Padmi
Microsoft logo
Microsoft

cloud computing (Azure) · AI and machine learning (Copilot, CoreAI)

Principal Software Engineers

Seattle · OnsitePosted 1 month ago
Software engineeringStaff+Full TimeH-1B track record
Apply at Microsoft

Opens the source posting on apply.careers.microsoft.com

Source description

About the role

View original

Security teams can identify vulnerabilities in running applications without a clear or fast path back to the code that caused them. Developers often lack real-time insight into how their code behaves under attack. Closing that gap is one of the most important unsolved challenges in security. MDASH is our first step. There's much more ahead. And to be clear, while we're helping shape the future of AI and security, this job description isn't AI-generated. It was written intentionally, because this work is about people. There are very few places where an individual engineer's code can directly impact customers. Defender is one of them. If you enjoy building, care about solving meaningful problems, and want to work with people who are equally passionate, let's talk. Design, build, and improve systems that enhance security across software supply chains and open-source ecosystems (e.g., npm, PyPI, NuGet, Maven, Cargo). Analyze dependencies, vulnerabilities, and potential malware to help ensure the integrity and safety of software components. Apply program analysis techniques (static, dynamic, sandboxing/detonation, deobfuscation, behavioral analysis) to better understand and assess code behavior. Develop and operate scalable cloud-based pipelines (Azure preferred) for large-scale scanning, detection, and data processing. Contribute to and uphold supply chain integrity practices, including SBOM, SLSA, provenance, and artifact signing (e.g., Sigstore). Collaborate on threat detection and security research, including malware and vulnerability analysis, within security-sensitive systems. Integrate security capabilities with developer tools and platforms such as GitHub, Visual Studio, and CI/CD systems. Partner cross-functionally with engineering, security, and product teams to improve secure development practices. Continuously evaluate and improve detection methods, tooling, and processes to adapt to evolving security threats. Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience These requirements include but are not limited to the following specialized security screenings: Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience. 4+ years of experience designing, building, and shipping production backend services, platforms, or data pipelines. 4+ years of experience with software supply chain security and open-source ecosystems (e.g., npm, PyPI, NuGet, Maven, Cargo), including dependency, vulnerability, or malware analysis. 4+ years of experience with program analysis techniques (e.g., static/dynamic analysis, sandboxing, deobfuscation, behavioral analysis) to understand code behavior. 4+ years of experience building or operating large-scale cloud-based scanning, detection, or data-processing pipelines (Azure preferred). 4+ years of experience with supply chain security standards (e.g., SBOM, SLSA, provenance, artifact signing) and integrating with CI/CD systems.

More at Microsoft

Related open roles

View all roles