Senior Security Engineer - Development
Job Description
Join Microsoft’s Quantum Security & IT Operations (QSIT) team to advance quantum security and strengthen IT operations through automation, AI-assisted investigations, and detection engineering. This onsite role in Redmond, WA combines operational ownership across network, infrastructure, and physical security services with hands-on development of security tooling and workflows that support reliable day-to-day operations.
What you’ll do
- Build AI-enabled SOC automation and investigation capabilities, including signal enrichment, workflow orchestration, and analyst tooling.
- Develop and operate security tooling and data integrations such as dashboards and supporting platforms needed for dependable security operations.
- Tune detections and investigation workflows to improve signal quality, reduce false positives, shorten investigation time, and increase analyst productivity.
- Participate in incident investigation and response, maintain operational readiness, and troubleshoot security issues impacting network, infrastructure, and physical security services.
- Partner with engineering, facilities, networking, and security teams to automate manual processes, resolve operational issues, and strengthen end-to-end resilience.
Required qualifications
- Doctorate in Statistics, Mathematics, Computer Science, or related field (or equivalent via degree + experience).
- OR Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience spanning software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, SOC detection, threat analytics, SIEM, IT, or operations incident response.
- OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience spanning software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, SOC detection, threat analytics, SIEM, IT, or operations incident response.
- OR equivalent experience.
- 2+ years of experience programming in C++/C# or Python or Scala or similar technologies.
- Demonstrated experience coordinating incidents and supporting live services, including investigation, containment, recovery, escalation, triage, root-cause analysis, stakeholder communication, and operational readiness.
- Hands-on experience with Microsoft Sentinel (KQL) or an equivalent enterprise SIEM, including detection engineering, data onboarding, investigative analysis, and resolution of ambiguous, high-impact security issues.
- Hands-on experience with security automation and AI-assisted operational workflows using PowerShell, Python, Logic Apps, or similar technologies for signal enrichment, investigation, orchestration, and decision support.
- Working knowledge of enterprise networking including DNS, TCP/IP, firewalls, routing, VPNs, and network troubleshooting.
- Experience working with SOC and NOC.
- Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions, including exposure to insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint.
- Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context.
- Experience or interest in protecting strategic research programs from sustained external targeting, including familiarity with export control (EAR / ITAR) and government program environments.
- Must be able to meet Microsoft, customer and/or government security screening requirements, including passing the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.
- Citizenship & Citizenship Verification: provide proof of country of citizenship or proof of U.S. permanent residency or other protected status; citizenship verification will be completed with a valid passport (or other documents for lawful permanent residents, refugees, and asylees where applicable).
Preferred / additional qualifications
- Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, or anomaly detection.
- OR Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, or anomaly detection.
- OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, or anomaly detection.
- OR equivalent experience.
- CISSP, CISA, CISM, SANS OSCP Security.
Compensation and location
Location: Redmond, WA (onsite).
Salary: USD 119,800 - 261,000 per year.
Relevant technologies
- C++, C#, Python, Scala
- Microsoft Sentinel, KQL
- PowerShell, Logic Apps
- SQL (implied through KQL usage)