Skip to content

Open nowPosted 2 days ago

Security Assurance Engineer II - Marketing Security Risk & Compliance

Microsoft569 open roles

Pay
$102,100 – $202,200 a year
Where
Redmond, WA, United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Assurance Engineer II - Marketing Security Risk & ComplianceMicrosoft · Redmond, WA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Microsoft's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market. Microsoft postings stay open a median of 26 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 2 days ago

Microsoft median: 26 days open

The posting

Overview

Microsoft's Marketing Security Risk & Compliance team is looking for a Security Assurance Engineer II to execute security assurance activities across Microsoft Marketing services, applications, data platforms, and cloud environments. The Marketing Security Risk & Compliance team works with service owners and engineering teams to identify security risks, strengthen service architecture, and support compliance with Microsoft security requirements. The team is modernizing its security review process by combining architecture analysis, cloud telemetry, automated evidence, and human security expertise. In this role, you will evaluate services against defined security requirements, support threat-model reviews, investigate security signals, document findings, and help service teams understand and complete remediation. You will work with more senior Security Assurance Engineers on complex reviews while independently owning well-scoped assessments and findings. You will gain experience across cloud security, application security, threat modeling, data protection, artificial intelligence security, identity, networking, and secure engineering. Your work will directly contribute to reducing risk and improving security accountability across Microsoft Marketing

Responsibilities

Execute security assurance activities for assigned Microsoft Marketing services and engineering programs, with a focus on scalable, automated, and data-driven review practices. · Support and independently conduct security reviews, threat-modeling engagements, Secure Development Lifecycle assessments, and automated security-analysis workflows. · Review service architecture, data flows, trust boundaries, cloud resources, identities, endpoints, network configurations, privileged access, code-security signals, data-protection signals, and supporting evidence. · Build and maintain scripts, queries, APIs, and automation that collect security evidence, analyze technical signals, identify potential control gaps, and reduce manual review effort. · Develop repeatable methods for automatically assessing service configurations, cloud resources, identity and access controls, vulnerabilities, sensitive-data exposure, and other security signals. · Use Microsoft security requirements, secure engineering guidance, automated analysis, and AI-assisted techniques to identify potential threats and security gaps. · Validate automated and AI-generated findings by investigating false positives, correlating signals across data sources, confirming affected scope, and gathering supporting evidence. · Integrate security-review activities with engineering systems and workflows to automate evidence collection, finding creation, remediation tracking, notifications, and reporting where appropriate. · Document findings with clear technical descriptions, affected components, recommended remediation, ownership, and required closure evidence. · Create and maintain security findings in engineering tracking systems and monitor progress toward remediation. · Work directly with service owners and developers to clarify requirements, answer security questions, and help teams prepare effective mitigation evidence. · Review submitted remediation evidence against established acceptance criteria and escalate complex or disputed decisions to senior reviewers. · Support security assurance for tenant migrations, new technologies, artificial intelligence solutions, platform changes, and emerging engineering patterns. · Build queries, reports, and automated monitoring to identify review coverage gaps, overdue findings, recurring control weaknesses, and other program-health indicators. · Contribute reusable security checks, review templates, automation components, technical documentation, security guidance, training materials, and knowledge-management practices. · Continuously identify opportunities to replace repetitive manual activities with standardized evidence, automated controls, APIs, agentic or AI-assisted workflows, and engineering solutions. · Test and improve security-review automation by evaluating accuracy, false positives, evidence quality, coverage, reliability, and operational effectiveness. · Participate in review calibration, technical learning, and mentoring activities to deepen security, software engineering, and automation expertise. · Collaborate with engineering, compliance, privacy, data protection, and security teams to support secure and compliant service operations at scale.

Qualifications

Required Qualification

  • Bachelor's Degree in Computer Science or related technical field AND 2+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.

Preferred Qualifications

  • Master's Degree in Computer Science or related technical field AND 3+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 5+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
  • Foundational experience with security assessments, threat modeling, vulnerability management, application security, cloud security, or secure software development.
  • Understanding of common security principles involving authentication, authorization, least privilege, encryption, network security, secrets management, logging, and data protection.
  • Experience analyzing technical information and documenting findings or recommendations.
  • Experience collaborating with engineering, operations, security, or compliance stakeholders.
  • Demonstrated ability to learn new technologies and apply structured technical guidance. ·
  • Experience developing or maintaining technical solutions using one or more programming, scripting, or query languages such as C#, Python, SQL, PowerShell, or KQL, with demonstrated ability to use code and automation to analyze data, integrate systems, streamline workflows, or solve security and engineering problems.
  • Experience with Microsoft Azure or another major cloud platform.
  • Experience with security-review or threat-modeling methodologies, including data flows, trust boundaries, threat identification, and mitigation.
  • Familiarity with cloud-resource configurations, identity and access management, network controls, storage security, Key Vault technologies, application services, or data platforms.
  • Familiarity with Azure DevOps, GitHub, static-analysis platforms, cloud-security posture management, or vulnerability-tracking systems.
  • Experience supporting Secure Development Lifecycle, security compliance, audit readiness, or control-validation activities.
  • Ability to use PowerShell, Python, Kusto Query Language, or another scripting or query language to analyze security information or automate repeatable tasks.
  • Experience reviewing technical evidence and tracking findings through remediation.
  • Interest in artificial intelligence security, data protection, tenant migrations, or security automation.
  • Security certifications such as Security+, Azure Security Engineer Associate, SSCP, or comparable credentials.
  • Experience building scripts, applications, APIs, queries, or automated workflows that integrate data from multiple technical or security systems.
  • Experience using C#, Python, SQL, or comparable technologies to automate security analysis, evidence collection, configuration validation, reporting, or remediation workflows.

Software Engineering IC3 - The typical base pay range for this role across the U.S. is USD $102,100 - $202,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $133,800 - $219,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Microsoft's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Microsoft's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Microsoft's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.