Security Assurance Engineer II - Marketing Security Risk & Compliance
What you'll need to apply
Fields this application requires
Company-specific questions
- Is your legal name the same as your preferred name?
- Address
- Country/region of residence
- State
- Postal Code/Zip
- Ethnicity/Race
- Gender
- U.S. Armed Forces Status
- Veteran Status
- Are you currently or have you ever been a member of the military, a civilian employee, or an official of any government, whether national, state, local, or foreign?
- Have you signed a non-compete or non-disclosure statement which may become an obstacle to your acceptance at Microsoft?
- Have you ever worked with Microsoft as a full-time / part-time employee, intern, vendor, agency temporary, or business guest? If yes, please provide as much information about your former employment as you can.
- Are you currently employed by a Microsoft subsidiary (e.g., LinkedIn, GitHub, Gaming Studios, Activision, Blizzard, King)?
- As part of the online application process you were asked whether you possess certain minimum required qualifications for the role to which you are applying. By selecting yes, you agree that you answered these questions accurately. You further acknowledge that your answers may result in your application not being considered further for this role if you do not currently meet the required qualifications for the role.
- By checking this you agree to the Microsoft Data Privacy Notice (DPN) .
- By checking this, you affirm that you have familiarized yourself with the Microsoft recruiting process and agree to the candidate code of conduct .
About this role
Employer-provided description, formatted for easier reading.
Overview Microsoft's Marketing Security Risk & Compliance team is looking for a Security Assurance Engineer II to execute security assurance activities across Microsoft Marketing services, applications, data platforms, and cloud environments.
The Marketing Security Risk & Compliance team works with service owners and engineering teams to identify security risks, strengthen service architecture, and support compliance with Microsoft security requirements. The team is modernizing its security review process by combining architecture analysis, cloud telemetry, automated evidence, and human security expertise.
In this role, you will evaluate services against defined security requirements, support threat-model reviews, investigate security signals, document findings, and help service teams understand and complete remediation. You will work with more senior Security Assurance Engineers on complex reviews while independently owning well-scoped assessments and findings.
You will gain experience across cloud security, application security, threat modeling, data protection, artificial intelligence security, identity, networking, and secure engineering. Your work will directly contribute to reducing risk and improving security accountability across Microsoft Marketing
Responsibilities Execute security assurance activities for assigned Microsoft Marketing services and engineering programs, with a focus on scalable, automated, and data-driven review practices. · Support and independently conduct security reviews, threat-modeling engagements, Secure Development Lifecycle assessments, and automated security-analysis workflows.
· Review service architecture, data flows, trust boundaries, cloud resources, identities, endpoints, network configurations, privileged access, code-security signals, data-protection signals, and supporting evidence. · Build and maintain scripts, queries, APIs, and automation that collect security evidence, analyze technical signals, identify potential control gaps, and reduce manual review effort.
· Develop repeatable methods for automatically assessing service configurations, cloud resources, identity and access controls, vulnerabilities, sensitive-data exposure, and other security signals. · Use Microsoft security requirements, secure engineering guidance, automated analysis, and AI-assisted techniques to identify potential threats and security gaps.
· Validate automated and AI-generated findings by investigating false positives, correlating signals across data sources, confirming affected scope, and gathering supporting evidence. · Integrate security-review activities with engineering systems and workflows to automate evidence collection, finding creation, remediation tracking, notifications, and reporting where appropriate.
· Document findings with clear technical descriptions, affected components, recommended remediation, ownership, and required closure evidence. · Create and maintain security findings in engineering tracking systems and monitor progress toward remediation. · Work directly with service owners and developers to clarify requirements, answer security questions, and help teams prepare effective mitigation evidence.
· Review submitted remediation evidence against established acceptance criteria and escalate complex or disputed decisions to senior reviewers. · Support security assurance for tenant migrations, new technologies, artificial intelligence solutions, platform changes, and emerging engineering patterns.
· Build queries, reports, and automated monitoring to identify review coverage gaps, overdue findings, recurring control weaknesses, and other program-health indicators. · Contribute reusable security checks, review templates, automation components, technical documentation, security guidance, training materials, and knowledge-management practices.
· Continuously identify opportunities to replace repetitive manual activities with standardized evidence, automated controls, APIs, agentic or AI-assisted workflows, and engineering solutions. · Test and improve security-review automation by evaluating accuracy, false positives, evidence quality, coverage, reliability, and operational effectiveness.
· Participate in review calibration, technical learning, and mentoring activities to deepen security, software engineering, and automation expertise. · Collaborate with engineering, compliance, privacy, data protection, and security teams to support secure and compliant service operations at scale.
Qualifications
Required Qualification
- Bachelor's Degree in Computer Science or related technical field AND 2+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Preferred Qualifications
- Master's Degree in Computer Science or related technical field AND 3+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 5+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
- Foundational experience with security assessments, threat modeling, vulnerability management, application security, cloud security, or secure software development.
- Understanding of common security principles involving authentication, authorization, least privilege, encryption, network security, secrets management, logging, and data protection.
- Experience analyzing technical information and documenting findings or recommendations.
- Experience collaborating with engineering, operations, security, or compliance stakeholders.
- Demonstrated ability to learn new technologies and apply structured technical guidance. ·
- Experience developing or maintaining technical solutions using one or more programming, scripting, or query languages such as C#, Python, SQL, PowerShell, or KQL, with demonstrated ability to use code and automation to analyze data, integrate systems, streamline workflows, or solve security and engineering problems.
- Experience with Microsoft Azure or another major cloud platform.
- Experience with security-review or threat-modeling methodologies, including data flows, trust boundaries, threat identification, and mitigation.
- Familiarity with cloud-resource configurations, identity and access management, network controls, storage security, Key Vault technologies, application services, or data platforms.
- Familiarity with Azure DevOps, GitHub, static-analysis platforms, cloud-security posture management, or vulnerability-tracking systems.
- Experience supporting Secure Development Lifecycle, security compliance, audit readiness, or control-validation activities.
- Ability to use PowerShell, Python, Kusto Query Language, or another scripting or query language to analyze security information or automate repeatable tasks.
- Experience reviewing technical evidence and tracking findings through remediation.
- Interest in artificial intelligence security, data protection, tenant migrations, or security automation.
- Security certifications such as Security+, Azure Security Engineer Associate, SSCP, or comparable credentials.
- Experience building scripts, applications, APIs, queries, or automated workflows that integrate data from multiple technical or security systems.
- Experience using C#, Python, SQL, or comparable technologies to automate security analysis, evidence collection, configuration validation, reporting, or remediation workflows.
Software Engineering IC3 - The typical base pay range for this role across the U. S. is USD $102,100 - $202,200 per year.
There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $133,800 - $219,200 per year