Senior Security Assurance Engineer

Overview

On Site
USD 119,800.00 - 234,700.00 per year
Full Time

Skills

FOCUS
Accountability
Regulatory Compliance
Software Engineering
Onboarding
Continuous Integration
Continuous Delivery
DevSecOps
Collaboration
Communication
Security Controls
Software Development Methodology
Security QA
Dynamic Testing
Vulnerability Scanning
Penetration Testing
Scripting
C#
Python
Microsoft Azure
Screening
PASS
Cloud Computing
Statistics
Mathematics
Computer Science
Risk Management
Software Development
Threat Modeling
Cyber Security
Artificial Intelligence
Machine Learning (ML)
Analytics
Predictive Modelling
Software Security
Integrated Circuit
Internal Communications
IC
Legal
Recruiting
Microsoft

Job Details

The Cloud & AI organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.

The Secure Production Access group is dedicated to protecting users and enterprise assets. We are looking for a Senior Security Assurance Engineer. As a collaborative group of engineers and program managers, we focus on developing effective, reliable cybersecurity products and services, often leveraging creative approaches and cutting-edge technologies.

Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.

Responsibilities:

Security Assessments:

Evaluate and certify applications/services/Infra before deployment to ensure security compliance against risks.

Monitor and analyze emerging threats and security trends to continuously update and strengthen security baselines.

Be able to establish tooling and engineering practices to detect, respond, and harden defenses.

Automation & Software Engineering:

Design and build production-grade security automation frameworks and custom tools to handle a high volume of application onboarding and security checks.

Establish new engineering solutions and practices to rapidly detect, respond, and harden defenses across the application landscape.

Integrate security assessments into CI/CD and DevSecOps pipelines to enable continuous security assurance at scale.

Collaboration & Communication:

Work with cross-functional engineering teams to maintain and evolve security controls and policies throughout SDLC

Partner with service owners, development teams, and operations to provide clear, actionable guidance.

Deliver detailed assessment reports and recommendations.

Embody our culture and values

Qualifications:

Required Qualifications
  • Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 3+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience.
  • 4+ years experience with security testing tools (static/dynamic analysis, vulnerability scanning, penetration testing).
  • 4+ years experience in common vulnerabilities, and mitigation techniques.
  • 2+ years experience in Programming/scripting skills (e.g., C#/Python) and experience building automation platforms and security tooling.
  • 2+ years experience in cloud environments (e.g. Azure)
Other Requirements

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

Microsoft Cloud Background Check:

This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications
  • Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection (enterprise experience)
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection (enterprise experience) OR equivalent experience.
  • Experience applying AI/ML techniques to security analytics, threat detection, or automation (e.g., anomaly detection, automated triage, or predictive modeling).
  • Prior experience in a large-scale application security review environments.
  • Experience in defensive and offensive security concepts.
Security Assurance IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $158,400 - $258,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

;br>
Microsoft will accept applications for the role until October 1, 2025

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form .

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.