About this role
<b>Overview</b><br><p><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Microsoft’s Marketing Security Risk & Compliance team is looking for a Senior Software Engineer to design and build security automation, platforms, and AI-enabled capabilities that identify and reduce security and compliance risk across the Microsoft Marketing landscape. Microsoft Marketing operates cloud services, data platforms, business applications, artificial intelligence solutions, and integrations that support critical marketing capabilities across the company. The Marketing Security Risk & Compliance team partners with engineering and service teams to identify vulnerabilities and systemic security risks, strengthen service architecture, improve compliance assurance, and drive accountable remediation. In this role, you will develop software and automation that aggregate and analyze security signals across cloud infrastructure, applications, identities, networks, data, code, and service configurations. You will build capabilities that correlate these signals to identify vulnerabilities, insecure configurations, attack paths, compliance gaps, and emerging risk patterns across Marketing services. You will also engineer AI-enabled security capabilities that improve how security programs collect evidence, analyze risk, identify threats, prioritize findings, and validate remediation. This includes building reusable services, integrations, automated workflows, queries, and intelligent agents that allow security and compliance programs to operate at scale. Threat modeling and security architecture review will be a core part of the role. You will perform threat modeling for Marketing services and high-impact programs, using hands-on analysis to understand architectures, data flows, trust boundaries, identities, attack surfaces, privileged access, and security controls. Insights from these engagements will directly inform the automation and engineering capabilities you build. This role combines software engineering, security engineering, cloud security, and security assurance. You will help move Marketing from primarily point-in-time security assessments toward a continuous, data-driven security assurance model where automation and AI identify risk across the landscape and engineering judgment validates and prioritizes the risks that matter.</span></p><br><br><b>Responsibilities</b><br><p style="margin: 12pt 0in; font-size: 12pt; font-family: Aptos, sans-serif;"><span style="font-family: 'Segoe UI', sans-serif;">Design, develop, test, deploy, and operate software services, automation, tools, and integrations supporting Marketing security and compliance programs. • Build capabilities that continuously identify vulnerabilities, insecure configurations, control gaps, and security risks across Microsoft Marketing services. • Develop automation to collect, normalize, correlate, and analyze security signals from cloud resources, applications, identities, networks, data platforms, code-security systems, service metadata, and security tooling. • Build scalable security analytics and risk-detection capabilities that identify attack paths, recurring vulnerabilities, systemic weaknesses, and emerging security patterns across the Marketing landscape. • Develop AI-enabled security automation and agents that accelerate evidence collection, threat identification, risk analysis, finding generation, remediation guidance, and security-program workflows. • Engineer reusable services, APIs, queries, pipelines, integrations, and workflow automation that enable security and compliance programs to operate at scale. • Build automation supporting security compliance and continuous assurance programs, including control validation, evidence collection, gap identification, exception management, and remediation tracking. • Perform end-to-end threat modeling and technical security reviews for Marketing services, platforms, AI solutions, tenant migrations, and other high-impact initiatives. • Analyze business context, service architecture, data flows, trust boundaries, service dependencies, identities, endpoints, privileged access, network exposure, logging, data classifications, and security controls. • Apply Microsoft security requirements and Secure Development Lifecycle practices to identify design weaknesses, implementation vulnerabilities, missing controls, and material security risks. • Use findings from threat models, incidents, security assessments, and security telemetry to identify opportunities for new automated controls and detection capabilities. • Validate automated and AI-generated security findings, reduce false positives, improve detection quality, and ensure automation focuses engineering teams on material risk. • Integrate security findings and remediation workflows with appropriate engineering tracking and security systems. • Develop mechanisms to measure security posture, compliance assurance, remediation progress, and recurring risk patterns across Marketing services. • Partner with service engineers, architects, security teams, privacy teams, Responsible AI practitioners, and program owners to design practical security solutions. • Provide engineering support for tenant migrations, platform modernization, AI adoption, and other high-impact programs where security capabilities must be integrated into the engineering lifecycle. • Develop reusable security patterns, libraries, templates, and engineering guidance that allow service teams to implement security requirements consistently. • Contribute to architecture and design decisions for security platforms, automation frameworks, data pipelines, and AI-enabled security capabilities. • Mentor engineers and security practitioners on secure engineering, threat modeling, security automation, and the effective use of security telemetry. • Communicate systemic security risks, engineering priorities, and remediation strategies clearly to service teams, program owners, and leadership. • Experience conducting or contributing to threat modeling, security architecture reviews, application security assessments, or Secure Development Lifecycle activities.</span></p><br><br><b>Qualifications</b><br><p><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Required Qualifications </span></p><p><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python </span><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">OR equivalent experience. </span></p><p><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Preferred Qualifications</span></p><ul><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;"><span style="font-size: 12pt; font-family: 'Segoe UI', sans-serif;">Professional software development experience using one or more general-purpose programming languages. </span></span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;"><span style="font-size: 12pt; font-family: 'Segoe UI', sans-serif;">Experience designing, developing, testing, deploying, and operating production software, automation, services, or engineering tools. </span></span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;"><span style="font-size: 12pt; font-family: 'Segoe UI', sans-serif;">Experience developing solutions using APIs, data pipelines, cloud services, automation frameworks, or distributed systems. </span></span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;"><span style="font-size: 12pt; font-family: 'Segoe UI', sans-serif;">Experience with cybersecurity principles and identifying vulnerabilities, design weaknesses, insecure configurations, or security-control gaps.</span></span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience building security platforms, developer-security tooling, compliance automation, security analytics, vulnerability-management systems, or continuous-assurance capabilities. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience with Microsoft Azure or another major cloud platform and cloud-native software development. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience developing security automation using cloud-resource APIs, security telemetry, code-security signals, identity information, asset inventories, or configuration data. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience applying AI, machine learning, large language models, agents, or other AI technologies to security engineering, automation, or operational workflows. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience designing systems that correlate multiple security signals to identify vulnerabilities, attack paths, control gaps, or systemic risk. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience with threat-modeling methodologies, attack-path analysis, data-flow diagrams, trust boundaries, and secure architecture reviews. </span></li><li><span style="font-size: 12.0pt; font-family: 'Segoe UI', sans-serif;">Experience with Azure DevOps, CI/CD systems, code-security platforms, cloud-security posture management, data-classification tooling, or similar engineering systems.</span></li></ul> <br><br><p>Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year. </p><p></p> <p>Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:<br><a href="https://careers.microsoft.com/us/en/us-corporate-pay">https://careers.microsoft.com/us/en/us-corporate-pay</a></p><br><p>This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.</p><br><hr><br><p>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about <a href="https://careers.microsoft.com/v2/global/en/accessibility.html"><b><u>requesting accommodations.</u></b></a></p>