Overview
The Policy and Configuration team builds the shared deployment and policy capabilities that help Microsoft Security services ship safely across Azure, regions, and sovereign clouds. As a Principal Software Engineer, you will set technical direction for this control plane, partner across Microsoft Security and Azure, and turn complex deployment requirements into secure, self-service developer experiences. Your work will reduce dependence on proprietary tools while creating reusable platform patterns that can scale from Defender to Microsoft.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
We are looking for a Principal Software Engineer to define the next generation of deployment configuration and policy for Microsoft Security. This role works across Microsoft Security, Azure, and partner platforms to make secure deployment self-service, reliable, and eventually invisible to service teams. The engineer will shape Azure-native security offerings, influence platform roadmaps, and replace legacy deployment patterns with a smaller, safer control plane.
• Define the architecture and migration path from proprietary tools to standard .NET Aspire and Azure platform capabilities. Make the path work for Defender and Microsoft Security today, all of Microsoft over time.
• Turn deployment, compliance, and security requirements into typed APIs, analyzers, and build gates. Move data residency, rollout, and configuration failures from deployment time to authoring time.
• Improve the service-team experience through clear diagnostics, safe upgrade paths, and self-service workflows. Use support demand and adoption data to remove recurring friction.
• Build production-quality control-plane capabilities with clear ownership, strong test strategy, secure defaults, and zero-touch deployment where possible.
• Drive technical agreements with .NET, Azure, CISO, and service team partners. Resolve dependency boundaries and make end-to-end security, compliance, and operational readiness real before release.
• Lead design reviews, incident learning, and reusable engineering practices across teams. Grow shared capability in modern cloud development and AI-assisted engineering.
Embody our culture and values
Qualifications
Required Qualifications
• Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Qualifications - Other Requirements:
Ability to meet Microsoft, customer and/or government security screening