Padmi
Microsoft logo
Microsoft

cloud computing (Azure) · AI and machine learning (Copilot, CoreAI)

Principal Software Engineer

Seattle · OnsitePosted 2 months ago
Software engineeringStaff+Full TimeH-1B track record
Apply at Microsoft

Opens the source posting on apply.careers.microsoft.com

Source description

About the role

View original

Set the technical strategy and architecture for AEGIS — multi-service security platforms, AI agentic systems (agentic vulnerability detection, continuous assessment, triage, automated/recommended remediation), and the developer-facing surfaces hundreds of IC3 engineers depend on. Own the 12-24 month technical roadmap and trade-offs. Provide architecture depth and review rigor across IC3 security work — lead design reviews, security reviews, and threat-model deep dives; act as the final technical reviewer on the most ambiguous, highest-risk designs; raise the bar without becoming a bottleneck. Define and enforce quality gates — codify the policies, controls, telemetry, and pipeline checks (SFI waves, secure-by-default patterns, identity / network / data protections, container hardening, key management) that make consistent security execution the default across IC3 services. Drive partner alignment across IC3 and M365 — with security architects, MSRC, privacy, compliance, and service-owner leadership; resolve cross-team architectural disagreements; ensure SFI and incident-driven work lands as a coherent program, not isolated point fixes. Apply AI/ML pragmatically and rigorously — set the architecture for agents that fuse service context, code signals, policy, and telemetry to reduce false positives, prioritize the highest-risk findings, and drive measurable remediation throughput; establish evaluation, safety, and human-in-the-loop patterns the rest of the org can adopt. Own production posture and incident leadership — serve as a senior DRI, lead Sev 1/2 post-incident reviews, and ensure outcomes are durable engineering improvements, not one-offs. Grow the bench — mentor senior and mid-level engineers, sponsor stretch work, contribute to hiring and calibration, and model inclusive, data-driven engineering culture. Communicate with leadership — write the technical narratives, briefs, and reviews that align L3/L4 partners and executive stakeholders on direction, risk, and investment. Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python These requirements include but are not limited to the following specialized security screenings: Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience. 6+ years of experience designing, shipping, and operating production cloud or large-scale distributed services (Azure, AWS, or GCP). 4+ years of demonstrated experience in security, trust, or compliance engineering — secure design, threat modeling, authN/authZ, secrets and key management, network and data protection, vulnerability management, or incident response. Proficiency in one or more modern languages such as C#, Python, Go, or Java, with a track record of personally shipping and operating production code. Demonstrated track record of technical leadership without formal authority — leading multi-team designs, raising the bar via review, and influencing peer principals and architects. Demonstrated experience architecting and shipping platform / multi-service systems end-to-end with measurable, business-visible outcomes (risk reduction, MTTR, coverage, developer adoption). Hands-on experience applying AI / ML or LLM-based agentic systems to engineering or security problems — vulnerability detection, triage, code analysis, anomaly detection, developer copilots — including evaluation, safety, and human-in-the-loop design. Deep familiarity with cloud-native security controls at scale: managed identity, Key Vault / HSM, network isolation, container and Kubernetes hardening, policy-as-code, secure SDLC. Solid working knowledge of compliance and regulatory frameworks — SOC 2, ISO 27001, GDPR, HIPAA, FedRAMP, DoD IL5 — and a track record of encoding them into engineering automation and quality gates. Mature DevSecOps practice: CI/CD, infrastructure-as-code (Bicep, Terraform), observability/telemetry, shift-left tooling, and policy / control automation. Track record of mentoring senior engineers and influencing principal-level peers and architects across organizational boundaries. Experience leading Sev 1/2 incident response and converting incidents into durable engineering programs. Excellent written and verbal communication — able to align executives, peer principals, partner teams, and customers on complex technical and risk trade-offs.

More at Microsoft

Related open roles

View all roles