New
Principal Security Operations Engineer - CTJ - Top Secret
![]() | |
![]() United States, Washington, Redmond | |
![]() | |
OverviewThe Cloud & AI organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers' heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world. The IAM Protect team secures Microsoft's most critical cloud services by reducing risks in the Trusted Computing Base (TCB). We focus on identifying adversary tactics and breach paths, driving structured risk burndown, and ensuring critical telemetry is consistently available for detection and response. We are hiring a Principal Security Operations Engineer to lead efforts to operationalize TTP (Tactics Techniqes Proceedures) burndown campaigns and expand telemetry coverage across TCB services. The ideal candidate brings a security engineering background with hands-on technical depth, combined with the program management skills to coordinate across engineering teams, prioritize risk reduction, and deliver durable outcomes at scale. You will shape how we quantify and mitigate top risks, while ensuring telemetry pipelines are resilient, validated, and usable for hunt and investigation teams. This role is both technical and strategic - perfect for someone who thrives at the intersection of security operations, data, and engineering.Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
ResponsibilitiesResponsibilities As a Principal Security Operations Engineer you will lead structured risk reduction campaigns by converting adversary tactics (TTPs) Tactics Techniques and Procedures) and breach paths into prioritized cohorts and driving execution until closure. Build and scale telemetry coverage across critical services, ensuring validated, reliable data is available for our security response efforts. Investigate security incidents, help contain threats, and provide technical support for high-impact response efforts. Partner across engineering and security teams to coordinate cross-team efforts, resolve blockers, and accelerate progress on high-impact initiatives. Apply a data-driven approach to define, track, and report risk metrics, giving leaders clear visibility into progress and gaps. Integrate AI/ML solutions into security operation for intelligent incident triage, control validation, and telemetry analysis. Serve as a technical advisor and mentor to security engineers, sharing best practices for automation and secure-by-design patterns. Drive automation and efficiency by improving pipelines, validation frameworks, and onboarding flows to reduce manual effort. Gain deep exposure to the most sensitive services and systems, working at the intersection of security operations, engineering, and executive decision-making with direct impact on Microsoft's cloud security posture. |