Principal Engineering Manager, Security Engineering
Overview
We are looking for a principal people and engineering leader to build and lead security engineering for Microsoft AI.
Microsoft AI develops and trains first-party models that Microsoft publishes and uses across products including Foundry, Copilot, Microsoft 365, and MDASH. The work spans model development and serving, large-scale compute, shared infrastructure, engineering systems, identity, data, and productivity services - the whole operational system that makes large-scale training, experimentation, and deployment possible. In the last year, MAI evolved from a research lab to a full production model factory. You have built or substantially reshaped engineering-heavy security teams before and are prepared to do so again. Your job is to turn Microsoft AI security strategy into a team: hire and develop the engineers responsible for building controls, making security status legible enough to drive organization-wide prioritization decisions, and to build the enabling tools and systems that make the business run faster and more securely. You support this by running the roadmap, establishing the operating mechanisms, being the Directly Responsible Individual for some of security’s key metrics and deliverables, and remaining close enough to architecture, code, telemetry, and incidents to unblock execution directly.
Working with the Deputy CISO, Microsoft AI, you will set priorities, clarify ownership, manage performance, and establish the operating mechanisms needed for a new organization to deliver reliably. You will also join design reviews, pitch in on difficult problems, contribute code or prototypes when useful, participate in incidents, and help establish technical direction. You should know when to execute directly, when to coach, when to delegate, and when the team needs a deeper specialist.
Microsoft security teams earn trust by understanding the mission, staying close to the work, and remaining accountable for outcomes. We prefer useful progress and learning through implementation over perfect plans. We create clarity through explicit priorities, ownership, decisions, and measures. We communicate facts, analysis, uncertainty, and tradeoffs honestly.
What You Will Do
Build and Lead a Security Engineering Team
- Hire, onboard, coach, and retain a high-performing team of security engineers, architects, and operators with complementary depth across product and application security, cloud and platform security, identity, detection and response, security tooling, and other priorities as the organization evolves.
- Set clear objectives, provide actionable feedback, manage performance transparently, support career growth, and create meaningful opportunities for senior engineers to lead.
- Design the team's structure, roles, interfaces, and hiring sequence with the Deputy CISO. Identify where Microsoft AI needs dedicated ownership, where central Microsoft teams create leverage, and where a principal specialist is required.
- Create an engineering culture that values technical depth, operational ownership, clear writing, constructive disagreement, and durable systems over repeated one-off fixes.
- Raise the team's capability through technical review, mentorship, incident learning, reusable patterns, documentation, and deliberate investment in engineering quality.
Turn Strategy into an Executable Engineering Portfolio
- Translate security strategy, threat intelligence, incidents, architectural risk, partner commitments, and business priorities into a focused engineering roadmap with explicit outcomes, owners, milestones, dependencies, and measures.
- Run planning and execution mechanisms that make priorities, capacity, commitments, risks, and blocked decisions visible without turning engineers into status reporters.
- Work with program management to maintain a clear view of what the team owns, what partner teams own, and where a critical dependency lacks funded ownership. Escalate with evidence, options, and a specific decision request.
- Balance urgent risk reduction with investment in secure defaults, reference architectures, automated controls, detection, exposure analysis, identity systems, response tooling, and validation platforms.
- Use security and operational metrics to identify trends, prioritize high-impact work, expose gaps in measurement, and verify that controls and services are functioning as intended.
- Establish a sustainable operating rhythm for technical reviews, roadmap decisions, service health, incident readiness, corrective actions, hiring, and team development.
Lead Technical Work and Decision Support
- Engage deeply in architecture, threat models, design reviews, code, configuration, telemetry, and operational data. Help the team identify important attack paths, make sound tradeoffs, and choose practical implementation strategies.
- Contribute directly when it changes the outcome: build a prototype, review or write code, analyze an incident, query telemetry, test a control, automate a repeated task, or work beside an engineer through a difficult design.
- Lead ambiguous security engineering efforts from problem framing through implementation, adoption, validation, and measurement. Ensure work ends in a changed system or decision, not only a finding or recommendation.
- Help accountable owners in partner engineering teams make risk-informed decisions on proposed designs, exceptions, access changes, and launches. Offer practical alternatives and stay engaged through the outcome rather than issuing an approval or denial alone.
- Set a high bar for production engineering. Critical controls need clear ownership, safe deployment and rollback, observability, service-health expectations, incident procedures, and evidence that they reduce the intended risk.
- Use the tools, workflows, and AI-assisted security capabilities the team builds. If the team's systems are not useful or reliable enough for its own leaders to use, improve them before expecting broad adoption.
Protect Frontier-Model Development and Production
- Partner with research, model, platform, infrastructure, developer-experience, product, privacy, legal, and central security teams to protect the systems and workflows used for training, evaluation, experimentation, deployment, and model operations.
- Help create secure paths from research through repeatable production deployment, including practical controls for identities, secrets, data, workloads, administrative surfaces, software supply chain, shared infrastructure, and high-consequence operations.
- Improve security capability in partner teams through paved paths, reference implementations, reusable libraries, telemetry requirements, automated validation, and engineering support rather than review gates alone.
- Build readiness for incidents involving compromised identities, token or workload-identity misuse, data exfiltration, provider compromise, telemetry tampering, or compromise of model and training infrastructure.
- Integrate threat intelligence, hunting, adversary simulation, and incident evidence into detection priorities, engineering roadmaps, and security-control improvements.
- Turn incidents, near misses, repeated exceptions, and partner friction into engineering priorities and systemic improvements.
Operate Across Microsoft
- Build strong working relationships with Microsoft AI leaders, Microsoft CISO teams and platform owners before difficult launches, incidents, or prioritization decisions test them.
- Use Microsoft's existing capabilities when they solve the problem, improve or extend them when shared investment creates leverage, and build Microsoft AI-specific capabilities when the mission requires a different control point or operating model.
- Communicate technical risk, execution status, staffing needs, tradeoffs, and recommendations clearly. Distinguish measured facts, analysis, uncertainty, and recommendation.
- Represent the team's work with accuracy and accountability. Surface material risk and delivery problems early, and describe status plainly rather than exaggerating urgency or framing setbacks as successes.
What Makes This Role Different
- You will build more than you inherit. The team boundaries, operating mechanisms, and technical portfolio are still being shaped.
- You are a manager who ships. People leadership is the core accountability, but your impact comes through the technical delivery you and your team create.
- You turn executive strategy and deep technical expertise into team output. You complement the Deputy CISO and senior engineers by creating priorities, ownership, staffing, engineering quality, and operating discipline around their direction.
- You work on the machinery behind frontier models. The scope includes technology used to develop, train, evaluate, and operate models.
- You have unusually direct leadership access. You will work closely with Microsoft AI platform and infrastructure leadership, the Deputy CISO, and Microsoft CISO leadership.
- You enable velocity rather than manage a gate. Success means researchers and engineers have safer, repeatable ways to move quickly.
What Success Looks Like
- Microsoft AI has a focused security engineering roadmap with explicit ownership, staffing, milestones, dependencies, and measures connected to material risk.
- A high-performing team is in place with clear roles, healthy management, strong technical leadership, and a credible hiring plan for remaining gaps.
- Senior engineers have meaningful ownership and are growing; the team is not dependent on the manager for every technical decision.
- Security priorities move from ambiguous needs or findings into adopted engineering capabilities and validated production changes.
- Platform, infrastructure, research, and developer-experience teams can use secure defaults, reference patterns, telemetry, and automation produced with the security team.
- Critical security capabilities have production ownership, observability, tested response paths, and a sustainable operating model.
- The Deputy CISO can support executive operations, partnerships with other Microsoft teams and strategic influence without becoming the default people manager, project tracker, or technical bottleneck.
Required/Minimum Qualifications
- Bachelor's Degree in Computer Science, Information Technology, Mechanical Engineering, Electrical Engineering, Aerospace Engineering, Data Science, Cybersecurity, or related field AND 6+ years technical experience in software engineering, network engineering, service engineering, systems engineering, or industrial controls
- OR equivalent experience.
Preferred/Additional Qualifications
Preferred qualifications are not independent pass/fail gates; candidates who meet some but not all are encouraged to apply.
- Master's Degree in Computer Science, Information Technology, Mechanical Engineering, Electrical Engineering, Aerospace Engineering, Data Science, Cybersecurity, or related field AND 8+ years technical experience in software engineering, network engineering, service engineering, systems engineering, or industrial controls
- OR Bachelor's Degree in Computer Science, Information Technology, Mechanical Engineering, Electrical Engineering, Aerospace Engineering, Data Science, Cybersecurity, or related field AND 12+ years technical experience in software engineering, network engineering, service engineering, systems engineering, or industrial controls
- OR equivalent experience.
- 5+ years technical experience working with large-scale cloud or distributed systems.
- Experience directly managing software, infrastructure, or security engineers, including hiring, expectations, feedback, performance, and development.
- Experience defining or substantially reshaping an engineering team's structure, roles, hiring plan, or operating mechanisms.
- Recent, direct experience writing code, reviewing architecture, analyzing telemetry, debugging production systems, or supporting complex incidents.
- Experience leading security engineering work from an ambiguous problem through implementation, production operation, and measurable improvement.
- Experience setting and executing a technical roadmap across organizational boundaries.
- Experience partnering with senior engineers and leaders on prioritization, staffing, architecture, launch, and risk decisions.
- Ability to explain technical risk, uncertainty, tradeoffs, decisions, and execution status to technical and non-technical audiences.
- 3+ years of people management or informal or indirect team-leadership experience.
- 2+ years leading a security function such as security operations or threat and vulnerability management.
- Experience managing senior, staff, principal, or equivalent engineers; and managing engineering managers and technical leads.
- Experience scaling a security engineering team in a startup, research, rapidly growing, or otherwise incompletely defined environment.
- Experience securing AI or machine-learning systems, large-scale compute, cloud and platform infrastructure, identity systems, developer platforms, sensitive data systems, or high-value intellectual property.
- Experience building security platforms, automated controls, detection and response systems, exposure-management capabilities, secure frameworks, or developer-facing security tooling.
Service Engineering M5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Apply for this job
*
indicates a required field
