Principal Security Engineer
Microsoft (Eightfold Apply)
- Location
- United States, Washington, Redmond
- Work model
- On-Site
- Level
- Principal
- Posted
- 2h ago
About this role
Overview
The Microsoft Edge Browser Security team is responsible for protecting the security of Microsoft Edge and helping make the web safer for billions of users worldwide. Our work spans three core areas: Security Engagement, Proactive Security, and Reactive Security. In the Engagement space, we partner closely with engineering teams, architects, and product leaders to shape the security posture of Edge from the earliest stages of design. We provide deep technical guidance, influence product architecture, and drive adoption of secure-by-default principles, defense-in-depth strategies, and resilient security controls across the browser platform. As a Principal Security Engineer, you will help define security strategy, identify systemic risk, and drive security investments that have broad impact across Microsoft Edge and the Chromium ecosystem. In Proactive Security, we identify and mitigate risk before it reaches customers. This includes conducting large-scale vulnerability research, security assessments, attack surface analysis, code auditing, fuzzing, exploitability analysis, and emerging threat investigations. We continuously challenge assumptions, evaluate new technologies, and develop innovative approaches to discovering vulnerabilities in complex browser, operating system, and web platform components. Principal engineers are expected to drive novel security research initiatives, influence long-term security roadmaps, and mentor others in advanced vulnerability discovery techniques. In Reactive Security, we ensure Microsoft can rapidly detect, assess, and respond to emerging threats. We collaborate with external researchers, threat intelligence teams, MSRC, and engineering organizations to investigate security reports, prioritize mitigation efforts, and protect customers from active exploitation. Principal engineers play a key role in driving cross-organizational incident response, identifying systemic lessons from security incidents, and influencing durable security improvements that reduce future risk. Throughout all of this, you will engage with industry partners, security researchers, and the open-source community to improve the security of Chromium and related technologies, helping strengthen the broader web ecosystem. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. Starting January 26, 2026, AI Experiences employees who live within a 50- mile commute of a designated Microsoft office in the U.S. or 25-mile commute of a non-U.S., country-specific location are expected to work from the office at least four days per week. This expectation is subject to local law and may vary by jurisdiction.
Responsibilities
Evaluates the security landscape to identify emerging trends and potential exploitable areas of vulnerability for Microsoft, supported, and/or competitor products. Conducts high-level analysis of complex security threats with a forward-looking perspective. Leads cross-functional initiatives, providing strategic direction for interdisciplinary teams in the design and implementation of security solutions, including for integration in or addition to new/existing products or features. Leverages artificial intelligence (AI) workflows to understand research operations and how customers use Microsoft products and proposes solutions to deliver comprehensive protection. Develops and oversees the implementation of security analysis plans that anticipate future product developments and align with long-term business objectives. Serves as a subject matter expert and shares guidance to identify potential security issues, tools, mitigations, and processes (e.g., architecture, failure modes,