Senior Security Assurance Engineer - Marketing Security Risk & Compliance
Microsoft | |
$119,800.00 - $234,700.00 / yr
| |
United States, Washington, Redmond | |
Oct 05, 2026 | |
|
Overview
Microsoft's Marketing Security Risk & Compliance team is looking for a Senior Security Assurance Engineer to lead complex security reviews and threat modeling for Microsoft Marketing services, platforms, and data. Microsoft Marketing operates a diverse technology estate that includes cloud services, data platforms, business applications, artificial intelligence solutions, and complex integrations across Microsoft. The team partners with engineering and business organizations to identify and address security risk through security reviews, threat modeling, Secure Development Lifecycle practices, data-driven analysis, and continuous remediation. In this role, you will provide senior technical security assurance across a portfolio of Marketing services. You will lead security reviews for complex services and high-impact initiatives, evaluate technical architectures and security evidence, identify material security risks, and partner with engineering teams to drive findings through remediation and closure. You will help modernize security assurance from primarily manual, point-in-time reviews toward a scalable, intelligence-driven model that combines current service data, cloud telemetry, automated evidence collection, AI-assisted analysis, and expert engineering judgment. You will also identify recurring risks and opportunities to improve review standards, automation, and secure engineering practices across Marketing. This role requires strong technical judgment, the ability to operate independently in complex environments, and the ability to translate security findings into actionable engineering work. Responsibilities - Lead end-to-end security reviews and threat-modeling engagements for complex Microsoft Marketing services, applications, platforms, and data environments. - Analyze architecture, data flows, trust boundaries, identities, endpoints, privileged access, network exposure, dependencies, logging, cloud configurations, and security controls. - Apply Microsoft security requirements and Secure Development Lifecycle practices to identify design weaknesses, implementation risks, control gaps, and missing evidence. - Lead security assurance for high-impact initiatives, including tenant migrations, new platforms, AI solutions, sensitive-data environments, and major architectural changes. - Evaluate security evidence and make risk-based recommendations on technical issues, remediation, and security requirements. - Facilitate technical security discussions with service owners, developers, architects, security and privacy teams, Responsible AI practitioners, and technical partners. - Validate automated and AI-assisted findings, distinguish material risk from false positives, and focus engineering teams on risks requiring action. - Document validated findings with clear severity, impact, remediation requirements, ownership, and closure evidence. - Translate security findings into clearly owned engineering work and track remediation through closure. - Review mitigation evidence and technical justifications, validate remediation, and escalate when evidence does not demonstrate sufficient risk reduction. - Use cloud telemetry, attack-path analysis, automated evidence collection, and AI-assisted capabilities to improve review depth, consistency, and efficiency. - Build and operationalize automation that accelerates evidence collection, security analysis, risk identification, reporting, and remediation workflows. - Identify recurring control failures, architectural weaknesses, and systemic security risks across services. - Translate recurring findings into reusable guidance, secure design patterns, improved review practices, and - Partner with service owners and engineering teams to apply Secure by Design, Secure by Default, and Secure Operations principles throughout the service lifecycle. - Contribute to security review standards, technical playbooks, templates, decision frameworks, training, and reusable guidance. - Partner with software engineers and security platform teams to develop and improve automated security review capabilities and workflows. - Provide technical guidance and mentoring to Security Assurance Engineers, improving review consistency and technical quality. - Communicate material risks, technical tradeoffs, remediation priorities, and escalation needs clearly Qualifications Required Qualifications
Preferred Qualifications
Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations. | |
$119,800.00 - $234,700.00 / yr
Oct 05, 2026