Enable job alerts via email!

Principal Security Engineer

AECOM

New York (NY)

On-site

USD 220,000 - 332,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in AI innovation seeks a Principal Security Engineer to lead security assessments and ensure AI integrations operate on a robust security model. The role emphasizes mitigating security threats and requires 8+ years of experience in technical engineering and security practices.

Qualifications

  • 8+ years technical engineering experience with coding in multiple languages.
  • Experience in security assessment methodologies and secure code development.
  • Experience in remediation across multiple security domains.

Responsibilities

  • Lead comprehensive risks assessments and validate security controls.
  • Identify and align remediation efforts to vulnerabilities.
  • Collaborate closely with partner teams to resolve security issues.

Skills

Security engineering
Coding in C#
Python

Education

Bachelor's Degree in Computer Science

Job description

Microsoft is at the forefront of AI innovation, tackling some of the most complex and significant AI challenges of our time. Our vision is ambitious—to deliver systems with genuine artificial intelligence capabilities across agents, applications, services, and infrastructure.

The Security Engineering team within MAI ensures our advancements in AI are secure and trustworthy. We integrate robust security measures directly into our platforms, enabling secure and efficient incorporation of external data and services without compromising safety or privacy.

We are looking for a **Principal Security Engineer** to lead security assessments and testing both internally and with external partners. Your role will ensure that Copilot and its integrations operate atop a robust security model that mitigates threats such as indirect prompt injection, unauthorized dataflows, and privacy breaches.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

**Responsibilities**

+ Lead comprehensive risks assessments, including automated risk identification, controls validation, and threat modeling across networking, operating systems, and application layers.

+ Identify security best practices, risks, and align remediations to vulnerabilities to drive remediation efforts effectively.

+ Proactively identify and help remediate security risks through code and configuration changes.

+ Collaborate closely with partner teams, facilitating their velocity by addressing and resolving underlying security issues.

+ Develop and maintain metrics to measure security impact, reliability at both tactical and strategic levels.

+ Provide security mentorship, fostering a culture of proactive security awareness and accountability.

+ Contribute to secure software development by writing, reviewing, and advising on secure coding practices, particularly in C#, Python, or equivalent languages.

**Qualifications**

**Required Qualifications:**

+ Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python

+ OR equivalent experience.

+ Experience in security engineering, including assessment, remediation, and secure code development.

+ Experience in security assessment methodologies, automated and manual testing techniques, and threat modeling.

+ Experience in remediation efforts across multiple product lines in one or more core security domains (networking, operating systems, software security).

**Preferred Qualifications:**

+ Experience assessing security specifically for AI/ML applications, including identification and remediation of risks through code or configuration changes.

+ Expertise in secure coding practices and code-level security in languages such as C#, Python, or similar. Familiarity with Rust, C++, or Go are pluses.

+ Experience working within AI, machine learning platforms, APIs, Retrieval-Augmented Generation (RAG), or similar technologies.

+ Understanding of AI/ML pipelines, including risks during and after both training and deployment.

+ Familiarity with interprocess communication in AI environments, including Agentic Model Context Protocol.

+ Deep understanding of agentic computing, communication patterns, and associated security considerations.

+ Demonstrated collaboration skills, with a proven track record of enabling partner teams and addressing systemic security risks proactively.

+ Experience implementing and interpreting performance, reliability, and risk metrics to drive security improvements.

Software Engineering IC6 - The typical base pay range for this role across the U.S. is USD $163,000 - $296,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $220,800 - $331,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

Microsoft will accept applications for the role until June 30, 2025.

\#MicrosoftAI #Copilot

Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations (https://careers.microsoft.com/v2/global/en/accessibility.html) .

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Principal Security Engineer - NY Remote

TieTalent

New York null

Remote

Remote

USD 215,000 - 260,000

Full time

Today
Be an early applicant

Principal Security Engineer

Microsoft

New York null

On-site

On-site

USD 220,000 - 332,000

Full time

Yesterday
Be an early applicant

Principal, Microsoft Security Engineer – Purview

Slalom

New York null

On-site

On-site

USD 122,000 - 225,000

Full time

12 days ago

Principal Enterprise Security Engineer

Upstart

null null

Remote

Remote

USD 182,000 - 253,000

Full time

25 days ago

Principal Product Security Engineer

Delinea Inc.

null null

Remote

Remote

USD 200,000 - 230,000

Full time

4 days ago
Be an early applicant

Lead Security Engineer

AECOM

New York null

On-site

On-site

USD 215,000 - 260,000

Full time

Yesterday
Be an early applicant

Principal Security Engineer

Ohiox

Columbus null

Remote

Remote

USD 182,000 - 253,000

Full time

30+ days ago

Principal Security Engineer

Upstart

null null

Remote

Remote

USD 182,000 - 253,000

Full time

30+ days ago

Sr. Security Engineer (1750)

Davita Inc.

New York null

Remote

Remote

USD 185,000 - 252,000

Full time

12 days ago