microsoft’s cloud services strategy and the future of Microsoft. Azure brings together virtualization, compute, storage, authentication, authorization, artificial intelligence and machine learning, media and more to enable anyone to bring their business in the cloud. Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions.
The Azure Customer Experiences (CXP) organization is on a mission to convert Azure customers into Azure fans. We want to ensure that our first- and third-party offerings adhere to the security standards, and that our products uphold the promise we have to our customers and partners. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
We are seeking a diligent, insightful, and creative Principal Security Software Engineer to discover, diagnose, analyze, quantify, characterize and help drive solutions for the most challenging security problems in CXP through a data-driven, product-driven lens.
In this role, you will advance security by working with other Security Engineers, Program and Product Managers, and Developers, as well as business leaders throughout Microsoft to turn individual findings and vulnerabilities into patterns and insights that can be measured and managed through engineering, automation, and other appropriate mitigations. You will identify the most demanding security problems through original research and data analysis and help design and deliver practical solutions at scale for select products and services. You will work up and down the stack, across platforms, operating systems, languages, and frameworks, using your broad security skills to solve problems in unfamiliar domains. You will demonstrate deep threat modeling expertise including experience in identifying attack vectors and creating comprehensive threat models. You have an understanding of security design patterns (defense in depth, least privilege, zero trust) and when to apply them. You reason through various tradeoffs between security, performance, and usability. You have a deep understanding of distributed systems, cloud architectures, networking, and AuthN/AuthZ systems to allow you to spot vulnerabilities across the stack. You explain security risks to non-technical stakeholders, mentor and coach other Engineers on secure coding patterns and drive a security culture.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.