layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Microsoft
Redmond, WA
Source: Microsoft careers · View original posting
From Microsoft's posting. “We” and “our” refer to the employer.
Overview
Help secure the cloud Microsoft runs on. Microsoft Digital's Network Defense Engineering (NDE) team in Redmond, Washington is hiring a Principal Security Engineer to lead cloud and hybrid network security.
Microsoft Digital (MSD) builds and runs the products and services Microsoft depends on. We pursue big ideas that drive transformational advances for Microsoft and its customers, and our engineers bring deep technical expertise and large-scale, first-hand experience to every problem we solve.
As a Principal Service Engineer - Security Focus with a Cloud Security focus on the NDE team, you will set the technical direction for cloud security and extend our security programs - governance, exposure management, protection, detection, and response - from the on-premises network into Azure and our hybrid estate.
You will partner closely with Cloud Network Engineering, the team that operates Microsoft's cloud connectivity, secure network zones, and Azure Firewall infrastructure, to harden the boundary between our corporate networks and the cloud, and you will define the security architecture, controls, and telemetry that protect it.
Working from industry-standard cybersecurity frameworks, you will lead multi-team programs spanning secure configuration and policy enforcement, identity and privileged access, vulnerability and configuration compliance, threat detection, and automated response. You will influence security policy across organizations, mentor engineers, and serve as a senior technical voice during major-impact incidents.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
5+ years technical experience working with large-scale cloud or distributed systems, including leading security architecture or security programs across multiple teams.
Deep experience securing Azure network infrastructure - Network Security Groups, Application Security Groups, Azure Firewall and Firewall Manager, Web Application Firewall, DDoS Protection, NAT Gateway and SNAT behavior, Private Link and private endpoints, and hub-and-spoke topologies.
Experience with enterprise hybrid connectivity and its security implications - ExpressRoute circuits, private peering and gateways, BGP and AS-path routing behavior, VNet peering, network zoning and trust boundaries, and DNS design including Anycast and Private DNS zones.
Experience with cloud security posture and governance at scale - Azure Policy, resource locks, Microsoft Entra ID, RBAC, PIM and least-privilege access, managed identities, Azure Key Vault and secrets management, subscription and tenant hardening, and Microsoft Defender for Cloud.
Experience with cloud threat detection and response - Microsoft Sentinel, Microsoft Defender XDR, KQL and Kusto (Azure Data Explorer), security telemetry and logging pipelines, and security orchestration and automated response.
Experience delivering security automation and infrastructure as code - ARM templates, Bicep or Terraform, PowerShell or Python, REST APIs, Azure DevOps pipelines, and policy-as-code.
Experience applying a security framework such as the NIST Cybersecurity Framework 2.0 or Zero Trust to build and mature enterprise security programs, including threat modeling, security reviews, and audit and SOX readiness.
Experience in SOC, SecOps, or InfoSec environments, including incident response, threat hunting, and vulnerability management across cloud and hybrid environments.
Relevant industry certifications such as AZ-500, SC-100, CISSP, CCSP, CCNP or CCIE Security, OSCP, or SANS GIAC (GCIA, GCIH, GPCS).
#MSD #MSDJOBS #NetworkDefense #CloudSecurity #Azure #Security #ServiceEngineering
Service Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: