Microsoft

Principal Security Engineer

Microsoft$142K — $274K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Doctorate in a related field and 3+ years of relevant experience, OR Master's with 4+ years, OR Bachelor's with 6+ years.
  • Expertise in software development lifecycle, large-scale computing, threat analysis, or cybersecurity.
  • Significant experience in vulnerability research and exploit analysis.
  • Proficiency in code auditing and secure architecture review.
  • Experience with AI-assisted vulnerability research, threat modeling, and attack surface analysis.

Responsibilities

  • Evaluate security trends and potential vulnerabilities for Microsoft products.
  • Lead cross-functional initiatives to design and implement security solutions.
  • Serve as a subject matter expert to identify security issues and propose mitigations.
  • Direct organization-wide security reviews and synthesize findings.
  • Oversee monitoring and response to security events and vulnerabilities.
  • Innovate solutions related to security issues and lead multidisciplinary teams.

Benefits

  • Flexible work schedule with hybrid options.
  • Opportunity for professional growth and development.
  • Collaboration with industry partners and academics.
  • Involvement in innovative security research initiatives.
  • Access to internal and external security community resources.
Full Job Description
Overview

The Microsoft Edge Browser Security team is responsible for protecting the security of Microsoft Edge and helping make the web safer for billions of users worldwide. Our work spans three core areas: Security Engagement, Proactive Security, and Reactive Security.

In the Engagement space, we partner closely with engineering teams, architects, and product leaders to shape the security posture of Edge from the earliest stages of design. We provide deep technical guidance, influence product architecture, and drive adoption of secure-by-default principles, defense-in-depth strategies, and resilient security controls across the browser platform. As a Principal Security Engineer, you will help define security strategy, identify systemic risk, and drive security investments that have broad impact across Microsoft Edge and the Chromium ecosystem.

In Proactive Security, we identify and mitigate risk before it reaches customers. This includes conducting large-scale vulnerability research, security assessments, attack surface analysis, code auditing, fuzzing, exploitability analysis, and emerging threat investigations. We continuously challenge assumptions, evaluate new technologies, and develop innovative approaches to discovering vulnerabilities in complex browser, operating system, and web platform components. Principal engineers are expected to drive novel security research initiatives, influence long-term security roadmaps, and mentor others in advanced vulnerability discovery techniques.

In Reactive Security, we ensure Microsoft can rapidly detect, assess, and respond to emerging threats. We collaborate with external researchers, threat intelligence teams, MSRC, and engineering organizations to investigate security reports, prioritize mitigation efforts, and protect customers from active exploitation. Principal engineers play a key role in driving cross-organizational incident response, identifying systemic lessons from security incidents, and influencing durable security improvements that reduce future risk.

Throughout all of this, you will engage with industry partners, security researchers, and the open-source community to improve the security of Chromium and related technologies, helping strengthen the broader web ecosystem.

Starting January 26, 2026, AI Experiences employees who live within a 50- mile commute of a designated Microsoft office in the U.S. or 25-mile commute of a non-U.S., country-specific location are expected to work from the office at least four days per week. This expectation is subject to local law and may vary by jurisdiction.

Responsibilities
  • Evaluates the security landscape to identify emerging trends and potential exploitable areas of vulnerability for Microsoft, supported, and/or competitor products. Conducts high-level analysis of complex security threats with a forward-looking perspective. Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions, including for integration in or addition to new/existing products or features. Leverages artificial intelligence (AI) workflows to understand research operations and how customers use Microsoft products and proposes solutions to deliver comprehensive protection. Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives.
  • Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes (e.g., architecture, failure modes, attack chain, threat modeling, vulnerabilities). Maintains and shares deep knowledge of industry trends, technologies, tools, securities, and advances. Proactively contributes to internal and external community through publications, white papers, seminars, or conferences, shaping understanding of threat protection in real-world impact and storytelling. Establishes deployment and security configuration standards and best practices to ensure technologies are deployed in a secure fashion across the organization.
  • Directs organization-wide security reviews, including architectural and design reviews, and synthesizes findings in analysis reports. Leads the implementation of best practices for security architecture, design, and development across product and feature areas and teams. Proactively evaluates and prioritizes security risks and orchestrates cross-functional partnerships to remove blockers and mitigate risks. Oversees the monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed.
  • Solves classes of issues in technical implementation and automation of solutions related to specific kinds of security issues (e.g., security posture, signature-based detection, malware, threat analysis, reverse engineering, attack disruption, anomaly detection). Leads multidisciplinary teams to innovate and implement improvements in solutions and methods.


Qualifications

Required Qualifications:
  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR equivalent experience.

Preferred Qualifications:
  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR equivalent experience.
  • Significant experience in areas such as:
    • Vulnerability research and exploit analysis.
    • Code auditing and secure architecture review.
    • AI assisted Vulnerability Research.
    • Fuzzer development and crash triage.
    • Browser, application, operating system, or cloud security.
    • Threat modeling and attack surface analysis.
    • Security automation and AI-assisted security research.
    • Software engineering and computer science fundamentals.


#MicrosoftAI #EdgeVR #EdgeSecurity

Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

About Microsoft

Microsoft is an American multinational corporation that develops, manufactures, licenses, supports, and sells a range of software products and services. Microsoft’s devices and consumer (D&C) licensing segment licenses the Windows operating system and related software, Microsoft Office for consumers, and the Windows Phone operating system. The company’s computing and gaming hardware segment provides Xbox gaming and entertainment consoles and accessories, second-party and third-party video games, and Xbox Live subscriptions; surface devices and accessories; and Microsoft PC accessories. Its phone hardware segment offers Lumia smartphones and other non-Lumia phones. Its D&C segment provides Windows Store, Xbox Live transactions, and Windows phone store; search advertising; display advertising; Office 365 Home and Office 365 Personal; first-party video games; and other consumer products and services as well as operating retail stores. Microsoft’s commercial licensing segments license server products, including Windows Server, Microsoft SQL Server, Visual Studio, System Center, and related Client Access Licenses (CALs); Windows Embedded; Windows operating system; Microsoft Office for business, including Office, Exchange, SharePoint, Lync, and related CALs; Microsoft Dynamics business solutions; and Skype. Its commercial segment offers enterprise services, including premier support services and Microsoft consulting services; commercial cloud comprising Office 365 Commercial, other Microsoft Office online offerings, Dynamics CRM Online, and Microsoft Azure; and other commercial products and online services. The company markets and distributes its products through original equipment manufacturers, distributors, and resellers, as well as online.

Microsoft Careers

Join Microsoft today and be part of a company that values innovation, leadership, and diversity in its workforce. As a global leader in technology and digital transformation, Microsoft offers unparalleled job opportunities that propel your career to new heights.

Explore Career Opportunities at Microsoft

Whether you're a seasoned professional looking for your next challenge or a recent graduate eager to start your career, Microsoft has a position that suits your skills and ambitions. We are committed to fostering a culture of growth and learning, where every team member is supported in expanding their horizons.

Internship Programs

Kickstart your career with a Microsoft internship. Our internships provide invaluable workplace experience and networking opportunities in a supportive and dynamic environment. You'll work on real projects, learn from industry leaders, and gain the skills necessary for a successful career in technology.

Employment Benefits

Choosing a career at Microsoft means more than just a job. Our employees enjoy a range of benefits designed to empower them both professionally and personally. These include comprehensive health benefits, flexible working conditions, and opportunities for career advancement through professional development and diversity training.

Inclusive Culture and Diversity

At Microsoft, we believe that innovation comes from diversity of thought and inclusion. We are committed to a workplace where everyone feels valued and inspired. Our leadership is dedicated to fostering an environment where diverse perspectives lead to breakthrough innovations and a competitive edge.

Grow with Us

Career growth at Microsoft is about more than climbing the corporate ladder; it's about continuous learning, expanding your skills, and improving your capabilities. With access to various leadership and training programs, you can evolve as a professional and make a significant impact within the company and on the global stage.

Hiring Process

Our hiring process is designed to identify true potential. Starting with a review of your resume, followed by interviews that assess your problem-solving abilities and cultural fit, we ensure that all candidates have a fair chance to demonstrate their strengths and potential to contribute to our team.

Networking and Professional Development

Microsoft is a place where you can build a professional network that spans the globe. Our employees benefit from connections with top-tier professionals and industry leaders, which opens doors to innovative projects and collaborative opportunities that are second to none.

Join Our Team

If you're ready to take on exciting challenges and make a difference in the world of technology, explore the job opportunities at Microsoft. Search for open positions that match your skills and interests, and prepare to embark on a rewarding career path filled with innovation and opportunities for personal and professional growth.

Stay Connected

Keep up to date with the latest at Microsoft Careers by subscribing to our job alert emails. Get tailored content that aligns with your career preferences and discover the exciting and rewarding opportunities that await at Microsoft.

SEARCH MICROSOFT JOBS

At Microsoft, your future is limitless. Join us in our mission to empower every person and every organization on the planet to achieve more. Your journey with Microsoft starts here.
Learn more about Microsoft
Size
181,000 employees
Market Cap
$1,762.4 billion
Industry
Net Income
$51.3 billion
Founded
1975
5 Year Trend
+15.5%
Revenue
$153.2 billion
NASDAQ

Similar Jobs

More Jobs at Microsoft

More Information Technology Jobs

Find similar Principal Security Engineer jobs: