Principal Security Engineer

Reposted 3 Hours Ago
Be an Early Applicant
Redmond, WA, USA
In-Office
143K-304K Annually
Senior level
Software • Quantum Computing • Metaverse • Infrastructure as a Service (IaaS)
The Role
Lead strategic security efforts for Microsoft Edge across proactive research, engagement, and incident response. Drive vulnerability research, fuzzing, exploit analysis, code auditing, threat modeling, and AI-assisted security workflows. Guide cross-functional security reviews, define secure architecture and deployment standards, mentor engineers, and coordinate responses to emerging threats while influencing long-term security roadmaps and community collaboration to improve Chromium and web platform security.
Summary Generated by Built In
Overview

The Microsoft Edge Browser Security team is responsible for protecting the security of Microsoft Edge and helping make the web safer for billions of users worldwide. Our work spans three core areas: Security Engagement, Proactive Security, and Reactive Security.

In the Engagement space, we partner closely with engineering teams, architects, and product leaders to shape the security posture of Edge from the earliest stages of design. We provide deep technical guidance, influence product architecture, and drive adoption of secure-by-default principles, defense-in-depth strategies, and resilient security controls across the browser platform. As a Principal Security Engineer, you will help define security strategy, identify systemic risk, and drive security investments that have broad impact across Microsoft Edge and the Chromium ecosystem.

In Proactive Security, we identify and mitigate risk before it reaches customers. This includes conducting large-scale vulnerability research, security assessments, attack surface analysis, code auditing, fuzzing, exploitability analysis, and emerging threat investigations. We continuously challenge assumptions, evaluate new technologies, and develop innovative approaches to discovering vulnerabilities in complex browser, operating system, and web platform components. Principal engineers are expected to drive novel security research initiatives, influence long-term security roadmaps, and mentor others in advanced vulnerability discovery techniques.

In Reactive Security, we ensure Microsoft can rapidly detect, assess, and respond to emerging threats. We collaborate with external researchers, threat intelligence teams, MSRC, and engineering organizations to investigate security reports, prioritize mitigation efforts, and protect customers from active exploitation. Principal engineers play a key role in driving cross-organizational incident response, identifying systemic lessons from security incidents, and influencing durable security improvements that reduce future risk.

Throughout all of this, you will engage with industry partners, security researchers, and the open-source community to improve the security of Chromium and related technologies, helping strengthen the broader web ecosystem.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.  

Starting January 26, 2026, AI Experiences employees who live within a 50- mile commute of a designated Microsoft office in the U.S. or 25-mile commute of a non-U.S., country-specific location are expected to work from the office at least four days per week. This expectation is subject to local law and may vary by jurisdiction.


Responsibilities
  • Evaluates the security landscape to identify emerging trends and potential exploitable areas of vulnerability for Microsoft, supported, and/or competitor products. Conducts high-level analysis of complex security threats with a forward-looking perspective. Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions, including for integration in or addition to new/existing products or features. Leverages artificial intelligence (AI) workflows to understand research operations and how customers use Microsoft products and proposes solutions to deliver comprehensive protection. Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives.
  • Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes (e.g., architecture, failure modes, attack chain, threat modeling, vulnerabilities). Maintains and shares deep knowledge of industry trends, technologies, tools, securities, and advances. Proactively contributes to internal and external community through publications, white papers, seminars, or conferences, shaping understanding of threat protection in real-world impact and storytelling. Establishes deployment and security configuration standards and best practices to ensure technologies are deployed in a secure fashion across the organization.
  • Directs organization-wide security reviews, including architectural and design reviews, and synthesizes findings in analysis reports. Leads the implementation of best practices for security architecture, design, and development across product and feature areas and teams. Proactively evaluates and prioritizes security risks and orchestrates cross-functional partnerships to remove blockers and mitigate risks. Oversees the monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed.
  • Solves classes of issues in technical implementation and automation of solutions related to specific kinds of security issues (e.g., security posture, signature-based detection, malware, threat analysis, reverse engineering, attack disruption, anomaly detection). Leads multidisciplinary teams to innovate and implement improvements in solutions and methods.

Qualifications

Required Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR equivalent experience.

Preferred Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR equivalent experience.
  • Significant experience in areas such as:
    • Vulnerability research and exploit analysis.
    • Code auditing and secure architecture review.
    • AI assisted Vulnerability Research.
    • Fuzzer development and crash triage.
    • Browser, application, operating system, or cloud security.
    • Threat modeling and attack surface analysis.
    • Security automation and AI-assisted security research.
    • Software engineering and computer science fundamentals.

#MicrosoftAI #EdgeVR #EdgeSecurity


Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Skills Required

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection; OR Master's Degree AND 4+ years; OR Bachelor's Degree AND 6+ years; OR equivalent experience.
  • Experience conducting vulnerability research, exploit analysis, and vulnerability triage.
  • Experience with code auditing and secure architecture or design reviews.
  • Experience developing fuzzers, crash triage, and fuzzing infrastructure.
  • Experience with browser, operating system, application, or cloud security.
  • Experience with threat modeling, attack surface analysis, and security automation.
  • Experience leveraging AI-assisted workflows for vulnerability research and security analysis.
  • Strong software engineering and computer science fundamentals.

Microsoft Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.

  • Fair & Transparent Compensation Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
  • Retirement Support Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
  • Parental & Family Support Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.

Microsoft Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Redmond, WA
206,870 Employees
Year Founded: 1975

What We Do

At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.

Similar Jobs

Remitly Logo Remitly

Security Engineer

eCommerce • Fintech • Payments • Software • Financial Services
In-Office
Seattle, WA, USA
2800 Employees
256K-320K Annually

Citizens Logo Citizens

Security Engineer

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees
150K-190K Annually
Hybrid
3 Locations
289097 Employees

Zscaler Logo Zscaler

Sales Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
USA
8697 Employees
176K-251K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account