Microsoft

Principal Service Engineer - Security Focused

Microsoft Redmond, Washington, United States · $143K–$304K/yr

Software Development · 10,001+ employees

11 h ago
Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will lead the design and implementation of cloud and hybrid network security across Microsoft's Azure estate, setting technical direction and defining security controls. Additionally, you will drive AI-driven security operations, respond to complex incidents as a senior technical lead, and influence security policy across the organization.

What they look for

Cloud Security Network Security Azure Security Architecture Vulnerability Management Identity and Access Management Threat Detection Incident Response Infrastructure as Code Automation Kusto Microsoft Sentinel Azure Firewall Zero Trust Compliance Mentoring

Requirements

Candidates must have a Bachelor's degree in a technical field and at least 6 years of relevant experience in software, network, or systems engineering. Deep expertise in Azure network infrastructure, cloud security governance, and threat detection is highly preferred.

Benefits

Health Insurance Retirement Plan Paid Time Off Professional Development Inclusive Culture

Full description

Overview Help secure the cloud Microsoft runs on. Microsoft Digital's Network Defense Engineering (NDE) team in Redmond, Washington is hiring a Principal Security Engineer to lead cloud and hybrid network security.

Microsoft Digital (MSD) builds and runs the products and services Microsoft depends on. We pursue big ideas that drive transformational advances for Microsoft and its customers, and our engineers bring deep technical expertise and large-scale, first-hand experience to every problem we solve.

As a Principal Service Engineer - Security Focus with a Cloud Security focus on the NDE team, you will set the technical direction for cloud security and extend our security programs - governance, exposure management, protection, detection, and response - from the on-premises network into Azure and our hybrid estate. You will partner closely with Cloud Network Engineering, the team that operates Microsoft's cloud connectivity, secure network zones, and Azure Firewall infrastructure, to harden the boundary between our corporate networks and the cloud, and you will define the security architecture, controls, and telemetry that protect it.

Working from industry-standard cybersecurity frameworks, you will lead multi-team programs spanning secure configuration and policy enforcement, identity and privileged access, vulnerability and configuration compliance, threat detection, and automated response. You will influence security policy across organizations, mentor engineers, and serve as a senior technical voice during major-impact incidents.

Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • You will lead the design and implementation of cloud and hybrid network security across Microsoft's Azure estate - security architecture, segmentation and zone models, secure connectivity, and control-plane protections - identifying gaps in existing industry standards and setting the technical direction that other teams build on.
  • You will extend NDE's security programs into the cloud space using the industry-standard cybersecurity frameworks- governance and secure configuration standards, exposure and vulnerability management, identity and privileged access, configuration compliance, and threat detection and response - defining the controls, adoption plan, and success measures for each.
  • You will create and monitor action plans for telemetry data and drive analytics that improve the detection and troubleshooting of problems, building large-scale detection and monitoring in Kusto (Azure Data Explorer)/Microsoft Sentinel, Microsoft Defender for Cloud and other Big Data tools such as Spark, SQL, and delivering high-quality automation that removes manual toil.
  • You will lead AI-driven security operations across cloud, network, and infrastructure environments and define security standards for agentic systems that monitor, troubleshoot, configure, and remediate this estate, embedding AI-first security principles into their architecture, engineering, deployment, governance, and incident response, including least-privilege access for agents that operate network and infrastructure.
  • You will respond to incidents and highly complex issues as a senior technical lead in the on-call (DRI) rotation - driving triage, root-cause analysis, containment, and enforcement actions - and then implement the automations and controls that prevent recurrence.
  • You will build coalitions of support across Cloud Network Engineering, security, identity, and application teams to deliver difficult cross-organization projects, resolve team misalignments, and influence security policy, standards, and architectural review.
  • You will ensure adherence to and implementation of security, privacy, and compliance standards - including threat modeling, proactive security reviews, penetration testing, SOX compliance, and audits - while developing thought leadership and mentoring other engineers.
  • Embody our culture and values.

Qualifications Required/Minimum Qualifications:

  • Bachelor's Degree in Computer Science, Information Technology, Mechanical Engineering, Electrical Engineering, Aerospace Engineering, Data Science, Cybersecurity, or related field AND 6+ years technical experience in software engineering, network engineering, service engineering, systems engineering, or industrial controls OR equivalent experience.

Other Requirements:

  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred/Additional Qualifications:

  • 5+ years technical experience working with large-scale cloud or distributed systems, including leading security architecture or security programs across multiple teams.
  • Deep experience securing Azure network infrastructure - Network Security Groups, Application Security Groups, Azure Firewall and Firewall Manager, Web Application Firewall, DDoS Protection, NAT Gateway and SNAT behavior, Private Link and private endpoints, and hub-and-spoke topologies.
  • Experience with enterprise hybrid connectivity and its security implications - ExpressRoute circuits, private peering and gateways, BGP and AS-path routing behavior, VNet peering, network zoning and trust boundaries, and DNS design including Anycast and Private DNS zones.
  • Experience with cloud security posture and governance at scale - Azure Policy, resource locks, Microsoft Entra ID, RBAC, PIM and least-privilege access, managed identities, Azure Key Vault and secrets management, subscription and tenant hardening, and Microsoft Defender for Cloud.
  • Experience with cloud threat detection and response - Microsoft Sentinel, Microsoft Defender XDR, KQL and Kusto (Azure Data Explorer), security telemetry and logging pipelines, and security orchestration and automated response.
  • Experience delivering security automation and infrastructure as code - ARM templates, Bicep or Terraform, PowerShell or Python, REST APIs, Azure DevOps pipelines, and policy-as-code.
  • Experience applying a security framework such as the NIST Cybersecurity Framework 2.0 or Zero Trust to build and mature enterprise security programs, including threat modeling, security reviews, and audit and SOX readiness.
  • Experience in SOC, SecOps, or InfoSec environments, including incident response, threat hunting, and vulnerability management across cloud and hybrid environments.
  • Relevant industry certifications such as AZ-500, SC-100, CISSP, CCSP, CCNP or CCIE Security, OSCP, or SANS GIAC (GCIA, GCIH, GPCS).

#MSD #MSDJOBS #NetworkDefense #CloudSecurity #Azure #Security #ServiceEngineering

Service Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.