Principal Architect
Microsoft
IT
Redmond, WA, USA
USD 165,600-296,400 / year
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
The Authorization and Root of Trust (ART) team builds the foundational security services that underpin Microsoft’s identity and platform trust fabric. We own core capabilities including authorization policy enforcement, public key infrastructure (PKI) and certificate trust, secrets and key management, and supply chain security. Our services enable secure access control, protect signing keys and credentials, and provide end-to-end cryptographic assurance for code, services, and devices across Microsoft and its customers. By operating at the heart of zero-trust architecture, ART ensures that every request, identity, and artifact can be verified and trusted at global scale.
We are looking for a Principal Architect who drives the improvement of artificial intelligence tools across the software development lifecycle, guides to anticipate and determine customer/user requirements for complex scenarios, oversees and owns efforts for the architecture of complex products ensuring high standards for solution quality, mentors in identifying dependencies and extending code functionalities across teams. In this role, you will act as an expert in debugging and verification across products, provide oversight for code reviews ensuring they meet team standards and best practices, and automate production deployment tasks, ensuring zero-touch deployment when possible. You will also enhance security, privacy, and safety across solutions ensuring strategic compliance while championing learning and development sessions to drive awareness of design principles, and driving collaboration within partner teams ensuring effective integration and testing frameworks; as well as championing code reviews with clear security standards while minimizing risk through layered security.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
- Define end-to-end security architecture across signing services, supply chain systems, ensuring a cohesive trust model for Microsoft services and platforms.
- Drive cryptographic and trust design decisions, including certificate issuance, key protection, and Post Quantum strategies that underpin global service security.
- Lead Zero Trust architecture adoption, ensuring identity, access, and artifacts are continuously verified across service-to-service and platform interactions.
- Align cross-org technical direction, partnering with Azure, Identity, and platform teams to unblock dependencies and ensure scalable, interoperable solutions.
- Own long-term evolution of the trust ecosystem, including readiness for emerging areas like post-quantum cryptography and secure supply chain assurances.
- Guide engineering execution, setting architectural standards, reviewing designs, and driving consistency, reliability, and compliance across services.
Qualifications
Required/minimum Qualifications:
- Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- Master's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 15+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
- Experience with modern cryptography and PKI systems, including signing, trust chains, and secure key management practices
- Exposure to cloud-scale secrets management platforms (e.g., HSM-backed services, secure key storage, rotation and governance)
Software Engineering IC6 - The typical base pay range for this role across the U.S. is USD $165,600 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.