Skip to content

Open nowPosted 11 hours agoWe saw it 9 min after it went up

Principal Software Engineer

Microsoft609 open roles

Where
Redmond, WA, United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Software EngineerMicrosoft · Redmond, WA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Microsoft's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Microsoft postings stay open a median of 22 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 11 hours ago

Microsoft median: 22 days open

The posting

Overview

Secure the next generation of Copilot experiences

The Copilot Security Engineering team sits at the core of Microsoft’s mission to deliver secure, trusted, and human-centered AI experiences across Microsoft’s Copilot offerings. We build the systems that detect, evaluate, and defend against emerging AI threats, including prompt injection, memory poisoning, data exfiltration, adversarial inputs, and abuse of agentic workflows. Our goal is to establish industry-leading security protections that enable customers to confidently adopt AI at scale.

Our team combines security engineering, AI systems expertise, and threat research to identify emerging risks, develop novel defenses, and continuously measure their effectiveness in production. We work closely with product teams, Microsoft Research, and platform organizations to ensure security is built into every layer of the Copilot ecosystem.

We are looking for a Principal Software Engineer to set technical direction and own the architecture of AI threat detection and defense capabilities spanning multiple Copilot experiences. You will turn ambiguous, evolving threats into an actionable engineering strategy and reusable platform protections, aligning partners on priorities, interfaces, and measurable security outcomes.

This is a hands-on individual contributor role at the intersection of security, AI, and large-scale distributed systems. You will design and write production code, lead complex work from threat discovery through deployment and operation, and remain accountable for the effectiveness and reliability of the defenses you deliver. Your impact will extend through cross-team architectural decisions, partner influence, and mentorship, rather than people management.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Define and drive a multi-team technical strategy for Copilot security. Translate emerging threats and product needs into prioritized engineering investments, architectural decisions, and an executable roadmap with clear ownership and success measures.
  • Own the end-to-end architecture and hands-on implementation of detection and defense systems for prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and abuse of agentic workflows. Resolve ambiguous problems across AI workflows, tools, orchestration layers, trust boundaries, and platform integrations.
  • Build reusable security services, classifiers, evaluation frameworks, telemetry pipelines, and risk assessment capabilities. Establish extensible interfaces and integration patterns that enable multiple Copilot teams to adopt durable protections instead of duplicating point solutions.
  • Define security effectiveness measures and release criteria with partners, including attack coverage, detection quality, false-positive impact, and mitigation effectiveness. Use adversarial evaluations and production telemetry to validate improvements, detect regressions, and balance protection with latency, reliability, cost, and customer experience.
  • Lead threat modeling and architectural security reviews across team boundaries. Partner with security researchers, Microsoft Research, product teams, and platform organizations to investigate emerging attack techniques, validate defenses, and turn research findings into deployable engineering capabilities.
  • Remain accountable for production readiness and ongoing operation of security capabilities. Establish observability, safe rollout and rollback approaches, and operational practices; participate in on-call rotations and lead cross-team investigations during complex security events.
  • Drive root cause analysis and durable remediation after security incidents. Address systemic failure modes through shared platform defenses, regression coverage, and improvements to detection, response, and recovery.
  • Influence architectural choices and engineering investments without direct authority. Build agreement on technical tradeoffs, dependencies, and adoption plans, and communicate risk, progress, and security outcomes clearly to engineers, product partners, and leadership.
  • Raise engineering quality through design and code reviews, technical mentorship, and knowledge sharing. Help engineers reason about AI security and distributed systems, grow technical ownership, and apply sound engineering practices while continuing to contribute directly to critical implementations.

Qualifications

Required Qualifications:

  • Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or PythonOR equivalent experience.

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings:

  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications:

  • Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or PythonOR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
  • 5+ years of experience designing, building, and operating production software systems.
  • Demonstrated ownership of ambiguous technical problems from strategy and architectural design through implementation, production rollout, and sustained operation; experience aligning multiple teams on shared platform capabilities and driving adoption without direct authority.
  • Experience identifying and mitigating security risks in production, with an understanding of prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic system risks.
  • Experience building security detection, reputation, anomaly detection, threat intelligence, abuse prevention, or Trust & Safety systems, and using evaluation data and production telemetry to demonstrate measurable improvements in protection and operational quality.
  • Experience with large language models, AI systems, machine learning infrastructure, or evaluation frameworks; familiarity with AI safety, AI security research, and emerging attack and defense techniques.
  • Experience leading threat modeling, security reviews, red teaming, adversarial testing, or incident response, and translating findings into durable architectural improvements and reusable defenses.
  • Ability to communicate complex technical tradeoffs and security risks to engineers, product teams, and leadership; experience mentoring engineers and improving design, code, and operational practices across teams.
  • Contributions to security tooling, patents, publications, open-source projects, or recognized technical leadership in security-related domains.
  • Experience identifying and mitigating security risks in production, with an understanding of prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic system risks.
  • Experience with large language models, AI systems, machine learning infrastructure, or evaluation frameworks; familiarity with AI safety, AI security research, and emerging attack and defense techniques.
  • Experience leading threat modeling, security reviews, red teaming, adversarial testing, or incident response, and translating findings into durable architectural improvements and reusable defenses.

#AISecurity #Copilot #SecurityEngineering #M365Core

Software Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Microsoft's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Microsoft's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Microsoft's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.