Microsoft Logo

Microsoft

Security Engineer

Posted 13 Hours Ago
Be an Early Applicant
In-Office
Redmond, WA, USA
102K-219K Annually
Junior
In-Office
Redmond, WA, USA
102K-219K Annually
Junior
Designs and deploys scalable security controls that prevent recurring identity-platform vulnerabilities. Translates breach learnings and threat actor behavior into reusable enforcement frameworks, integrates protections across production services, and automates countermeasures across Microsoft’s identity fleet. The role partners with engineering teams to strengthen authentication and authorization defenses while maintaining service reliability.
The summary above was generated by AI
Overview

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.

The Identity Security (IDSEC) Breach Preventions team is responsible for preventing repeat security incidents across Microsoft’s Identity platform by building scalable, engineering driven security controls that eliminate entire classes of vulnerabilities before they can be exploited. Our team operates at the intersection of software engineering and security research to design and deploy platform level countermeasures across Microsoft’s Identity and Network Access (IDNA) services. We focus on proactively identifying authentication and authorization attack paths, translating breach learnings into reusable preventative mechanisms, and automating security enforcement across hundreds of production services. Our goal is to move beyond reactive vulnerability mitigation by harmonizing engineering and security systems to automate reusable protections across the identity technology stack.

We are looking for a Security Engineer, who can help contribute to scalable automation and analysis across signals from vulnerability research, threat intelligence, and security risk posture monitoring. Our culture is inclusive, casual, and highly engaged; our researchers and engineers come from diverse backgrounds, are passionate and grounded in our customer needs.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.


Responsibilities
  • Translating breach learnings and threat actor behaviors into deterministic engineering controls that prevent recurrence across multiple services.
  • Designing platform level enforcement mechanisms that eliminate classes of vulnerabilities without requiring service by service remediation.
  • Developing reusable prevention frameworks and paved path security standards.
  • Partnering with engineering teams to integrate preventative controls into production environments while maintaining service reliability.
  • Enabling rapid deployment of security countermeasures across Microsoft’s identity fleet to proactively strengthen defenses against emerging threats.

Qualifications

Minimum Qualifications:

  • Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 1+ year(s) experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 2+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

Microsoft Cloud Background Check:

  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
    • OR equivalent experience.
  • 3+ years experience in Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response.
  • Understanding of identity and access technologies, such as authentication and authorization protocols (OAuth, OIDC, SAML), tokens, certificates/PKI, and MFA.

Security Research IC3 - The typical base pay range for this role across the U.S. is USD $102,100 - $202,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $133,800 - $219,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

HQ

Microsoft Redmond, Washington, USA Office

1 Microsoft Way, Redmond, WA, United States, 98052

Microsoft Bellevue, Washington, USA Office

Bellevue, United States

Microsoft Issaquah, Washington, USA Office

Issaquah, United States

Microsoft Kirkland, Washington, USA Office

Kirkland, United States

Microsoft Mercer Island, Washington, USA Office

Mercer Island, United States

Microsoft Sammamish, Washington, USA Office

Sammamish, United States

Microsoft Seattle, Washington, USA Office

Seattle, United States

Similar Jobs

12 Hours Ago
In-Office
Seattle, WA, USA
47-64 Hourly
Internship
47-64 Hourly
Internship
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Security Engineering Intern responsible for completing a scoped security project, developing automation and investigation tools, researching vulnerabilities, analyzing findings, validating AI-assisted outputs, collaborating with engineers, and documenting and demonstrating solutions. The role requires programming, web and systems knowledge, foundational security understanding, AI familiarity, and current enrollment in a bachelor’s or master’s program.
Top Skills: APIsAutomated TestingBurp SuiteGitGoJavaScriptLarge Language ModelsLlm ApisOwasp ZapPythonSemgrepSnykTypescript
Yesterday
In-Office or Remote
Seattle, WA, USA
223K-279K Annually
Senior level
223K-279K Annually
Senior level
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Build and mature Headway’s infrastructure security program across AWS and application platforms. Partner with Product and Infrastructure teams on secure system design, security reviews, platform guardrails, vulnerability remediation, and continuous infrastructure improvement. Support incident response and security operations while advancing AI-native cloud security practices. The role requires strong technical depth, cross-functional collaboration, and the ability to establish secure-by-default engineering practices in an ambiguous, fast-paced environment.
Top Skills: Amazon EcsAmazon S3AnthropicAWSAws FargateCloudflareCursorDatadogFastapiGitKubernetesLangsmithPagerdutyPostgresPython 3ReactRedisSemgrepSqlalchemyTypescriptWiz
4 Days Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
134K-168K Annually
Senior level
134K-168K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead insider risk detection engineering and investigations using EDR/XDR, UEBA, SIEM, and SOAR tools. Refine detection rules, reduce alert noise, close coverage gaps, manage investigations, develop playbooks, document evidence, mentor analysts, and collaborate discreetly with HR, Legal, business leaders, and executives. The role also requires investigative workflow automation using Python or JavaScript and ownership of scalable security processes.
Top Skills: Ai/MlCertEdr/XdrJavaScriptNistNsaPythonSIEMSoarUebaZscaler Cyberrisk ProtectionZscaler Data ProtectionZscaler Zero Trust Networking

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account