Job Description
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
The mission of Microsoft CISO Operations team is to enable Microsoft to build the most trusted devices and services, while keeping our company safe and our data protected. As part of the Microsoft Cloud and AI organization, and a steward of Microsoft and our customer's data, a core function of Microsoft CISO Operations is ensuring the security of every aspect of the business. Microsoft CISO Operations is responsible for company-wide information security and compliance, with a strategic focus on information protection, assessment, awareness, governance, and enterprise business continuity. As customer zero, we deploy and secure these services inside Microsoft and then share best practices with enterprise customers on a scale across the globe. We have exciting opportunities for you to innovate, influence, transform, inspire, and grow within our organization and we encourage you to apply to learn more!
Do you have a passion for information and cloud security? Do you get excited about protecting Microsoft by setting the direction and guidance for securing our enterprise's Azure Cloud and other existing infrastructure? This is your opportunity to be a leader in protecting the end-to-end infrastructure that enable our businesses while protecting the enterprise from current and future threats.
CISO Operations is looking for a **Senior Software Engineer** to improve and expand the security of Azure and other infrastructure through the definition and implementation of security controls leveraging Microsoft security products and custom tooling. As part of a high impact security team, you will be empowered to lead and work across Microsoft's organizations to raise the bar for protecting the Microsoft cloud and other infrastructure.
In this role, you will leverage your software development expertise to build capabilities including automation to increase the security posture of Microsoft cloud infrastructure that bring alignment to standards, processes, and technologies used to secure Azure infrastructure in the enterprise. You will identify systemic areas of opportunity, define plans to close gaps, and gain buy-in from teams across Microsoft to execute the plans. You will identify and push for automation and drive towards secure by default environments. Along the way, you will be a trusted voice who shares your knowledge and expertise.
_Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond._
**Responsibilities**
As a Senior Software Engineer, you will focus on 6 key components:
Cloud Security Engineering
- Design and implement secure cloud-native applications and services across cloud platforms.
- Develop and maintain security automation and tooling to detect, prevent, and respond to threats.
- Implement infrastructure security controls such as network segmentation, encryption, key management, and secure service-to-service communication.
Security Architecture & Development
- Collaborate with architecture teams to integrate security into system design and service lifecycles.
- Define and enforce secure coding standards, conduct peer code reviews with a security-first mindset.
- Build and maintain CI/CD pipeline security, incorporating SAST, DAST, container scanning, and compliance checks.
Threat Detection & Response
- Develop systems for real-time monitoring, alerting, and anomaly detection within cloud environments.
- Work with security teams to analyze and respond to incidents, contribute to root cause analysis, and drive remediation.
- Build capabilities for log ingestion, analysis, and forensic readiness using tools like CloudTrail, Security Hub, or SIEM platforms.
DevSecOps & Automation
- Create and manage infrastructure-as-code (e.g., Terraform, CloudFormation) with security best practices.
- Automate manual security tasks to reduce risk and human error across engineering teams.
- Integrate security scanning and compliance checks directly into developer workflows.
Cross-Functional Collaboration
- Work closely with product, platform, and SRE teams to ensure secure product delivery.
- Serve as a technical advisor on security across multiple teams and initiatives.
- Mentor junior engineers on secure design and implementation patterns.
Leadership-Oriented Responsibilities
- Drive security architecture reviews for new projects.
- Lead incident response exercises or threat modeling workshops.
- Participate in open-source security tool development or research.
**Qualifications**
**Minimum Qualifications:**
+ Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python.
+ OR equivalent experience.
+ 2+ years of experience producing concise and quality technical documentation.
+ 1+ years of experience with hands on cloud infrastructure / security configuration experience.
+ 1+ years of experience with building networking infrastructure and network security operations.
+ Customer facing experience supporting complex infrastructure products or solutions.
**Other Requirements:**
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check:
+ This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
**Preferred Qualifications:**
+ Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python.
+ OR Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python.
+ OR equivalent experience.
+ General cybersecurity experience.
+ General understanding of cybersecurity standards.
+ Demonstrated leadership capabilities with an ability to influence the business and stakeholders as well as foster effective collaboration across diverse business units.
+ Presentation skills and experience with presenting to management.
Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $158,400 - $258,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
Microsoft will accept applications for the role until July 15, 2025.
**\#MSFTSecurity #Security #CSVA**
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations ( .
Job Tags
Local area,
Similar Jobs
Center of Excellence in Wireless Technology
Role Overview: As an Entry-Level Virtual Assistant, you will provide essential administrative and operational support to our team and clients. Your role will involve handling a variety of tasks such as scheduling, email management, data entry, and customer communication...
Senior Helpers Maine LLC
...personal protective equipment and work supplies* Maine paid family medical leave Description of the role:As a Home Health Registered Nurse at Senior Helpers Maine LLC in Penobscot county of Maine, you will be responsible for providing essential care to...
The Bridgerr Group
...candidate will be responsible for maintaining diverse plant health, including vegetables, herbs, and flowers, as well as assisting with greenhouse operations and potential homesteading activities. Responsibilities - Perform regular garden duties, including: - Watering...
ManTech
ManTech seeks a motivated, career and customer-oriented Information Systems Security Officer (ISSO) to join our Air Force / Space team at Eglin AFB.The ISSO's primary function is to support the United States Air Force's 53rd Wing Technical Support Services (53rd WTSS) contract...
SupportFinity
Postman is the worlds leading API platform, used by more than 35 million developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API...