Description
The Microsoft Edge Browser Security team is responsible for protecting the security of Microsoft Edge and helping make the web safer for billions of users worldwide.
As a Principal Security Engineer, you will help define security strategy, identify systemic risk, and drive security investments that have broad impact across Microsoft Edge and the Chromium ecosystem.
Responsibilities:
- Evaluates the security landscape to identify emerging trends and potential exploitable areas of vulnerability for Microsoft, supported, and/or competitor products.
- Conducts high-level analysis of complex security threats with a forward-looking perspective.
- Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions.
- Leverages artificial intelligence (AI) workflows to understand research operations and how customers use Microsoft products and proposes solutions to deliver comprehensive protection.
- Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives.
- Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes.
- Maintains and shares deep knowledge of industry trends, technologies, tools, securities, and advances.
- Proactively contributes to internal and external community through publications, white papers, seminars, or conferences, shaping understanding of threat protection in real-world impact and storytelling.
- Establishes deployment and security configuration standards and best practices to ensure technologies are deployed in a secure fashion across the organization.
- Directs organization-wide security reviews, including architectural and design reviews, and synthesizes findings in analysis reports.
- Leads the implementation of best practices for security architecture, design, and development across product and feature areas and teams.
- Proactively evaluates and prioritizes security risks and orchestrates cross-functional partnerships to remove blockers and mitigate risks.
- Oversees the monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed.
- Solves classes of issues in technical implementation and automation of solutions related to specific kinds of security issues.
- Leads multidisciplinary teams to innovate and implement improvements in solutions and methods.
Qualifications:
- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
- OR equivalent experience.
Preferred Qualifications:
- Significant experience in areas such as:
- Vulnerability research and exploit analysis.
- Code auditing and secure architecture review.
- AI assisted Vulnerability Research.
- Fuzzer development and crash triage.
- Browser, application, operating system, or cloud security.
- Threat modeling and attack surface analysis.
- Security automation and AI-assisted security research.
- Software engineering and computer science fundamentals.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://microsoft.ai/job/principal-security-engineer-4/