Senior Software Engineer
The Copilot Security Engineering team sits at the core of Microsoft's mission to deliver secure, trusted, and human-centered AI experiences across Microsoft's Copilot offerings. We build the systems that detect, evaluate, and defend against emerging AI threats, including prompt injection, memory poisoning, data exfiltration, adversarial inputs, and abuse of agentic workflows. Our goal is to establish industry-leading security protections that enable customers to confidently adopt AI at scale.
Our team combines security engineering, AI systems expertise, and threat research to identify emerging risks, develop novel defenses, and continuously measure the effectiveness of those protections in production environments. We work closely with product teams, Microsoft Research, and platform organizations to ensure security is built into every layer of the Copilot ecosystem.
We are looking for a Senior Software Engineer who is passionate about securing AI-powered systems and enjoys solving complex security challenges at large scale.
In this role, you will lead the design and development of AI threat detection and defense systems that protect Copilot experiences across Microsoft. You will drive solutions from threat identification through production deployment, partnering closely with engineers, security researchers, product teams, and platform organizations.
This is a hands-on technical leadership role for an engineer who enjoys operating at the intersection of security, AI, and large-scale distributed systems. You will help define how Microsoft detects, evaluates, and mitigates emerging AI attacks while building the security capabilities that enable Copilot experiences to operate safely and responsibly for millions of users worldwide.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
Lead the design and implementation of AI threat detection systems that identify and mitigate threats such as prompt injection, memory poisoning, data exfiltration, agentic workflow abuse, and emerging adversarial attacks.
Drive the development of security services, classifiers, evaluation frameworks, telemetry pipelines, and risk assessment systems used to measure and improve Copilot security posture.
Conduct threat modeling exercises and identify security gaps across AI workflows, tools, orchestration layers, and platform integrations.
Partner with product teams to translate security requirements into scalable engineering solutions and platform capabilities.
Investigate emerging attack techniques and develop durable defenses that can be adopted across multiple Copilot experiences.
Drive root cause analysis and technical remediation efforts following security incidents.
Influence architectural decisions and engineering investments that improve platform security, resilience, and trustworthiness.
Lead design reviews and mentor engineers through technical guidance, code reviews, and knowledge sharing.
Contribute to technical strategy and roadmap planning for key AI security investments.
Participate in on-call rotations and lead investigations during complex security events impacting production systems.
Qualifications
Required Qualifications:
- Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR equivalent experience.
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings:
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR equivalent experience.
- 5+ years of experience designing, building, and operating production software systems.
- Software engineering fundamentals and proficiency in one or more modern programming languages such as C#, C++, Go, Rust, Python, or TypeScript.
- Experience designing distributed systems, cloud-native services, or platform infrastructure at scale.
- Experience identifying, analyzing, or mitigating security risks in production environments.
- Understanding of modern AI security challenges, including prompt injection, indirect prompt attacks, memory poisoning, data exfiltration, model misuse, and agentic system risks.
- Ability to drive technical initiatives across multiple teams and influence engineering decisions without direct authority.
- Problem-solving and communication skills, including the ability to explain technical tradeoffs to engineers, product teams, and leadership.
- Ability to meet Microsoft, customer, and government security screening requirements.
- Experience building security detection systems, reputation systems, anomaly detection platforms, threat intelligence systems, abuse prevention technologies, or Trust & Safety systems.
- Experience with large language models, AI systems, machine learning infrastructure, or evaluation frameworks.
- Experience performing threat modeling, security reviews, red teaming, adversarial testing, or incident response.
- Familiarity with AI safety, AI security research, or emerging attack and defense techniques.
- Contributions to security tooling, patents, publications, open-source projects, or recognized technical leadership in security-related domains.
#AISecurity #Copilot #SecurityEngineering #M365Core
Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.