> Markdown version of [/jobs/ext/1509353-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/1509353-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** Microsoft - **Location:** Redmond, WA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Information Systems Security Architecture Professional, Reverse Engineering, Software Engineering, Malware, Information Technology, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 30, 2026 - **Apply:** https://www.careerjet.com/job/uscf71076dde0111a7add4052833bc20c5/eaa ## About the Role multidisciplinary teams to innovate and implement improvements in solutions and methods. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience. Vulnerability research and exploit analysis. Code auditing and secure architecture review. AI assisted Vulnerability Research. Fuzzer development and crash triage. Browser, application, operating system, or cloud security. Threat modeling and attack surface analysis. Security automation and AI-assisted security research. Software engineering and computer science fundamentals. ## Description Conducts high-level analysis of complex security threats with a forward-looking perspective. Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions, including for integration in or addition to new/existing products or features. Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives. Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes (e.g., architecture, failure modes, attack chain, threat modeling, vulnerabilities). Maintains and shares deep knowledge of industry trends, technologies, tools, securities, and advances. Proactively contributes to internal and external community through publications, white papers, seminars, or conferences, shaping understanding of threat protection in real-world impact and storytelling. Establishes deployment and security configuration standards and best practices to ensure technologies are deployed in a secure fashion across the organization. Directs organization-wide security reviews, including architectural and design reviews, and synthesizes findings in analysis reports. Leads the implementation of best practices for security architecture, design, and development across product and feature areas and teams. Proactively evaluates and prioritizes security risks and orchestrates cross-functional partnerships to remove blockers and mitigate risks. Oversees the monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed. Solves classes of issues in technical implementation and automation of solutions related to specific kinds of security issues (e.g., security posture, signature-based detection, malware, threat analysis, reverse engineering, attack disruption, anomaly detection). Leads ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Hacking iOS and Developing for Airbnb with Nicolas Haunold, Software Engineer at Airbnb](https://www.wearedevelopers.com/videos/100361-hacking-ios-and-developing-for-airbnb-with-nicolas-haunold-software-engineer-at-airbnb) - [WeAreDevelopers LIVE - Yes, CSS Can Do That!](https://www.wearedevelopers.com/videos/1819-wearedevelopers-live-yes-css-can-do-that) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)