Principal Security Engineer

Microsoft
Microsoft

Redmond, WA, USA

USD 142,800-274,800 / year

Posted on Jul 29, 2026
Overview

The Microsoft Edge Browser Security team is responsible for protecting the security of Microsoft Edge and helping make the web safer for billions of users worldwide. Our work spans three core areas: Security Engagement, Proactive Security, and Reactive Security.

In the Engagement space, we partner closely with engineering teams, architects, and product leaders to shape the security posture of Edge from the earliest stages of design. We provide deep technical guidance, influence product architecture, and drive adoption of secure-by-default principles, defense-in-depth strategies, and resilient security controls across the browser platform. As a Principal Security Engineer, you will help define security strategy, identify systemic risk, and drive security investments that have broad impact across Microsoft Edge and the Chromium ecosystem.

In Proactive Security, we identify and mitigate risk before it reaches customers. This includes conducting large-scale vulnerability research, security assessments, attack surface analysis, code auditing, fuzzing, exploitability analysis, and emerging threat investigations. We continuously challenge assumptions, evaluate new technologies, and develop innovative approaches to discovering vulnerabilities in complex browser, operating system, and web platform components. Principal engineers are expected to drive novel security research initiatives, influence long-term security roadmaps, and mentor others in advanced vulnerability discovery techniques.

In Reactive Security, we ensure Microsoft can rapidly detect, assess, and respond to emerging threats. We collaborate with external researchers, threat intelligence teams, MSRC, and engineering organizations to investigate security reports, prioritize mitigation efforts, and protect customers from active exploitation. Principal engineers play a key role in driving cross-organizational incident response, identifying systemic lessons from security incidents, and influencing durable security improvements that reduce future risk.

Throughout all of this, you will engage with industry partners, security researchers, and the open-source community to improve the security of Chromium and related technologies, helping strengthen the broader web ecosystem.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Starting January 26, 2026, AI Experiences employees who live within a 50- mile commute of a designated Microsoft office in the U.S. or 25-mile commute of a non-U.S., country-specific location are expected to work from the office at least four days per week. This expectation is subject to local law and may vary by jurisdiction.



Responsibilities
  • Evaluates the security landscape to identify emerging trends and potential exploitable areas of vulnerability for Microsoft, supported, and/or competitor products. Conducts high-level analysis of complex security threats with a forward-looking perspective. Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions, including for integration in or addition to new/existing products or features. Leverages artificial intelligence (AI) workflows to understand research operations and how customers use Microsoft products and proposes solutions to deliver comprehensive protection. Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives.
  • Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes (e.g., architecture, failure modes, attack chain, threat modeling, vulnerabilities). Maintains and shares deep knowledge of industry trends, technologies, tools, securities, and advances. Proactively contributes to internal and external community through publications, white papers, seminars, or conferences, shaping understanding of threat protection in real-world impact and storytelling. Establishes deployment and security configuration standards and best practices to ensure technologies are deployed in a secure fashion across the organization.
  • Directs organization-wide security reviews, including architectural and design reviews, and synthesizes findings in analysis reports. Leads the implementation of best practices for security architecture, design, and development across product and feature areas and teams. Proactively evaluates and prioritizes security risks and orchestrates cross-functional partnerships to remove blockers and mitigate risks. Oversees the monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance issues, escalating as needed.
  • Solves classes of issues in technical implementation and automation of solutions related to specific kinds of security issues (e.g., security posture, signature-based detection, malware, threat analysis, reverse engineering, attack disruption, anomaly detection). Leads multidisciplinary teams to innovate and implement improvements in solutions and methods.


Qualifications

Required Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR equivalent experience.

Preferred Qualifications:

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection
    • OR equivalent experience.
  • Significant experience in areas such as:
    • Vulnerability research and exploit analysis.
    • Code auditing and secure architecture review.
    • AI assisted Vulnerability Research.
    • Fuzzer development and crash triage.
    • Browser, application, operating system, or cloud security.
    • Threat modeling and attack surface analysis.
    • Security automation and AI-assisted security research.
    • Software engineering and computer science fundamentals.


#MicrosoftAI #EdgeVR #EdgeSecurity



Security Research IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.




Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.