Senior Security Assurance Engineer - Marketing Security Risk & Compliance
What you'll need to apply
Fields this application requires
Company-specific questions
- Is your legal name the same as your preferred name?
- Address
- Country/region of residence
- State
- Postal Code/Zip
- Ethnicity/Race
- Gender
- U.S. Armed Forces Status
- Veteran Status
- Are you currently or have you ever been a member of the military, a civilian employee, or an official of any government, whether national, state, local, or foreign?
- Have you signed a non-compete or non-disclosure statement which may become an obstacle to your acceptance at Microsoft?
- Have you ever worked with Microsoft as a full-time / part-time employee, intern, vendor, agency temporary, or business guest? If yes, please provide as much information about your former employment as you can.
- Are you currently employed by a Microsoft subsidiary (e.g., LinkedIn, GitHub, Gaming Studios, Activision, Blizzard, King)?
- As part of the online application process you were asked whether you possess certain minimum required qualifications for the role to which you are applying. By selecting yes, you agree that you answered these questions accurately. You further acknowledge that your answers may result in your application not being considered further for this role if you do not currently meet the required qualifications for the role.
- By checking this you agree to the Microsoft Data Privacy Notice (DPN) .
- By checking this, you affirm that you have familiarized yourself with the Microsoft recruiting process and agree to the candidate code of conduct .
About this role
Employer-provided description, formatted for easier reading.
Overview
Microsoft’s Marketing Security Risk & Compliance team is looking for a Senior Security Assurance Engineer to lead complex security reviews and threat modeling for Microsoft Marketing services, platforms, and data. Microsoft Marketing operates a diverse technology estate that includes cloud services, data platforms, business applications, artificial intelligence solutions, and complex integrations across Microsoft.
The team partners with engineering and business organizations to identify and address security risk through security reviews, threat modeling, Secure Development Lifecycle practices, data-driven analysis, and continuous remediation. In this role, you will provide senior technical security assurance across a portfolio of Marketing services.
You will lead security reviews for complex services and high-impact initiatives, evaluate technical architectures and security evidence, identify material security risks, and partner with engineering teams to drive findings through remediation and closure.
You will help modernize security assurance from primarily manual, point-in-time reviews toward a scalable, intelligence-driven model that combines current service data, cloud telemetry, automated evidence collection, AI-assisted analysis, and expert engineering judgment. You will also identify recurring risks and opportunities to improve review standards, automation, and secure engineering practices across Marketing.
This role requires strong technical judgment, the ability to operate independently in complex environments, and the ability to translate security findings into actionable engineering work.
Responsibilities
- Lead end-to-end security reviews and threat-modeling engagements for complex Microsoft Marketing services, applications, platforms, and data environments. - Analyze architecture, data flows, trust boundaries, identities, endpoints, privileged access, network exposure, dependencies, logging, cloud configurations, and security controls. - Apply Microsoft security requirements and Secure Development Lifecycle practices to identify design weaknesses, implementation risks, control gaps, and missing evidence. - Lead security assurance for high-impact initiatives, including tenant migrations, new platforms, AI solutions, sensitive-data environments, and major architectural changes. - Evaluate security evidence and make risk-based recommendations on technical issues, remediation, and security requirements. - Facilitate technical security discussions with service owners, developers, architects, security and privacy teams, Responsible AI practitioners, and technical partners. - Validate automated and AI-assisted findings, distinguish material risk from false positives, and focus engineering teams on risks requiring action. - Document validated findings with clear severity, impact, remediation requirements, ownership, and closure evidence. - Translate security findings into clearly owned engineering work and track remediation through closure. - Review mitigation evidence and technical justifications, validate remediation, and escalate when evidence does not demonstrate sufficient risk reduction. - Use cloud telemetry, attack-path analysis, automated evidence collection, and AI-assisted capabilities to improve review depth, consistency, and efficiency. - Build and operationalize automation that accelerates evidence collection, security analysis, risk identification, reporting, and remediation workflows. - Identify recurring control failures, architectural weaknesses, and systemic security risks across services. - Translate recurring findings into reusable guidance, secure design patterns, improved review practices, and - Partner with service owners and engineering teams to apply Secure by Design, Secure by Default, and Secure Operations principles throughout the service lifecycle. - Contribute to security review standards, technical playbooks, templates, decision frameworks, training, and reusable guidance. - Partner with software engineers and security platform teams to develop and improve automated security review capabilities and workflows. - Provide technical guidance and mentoring to Security Assurance Engineers, improving review consistency and technical quality. - Communicate material risks, technical tradeoffs, remediation priorities, and escalation needs clearly
Qualifications
Required Qualifications
- Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Preferred Qualifications
- Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
- Experience conducting or leading security architecture reviews, threat modeling, application security assessments, cloud security assessments, or Secure Development Lifecycle activities.
- Experience assessing cloud architectures and security controls across identity, networking, data protection, applications, infrastructure, secrets management, logging, monitoring, and DevOps.
- Experience identifying security vulnerabilities, architectural weaknesses, control gaps, and other material technical risks.
- Experience making risk-based technical recommendations in complex or ambiguous engineering environments.
- Experience working with engineering teams to translate security findings into actionable remediation and validating evidence through closure.
- Experience leading technical security engagements involving multiple engineering or business stakeholders.
- Demonstrated ability to communicate complex security risks, architectural concerns, and technical tradeoffs to engineering teams and other stakeholders.
- Experience leading complex security reviews or threat-modeling engagements across cloud services, applications, data platforms, or enterprise systems.
- Strong understanding of threat-modeling methodologies, secure architecture principles, attack paths, data flows, trust boundaries, and adversarial analysis.
- Experience securing Microsoft Azure services, hybrid environments, data platforms, Power Platform, Dynamics 365, or artificial intelligence systems.
- Experience with security and engineering platforms such as Azure DevOps, Service Tree, Microsoft Purview, Defender for Cloud, CodeQL, or similar systems.
- Experience using automation, data analysis, or AI-assisted capabilities to improve security assessment, evidence collection, vulnerability identification, or remediation workflows.
- Experience supporting cloud or tenant migrations, platform modernization, service transfers, or other large-scale technical transitions.
- Experience validating automated security findings and differentiating material security risk from false positives.
- Experience developing or contributing to reusable security patterns, control baselines, automated guardrails, assessment queries, scripts, dashboards, or self-service security capabilities.
- Experience identifying recurring security weaknesses and translating individual findings into broader engineering or process improvements.
- Experience with privacy, regulatory, or compliance requirements affecting enterprise cloud services and data.
- Security certifications such as CISSP, CSSLP, CCSP, GIAC, or comparable credentials.
Software Engineering IC4 - The typical base pay range for this role across the U. S. is USD $119,800 - $234,700 per year.
There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay