Microsoft is seeking Principal Software Engineers to join their new team focused on building innovative software-security solutions. This role involves designing and improving systems that enhance security across software supply chains and collaborating with various teams to implement secure development practices.
Responsibilities:
- Design, build, and improve systems that enhance security across software supply chains and open-source ecosystems (e.g., npm, PyPI, NuGet, Maven, Cargo)
- Analyze dependencies, vulnerabilities, and potential malware to help ensure the integrity and safety of software components
- Apply program analysis techniques (static, dynamic, sandboxing/detonation, deobfuscation, behavioral analysis) to better understand and assess code behavior
- Develop and operate scalable cloud-based pipelines (Azure preferred) for large-scale scanning, detection, and data processing
- Contribute to and uphold supply chain integrity practices, including SBOM, SLSA, provenance, and artifact signing (e.g., Sigstore)
- Collaborate on threat detection and security research, including malware and vulnerability analysis, within security-sensitive systems
- Integrate security capabilities with developer tools and platforms such as GitHub, Visual Studio, and CI/CD systems
- Partner cross-functionally with engineering, security, and product teams to improve secure development practices
- Continuously evaluate and improve detection methods, tooling, and processes to adapt to evolving security threats