Senior Software Engineer - Marketing Security Risk & Compliance
What you'll need to apply
Fields this application requires
Company-specific questions
- Is your legal name the same as your preferred name?
- Address
- Country/region of residence
- State
- Postal Code/Zip
- Ethnicity/Race
- Gender
- U.S. Armed Forces Status
- Veteran Status
- Are you currently or have you ever been a member of the military, a civilian employee, or an official of any government, whether national, state, local, or foreign?
- Have you signed a non-compete or non-disclosure statement which may become an obstacle to your acceptance at Microsoft?
- Have you ever worked with Microsoft as a full-time / part-time employee, intern, vendor, agency temporary, or business guest? If yes, please provide as much information about your former employment as you can.
- Are you currently employed by a Microsoft subsidiary (e.g., LinkedIn, GitHub, Gaming Studios, Activision, Blizzard, King)?
- As part of the online application process you were asked whether you possess certain minimum required qualifications for the role to which you are applying. By selecting yes, you agree that you answered these questions accurately. You further acknowledge that your answers may result in your application not being considered further for this role if you do not currently meet the required qualifications for the role.
- By checking this you agree to the Microsoft Data Privacy Notice (DPN) .
- By checking this, you affirm that you have familiarized yourself with the Microsoft recruiting process and agree to the candidate code of conduct .
About this role
Employer-provided description, formatted for easier reading.
Overview Microsoft’s Marketing Security Risk & Compliance team is looking for a Senior Software Engineer to design and build security automation, platforms, and AI-enabled capabilities that identify and reduce security and compliance risk across the Microsoft Marketing landscape.
Microsoft Marketing operates cloud services, data platforms, business applications, artificial intelligence solutions, and integrations that support critical marketing capabilities across the company.
The Marketing Security Risk & Compliance team partners with engineering and service teams to identify vulnerabilities and systemic security risks, strengthen service architecture, improve compliance assurance, and drive accountable remediation.
In this role, you will develop software and automation that aggregate and analyze security signals across cloud infrastructure, applications, identities, networks, data, code, and service configurations. You will build capabilities that correlate these signals to identify vulnerabilities, insecure configurations, attack paths, compliance gaps, and emerging risk patterns across Marketing services.
You will also engineer AI-enabled security capabilities that improve how security programs collect evidence, analyze risk, identify threats, prioritize findings, and validate remediation. This includes building reusable services, integrations, automated workflows, queries, and intelligent agents that allow security and compliance programs to operate at scale.
Threat modeling and security architecture review will be a core part of the role. You will perform threat modeling for Marketing services and high-impact programs, using hands-on analysis to understand architectures, data flows, trust boundaries, identities, attack surfaces, privileged access, and security controls. Insights from these engagements will directly inform the automation and engineering capabilities you build.
This role combines software engineering, security engineering, cloud security, and security assurance. You will help move Marketing from primarily point-in-time security assessments toward a continuous, data-driven security assurance model where automation and AI identify risk across the landscape and engineering judgment validates and prioritizes the risks that matter.
Responsibilities
- Design, develop, test, deploy, and operate software services, automation, tools, and integrations supporting Marketing security and compliance programs.
- • Build capabilities that continuously identify vulnerabilities, insecure configurations, control gaps, and security risks across Microsoft Marketing services.
- • Develop automation to collect, normalize, correlate, and analyze security signals from cloud resources, applications, identities, networks, data platforms, code-security systems, service metadata, and security tooling.
- • Build scalable security analytics and risk-detection capabilities that identify attack paths, recurring vulnerabilities, systemic weaknesses, and emerging security patterns across the Marketing landscape.
- • Develop AI-enabled security automation and agents that accelerate evidence collection, threat identification, risk analysis, finding generation, remediation guidance, and security-program workflows.
- • Engineer reusable services, APIs, queries, pipelines, integrations, and workflow automation that enable security and compliance programs to operate at scale.
- • Build automation supporting security compliance and continuous assurance programs, including control validation, evidence collection, gap identification, exception management, and remediation tracking.
- • Perform end-to-end threat modeling and technical security reviews for Marketing services, platforms, AI solutions, tenant migrations, and other high-impact initiatives.
- • Analyze business context, service architecture, data flows, trust boundaries, service dependencies, identities, endpoints, privileged access, network exposure, logging, data classifications, and security controls.
- • Apply Microsoft security requirements and Secure Development Lifecycle practices to identify design weaknesses, implementation vulnerabilities, missing controls, and material security risks.
- • Use findings from threat models, incidents, security assessments, and security telemetry to identify opportunities for new automated controls and detection capabilities.
- • Validate automated and AI-generated security findings, reduce false positives, improve detection quality, and ensure automation focuses engineering teams on material risk.
- • Integrate security findings and remediation workflows with appropriate engineering tracking and security systems.
- • Develop mechanisms to measure security posture, compliance assurance, remediation progress, and recurring risk patterns across Marketing services.
- • Partner with service engineers, architects, security teams, privacy teams, Responsible AI practitioners, and program owners to design practical security solutions.
- • Provide engineering support for tenant migrations, platform modernization, AI adoption, and other high-impact programs where security capabilities must be integrated into the engineering lifecycle.
- • Develop reusable security patterns, libraries, templates, and engineering guidance that allow service teams to implement security requirements consistently.
- • Contribute to architecture and design decisions for security platforms, automation frameworks, data pipelines, and AI-enabled security capabilities.
- • Mentor engineers and security practitioners on secure engineering, threat modeling, security automation, and the effective use of security telemetry.
- • Communicate systemic security risks, engineering priorities, and remediation strategies clearly to service teams, program owners, and leadership.
- • Experience conducting or contributing to threat modeling, security architecture reviews, application security assessments, or Secure Development Lifecycle activities.
Required Qualifications
Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Preferred Qualifications
- Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
- Professional software development experience using one or more general-purpose programming languages.
- Experience designing, developing, testing, deploying, and operating production software, automation, services, or engineering tools.
- Experience developing solutions using APIs, data pipelines, cloud services, automation frameworks, or distributed systems.
- Experience with cybersecurity principles and identifying vulnerabilities, design weaknesses, insecure configurations, or security-control gaps.
- Experience building security platforms, developer-security tooling, compliance automation, security analytics, vulnerability-management systems, or continuous-assurance capabilities.
- Experience with Microsoft Azure or another major cloud platform and cloud-native software development.
- Experience developing security automation using cloud-resource APIs, security telemetry, code-security signals, identity information, asset inventories, or configuration data.
- Experience applying AI, machine learning, large language models, agents, or other AI technologies to security engineering, automation, or operational workflows.
- Experience designing systems that correlate multiple security signals to identify vulnerabilities, attack paths, control gaps, or systemic risk.
- Experience with th