# Principal Security Engineer

**Company**: Microsoft
**Location**: Redmond, Washington
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: USD $142,800 – $274,800 per year
**Category**: Engineering
**Industry**: Technology
**Ticker**: MSFT
**Wikidata**: https://www.wikidata.org/wiki/Q2283

**Apply**: https://microsoft.ai/job/principal-security-engineer-4/?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_cfb6fa39-436

## Description

The Microsoft Edge Browser Security team is responsible for protecting the security of Microsoft Edge and helping make the web safer for billions of users worldwide.

As a Principal Security Engineer, you will help define security strategy, identify systemic risk, and drive security investments that have broad impact across Microsoft Edge and the Chromium ecosystem.

Responsibilities:

- Evaluates the security landscape to identify emerging trends and potential exploitable areas of vulnerability for Microsoft, supported, and/or competitor products.

- Conducts high-level analysis of complex security threats with a forward-looking perspective.

- Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions.

- Leverages artificial intelligence (AI) workflows to understand research operations and how customers use Microsoft products and proposes solutions to deliver comprehensive protection.

- Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives.

- Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes.

- Maintains and shares deep knowledge of industry trends, technologies, tools, securities, and advances.

- Proactively contributes to internal and external community through publications, white papers, seminars, or conferences, shaping understanding of threat protection in real-world impact and storytelling.

- Establishes deployment and security configuration standards and best practices to ensure technologies are deployed in a secure fashion across the organization.

- Directs organization-wide security reviews, including architectural and design reviews, and synthesizes findings in analysis reports.

- Leads the implementation of best practices for security architecture, design, and development across product and feature areas and teams.

- Proactively evaluates and prioritizes security risks and orchestrates cross-functional partnerships to remove blockers and mitigate risks.

- Oversees the monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed.

- Solves classes of issues in technical implementation and automation of solutions related to specific kinds of security issues.

- Leads multidisciplinary teams to innovate and implement improvements in solutions and methods.

Qualifications:

- Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection

- OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection

- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection

- OR equivalent experience.

Preferred Qualifications:

- Significant experience in areas such as:

- Vulnerability research and exploit analysis.

- Code auditing and secure architecture review.

- AI assisted Vulnerability Research.

- Fuzzer development and crash triage.

- Browser, application, operating system, or cloud security.

- Threat modeling and attack surface analysis.

- Security automation and AI-assisted security research.

- Software engineering and computer science fundamentals.

## Skills

### Required
- Statistics
- Mathematics
- Computer Science
- Computer Security
- software development lifecycle
- large-scale computing
- threat analysis or modeling
- cybersecurity
- vulnerability research
- anomaly detection

### Nice to have
- Vulnerability research and exploit analysis
- Code auditing and secure architecture review
- AI assisted Vulnerability Research
- Fuzzer development and crash triage
- Browser, application, operating system, or cloud security
- Threat modeling and attack surface analysis
- Security automation and AI-assisted security research
- Software engineering and computer science fundamentals

---

Source: [Apply at microsoft.ai](https://microsoft.ai/job/principal-security-engineer-4/?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
