About the job
The Copilot Security Engineering team is at the core of Microsoft’s mission to deliver secured , trusted, human-centered AI experiences across the company’s Copilot offerings. We design, build, and operate systems that help identify, evaluate, and mitigate emerging AI security threats, covering adversarial testing frameworks, telemetry pipelines, evaluation systems, and production security defenses. Our goal is to be the industry leader in delivering best-in-class AI security protections for our enterprise customers.
We are looking for a Principal Software Engineer role to lead, architect, and develop solutions for solving some of hardest AI security problems our customers are facing, including but not limited to incident response, evaluation frameworks, security mitigations, and monitoring infrastructure. You will help shape technical strategy, drive execution, and collaborate across security, applied science, platform, and product organizations to reduce real‑world risk in next‑generation AI. You will spend much of your time both being extremely hands-on with technical deliverables and being a strong leader on the team to do the same via effective adoption of agentic workflows. Your work will directly influence Microsoft’s security posture, accelerate risk mitigation, and underpin customer trust in the AI experiences that power the company’s future.
This position is based at the Redmond campus with 3 days per week work in the office and 2 days per week work from home. Domestic relocation assistance is available.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
Directly accountable and responsible for the design and implementation of distributed systems that deliver security‑focused improvements and mitigations, including telemetry, reproducibility, CI/CD safety gates, governance, and automated validations.
Set engineering direction for services and tooling supporting adversarial testing, model evaluation, risk measurement, and secure deployment workflows.
Ensure that security mitigations and security‑driven architectural changes meet high bars for availability, reliability, security, performance, and scalability, providing durable protection across complex AI systems.
Champion best practices in threat modeling, observability, automation, and sustainable engineering.
Partner with security researchers, red teams, applied scientists, Responsible AI, platform engineering, and product teams to translate risks into actionable engineering plans and hardening strategies.
Work closely with PM/TPM partners on roadmaps, prioritization, and delivery commitments.
Represent Copilot Security Engineering in architecture reviews, risk assessments, and cross‑team security initiatives.
Deliver engineering capabilities that increase detection coverage, accelerate time‑to‑mitigation, and provide auditable, repeatable evaluation workflows across AI systems.
Drive simplification, reusable patterns, and platform approaches that scale across Microsoft's AI ecosystem.
Communicate technical strategy, progress, risks, and results clearly to leadership and partner teams.
Qualifications
Minimum
Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred
Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Experience building or operating security critical systems, evaluation frameworks, or platform services.
Familiarity with adversarial testing, AI/ML evaluation, telemetry pipelines, or secure by design engineering practices.
Experience partnering with applied science, security research, red teams, or Responsible AI stakeholders.
Proven ability to influence cross organizational partners and align engineering execution with product and risk priorities.
Solid written and verbal communication skills, including experience presenting technical strategy to senior leadership.