Back to jobs

Principal Software Engineer

Microsoft · Redmond, WA, US

Spotted 4d ago

Job details

Level
Staff / principal
Experience
6+ years
Education
Bachelor's degree
Posted
Oct 6, 2026
Last confirmed open
Oct 11, 2026

What you'll need to apply

Fields this application requires

ResumeNameEmailPhoneLocationWork authorization answerVisa sponsorship answer

Company-specific questions

  • Is your legal name the same as your preferred name?
  • Address
  • Country/region of residence
  • State
  • Postal Code/Zip
  • Ethnicity/Race
  • Gender
  • U.S. Armed Forces Status
  • Veteran Status
  • Are you currently or have you ever been a member of the military, a civilian employee, or an official of any government, whether national, state, local, or foreign?
  • Have you signed a non-compete or non-disclosure statement which may become an obstacle to your acceptance at Microsoft?
  • Have you ever worked with Microsoft as a full-time / part-time employee, intern, vendor, agency temporary, or business guest? If yes, please provide as much information about your former employment as you can.
  • Are you currently employed by a Microsoft subsidiary (e.g., LinkedIn, GitHub, Gaming Studios, Activision, Blizzard, King)?
  • As part of the online application process you were asked whether you possess certain minimum required qualifications for the role to which you are applying. By selecting yes, you agree that you answered these questions accurately. You further acknowledge that your answers may result in your application not being considered further for this role if you do not currently meet the required qualifications for the role.
  • By checking this you agree to the Microsoft Data Privacy Notice (DPN) .
  • By checking this, you affirm that you have familiarized yourself with the Microsoft recruiting process and agree to the candidate code of conduct .
Job description

About this role

Overview Secure the next generation of Copilot experiences

The Copilot Security Engineering team sits at the core of Microsoft’s mission to deliver secure, trusted, and human-centered AI experiences across Microsoft’s Copilot offerings. We build the systems that detect, evaluate, and defend against emerging AI threats, including prompt injection, memory poisoning, data exfiltration, adversarial inputs, and abuse of agentic workflows.

Our goal is to establish industry-leading security protections that enable customers to confidently adopt AI at scale.

Our team combines security engineering, AI systems expertise, and threat research to identify emerging risks, develop novel defenses, and continuously measure their effectiveness in production. We work closely with product teams, Microsoft Research, and platform organizations to ensure security is built into every layer of the Copilot ecosystem.

We are looking for a Principal Software Engineer to set technical direction and own the architecture of AI threat detection and defense capabilities spanning multiple Copilot experiences. You will turn ambiguous, evolving threats into an actionable engineering strategy and reusable platform protections, aligning partners on priorities, interfaces, and measurable security outcomes.

This is a hands-on individual contributor role at the intersection of security, AI, and large-scale distributed systems. You will design and write production code, lead complex work from threat discovery through deployment and operation, and remain accountable for the effectiveness and reliability of the defenses you deliver.

Your impact will extend through cross-team architectural decisions, partner influence, and mentorship, rather than people management.

This position is based in Redmond, Washington and requires the employee be in the office a minimum of 3 days per week.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Define and drive a multi-team technical strategy for Copilot security. Translate emerging threats and product needs into prioritized engineering investments, architectural decisions, and an executable roadmap with clear ownership and success measures.
  • Own the end-to-end architecture and hands-on implementation of detection and defense systems for prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and abuse of agentic workflows. Resolve ambiguous problems across AI workflows, tools, orchestration layers, trust boundaries, and platform integrations.
  • Build reusable security services, classifiers, evaluation frameworks, telemetry pipelines, and risk assessment capabilities. Establish extensible interfaces and integration patterns that enable multiple Copilot teams to adopt durable protections instead of duplicating point solutions.
  • Define security effectiveness measures and release criteria with partners, including attack coverage, detection quality, false-positive impact, and mitigation effectiveness. Use adversarial evaluations and production telemetry to validate improvements, detect regressions, and balance protection with latency, reliability, cost, and customer experience.
  • Lead threat modeling and architectural security reviews across team boundaries. Partner with security researchers, Microsoft Research, product teams, and platform organizations to investigate emerging attack techniques, validate defenses, and turn research findings into deployable engineering capabilities.
  • Remain accountable for production readiness and ongoing operation of security capabilities. Establish observability, safe rollout and rollback approaches, and operational practices; participate in on-call rotations and lead cross-team investigations during complex security events.
  • Drive root cause analysis and durable remediation after security incidents. Address systemic failure modes through shared platform defenses, regression coverage, and improvements to detection, response, and recovery.
  • Influence architectural choices and engineering investments without direct authority. Build agreement on technical tradeoffs, dependencies, and adoption plans, and communicate risk, progress, and security outcomes clearly to engineers, product partners, and leadership.
  • Raise engineering quality through design and code reviews, technical mentorship, and knowledge sharing. Help engineers reason about AI security and distributed systems, grow technical ownership, and apply sound engineering practices while continuing to contribute directly to critical implementations.

Required Qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
  • OR equivalent experience.

Other Requirements

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings:

  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications

  • Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
  • OR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
  • OR equivalent experience.
  • 5+ years of experience designing, building, and operating production software systems.
  • Demonstrated ownership of ambiguous technical problems from strategy and architectural design through implementation, production rollout, and sustained operation; experience aligning multiple teams on shared platform capabilities and driving adoption without direct authority.
  • Experience identifying and mitigating security risks in production, with an understanding of prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic system risks.
  • Experience building security detection, reputation, anomaly detection, threat intelligence, abuse prevention, or Trust & Safety systems, and using evaluation data and production telemetry to demonstrate measurable improvements in protection and operational quality.
  • Experience with large language models, AI systems, machine learning infrastructure, or evaluation frameworks; familiarity with AI safety, AI security research, and emerging attack and defense techniques.
  • Experience leading threat modeling, security reviews, red teaming, adversarial testing, or incident response, and translating findings into durable architectural improvements and reusable defenses.
  • Ability to communicate complex technical tradeoffs and security risks to engineers, product teams, and leadership; experience mentoring engineers and improving design, code, and operational practices across teams.
  • Contributions to security tooling, patents, publications, open-source projects, or recognized technical leadership in security-related domains.
  • Experience identifying and mitigating security risks in production, with an understanding of prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic system risks.
  • Experience with large language models, AI systems, machine learning infrastructure, or evaluation fram
Interested in this role?Continue on Microsoft's careers page.
Apply on Microsoft