Microsoft Corp logo

Senior Security Assurance Engineer - Marketing Security Risk & Compliance

Microsoft Corp
  • Redmond, WA
  • $119,800–$234,700 Per Year
2 days ago

Job Description

Overview

Microsoft's Marketing Security Risk & Compliance team is looking for a Senior Security Assurance Engineer to lead complex security reviews and threat modeling for Microsoft Marketing services, platforms, and data. Microsoft Marketing operates a diverse technology estate that includes cloud services, data platforms, business applications, artificial intelligence solutions, and complex integrations across Microsoft. The team partners with engineering and business organizations to identify and address security risk through security reviews, threat modeling, Secure Development Lifecycle practices, data-driven analysis, and continuous remediation. In this role, you will provide senior technical security assurance across a portfolio of Marketing services. You will lead security reviews for complex services and high-impact initiatives, evaluate technical architectures and security evidence, identify material security risks, and partner with engineering teams to drive findings through remediation and closure. You will help modernize security assurance from primarily manual, point-in-time reviews toward a scalable, intelligence-driven model that combines current service data, cloud telemetry, automated evidence collection, AI-assisted analysis, and expert engineering judgment. You will also identify recurring risks and opportunities to improve review standards, automation, and secure engineering practices across Marketing. This role requires strong technical judgment, the ability to operate independently in complex environments, and the ability to translate security findings into actionable engineering work.

Responsibilities

  • Lead end-to-end security reviews and threat-modeling engagements for complex Microsoft Marketing services, applications, platforms, and data environments. - Analyze architecture, data flows, trust boundaries, identities, endpoints, privileged access, network exposure, dependencies, logging, cloud configurations, and security controls. - Apply Microsoft security requirements and Secure Development Lifecycle practices to identify design weaknesses, implementation risks, control gaps, and missing evidence. - Lead security assurance for high-impact initiatives, including tenant migrations, new platforms, AI solutions, sensitive-data environments, and major architectural changes. - Evaluate security evidence and make risk-based recommendations on technical issues, remediation, and security requirements. - Facilitate technical security discussions with service owners, developers, architects, security and privacy teams, Responsible AI practitioners, and technical partners. - Validate automated and AI-assisted findings, distinguish material risk from false positives, and focus engineering teams on risks requiring action. - Document validated findings with clear severity, impact, remediation requirements, ownership, and closure evidence. - Translate security findings into clearly owned engineering work and track remediation through closure. - Review mitigation evidence and technical justifications, validate remediation, and escalate when evidence does not demonstrate sufficient risk reduction. - Use cloud telemetry, attack-path analysis, automated evidence collection, and AI-assisted capabilities to improve review depth, consistency, and efficiency. - Build and operationalize automation that accelerates evidence collection, security analysis, risk identification, reporting, and remediation workflows. - Identify recurring control failures, architectural weaknesses, and systemic security risks across services. - Translate recurring findings into reusable guidance, secure design patterns, improved review practices, and - Partner with service owners and engineering teams to apply Secure by Design, Secure by Default, and Secure Operations principles throughout the service lifecycle. - Contribute to security review standards, technical playbooks, templates, decision frameworks, training, and reusable guidance. - Partner with software engineers and security platform teams to develop and improve automated security review capabilities and workflows. - Provide technical guidance and mentoring to Security Assurance Engineers, improving review consistency and technical quality. - Communicate material risks, technical tradeoffs, remediation priorities, and escalation needs clearly

Qualifications

Required Qualifications

  • Bachelors Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.

Preferred Qualifications

  • Masters Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelors Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
  • Experience conducting or leading security architecture reviews, threat modeling, application security assessments, cloud security assessments, or Secure Development Lifecycle activities.
  • Experience assessing cloud architectures and security controls across identity, networking, data protection, applications, infrastructure, secrets management, logging, monitoring, and DevOps.
  • Experience identifying security vulnerabilities, architectural weaknesses, control gaps, and other material technical risks.
  • Experience making risk-based technical recommendations in complex or ambiguous engineering environments.
  • Experience working with engineering teams to translate security findings into actionable remediation and validating evidence through closure.
  • Experience leading technical security engagements involving multiple engineering or business stakeholders.
  • Demonstrated ability to communicate complex security risks, architectural concerns, and technical tradeoffs to engineering teams and other stakeholders.
  • Experience leading complex security reviews or threat-modeling engagements across cloud services, applications, data platforms, or enterprise systems.
  • Strong understanding of threat-modeling methodologies, secure architecture principles, attack paths, data flows, trust boundaries, and adversarial analysis.
  • Experience securing Microsoft Azure services, hybrid environments, data platforms, Power Platform, Dynamics 365, or artificial intelligence systems.
  • Experience with security and engineering platforms such as Azure DevOps, Service Tree, Microsoft Purview, Defender for Cloud, CodeQL, or similar systems.
  • Experience using automation, data analysis, or AI-assisted capabilities to improve security assessment, evidence collection, vulnerability identification, or remediation workflows.
  • Experience supporting cloud or tenant migrations, platform modernization, service transfers, or other large-scale technical transitions.
  • Experience validating automated security findings and differentiating material security risk from false positives.
  • Experience developing or contributing to reusable security patterns, control baselines, automated guardrails, assessment queries, scripts, dashboards, or self-service security capabilities.
  • Experience identifying recurring security weaknesses and translating individual findings into broader engineering or process improvements.
  • Experience with privacy, regulatory, or compliance requirements affecting enterprise cloud services and data.
  • Security certifications such as CISSP, CSSLP, CCSP, GIAC, or comparable credentials.

Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Numbers & Facts

LocationRedmond, WA
IndustryComputer Software
Salary$119,800–$234,700 Per Year
Company Size10,000 employees or more
Year Founded1975
Websitehttp://www.microsoft.com

About Company

DO WHAT YOU LOVE
Make your mark on the world’s most used technologies. Develop the next hit mobile application. Pioneer a startup that could be the next big thing. At Microsoft, you choose your path.

Headquartered in Redmond, Washington, Microsoft is a top innovator in both the consumer and enterprise technology industry. Just a few of the many things our products do are unleash creativity, connect businesses, and make learning more fun. But our continued success is based on one thing: our employees. We hire amazing, talented people and give them the opportunities—and the tools—to succeed.

WHY MICROSOFT?
As a Microsoft employee, you’re surrounded by a diverse group of the smartest people in your field. This fosters new ideas, better business results, and creates a dynamic work environment. In the office, you’re constantly challenged and supported by your colleagues. Every day holds something new and exciting.

We also offer unparalleled depth and breadth of career opportunities. As an industry leader in multiple fields, working for Microsoft means being able to do whatever you feel passionate about—and being able to make an impact in that field. From day one, we give our employees significant responsibility. This means that you’ll know that you directly contributed to something that has a positive impact on people worldwide. Whether you choose to work in management, dive deep into the newest technology, or explore multiple professions, you’ll find everything you need at Microsoft to drive your career—and to make a difference.

WE GET IT – YOU’RE MORE THAN YOUR JOB
Everyone works differently and is motivated by different things. We also understand that there’s more to you than your job. That’s why we offer competitive pay and a wide assortment of benefits-- to help you make the most of life at work and away from it.

GET THE BALL ROLLING

Skills

  • Analysis Skillsunmatched
  • Applications Securityunmatched
  • Architectural Analysisunmatched
  • Architectural Servicesunmatched
  • Artificial Intelligence (AI)unmatched
  • Automationunmatched
  • Business Intelligence Softwareunmatched
  • C Programming Languageunmatched
  • C++ Programming Languageunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Change Controlunmatched
  • Cloud Applicationsunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Data Analysisunmatched
  • Design Patterns Programming Methodologiesunmatched
  • DevOpsunmatched
  • Engineeringunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • Information/Data Security (InfoSec)unmatched
  • Javaunmatched
  • JavaScriptunmatched
  • Leadershipunmatched
  • Marketingunmatched
  • Marketing Softwareunmatched
  • Mentoringunmatched
  • Microsoft C# (C Sharp)unmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Model Reviewunmatched
  • Network Securityunmatched
  • Operations Security (OPSEC)unmatched
  • Privacy Controlsunmatched
  • Privacy Regulationsunmatched
  • Process Improvementunmatched
  • Product Lifecycleunmatched
  • Protective Servicesunmatched
  • Python Programming/Scripting Languageunmatched
  • Query Analysisunmatched
  • Regulatory Complianceunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Infrastructureunmatched
  • Software Engineeringunmatched
  • Team Playerunmatched
  • Technical Analysisunmatched
  • Technical Leadershipunmatched
  • Telemetryunmatched
  • Threat Modelingunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder