
Microsoft's Marketing Security Risk & Compliance team is looking for a Security Assurance Engineer II to execute security assurance activities across Microsoft Marketing services, applications, data platforms, and cloud environments. The Marketing Security Risk & Compliance team works with service owners and engineering teams to identify security risks, strengthen service architecture, and support compliance with Microsoft security requirements. The team is modernizing its security review process by combining architecture analysis, cloud telemetry, automated evidence, and human security expertise. In this role, you will evaluate services against defined security requirements, support threat-model reviews, investigate security signals, document findings, and help service teams understand and complete remediation. You will work with more senior Security Assurance Engineers on complex reviews while independently owning well-scoped assessments and findings. You will gain experience across cloud security, application security, threat modeling, data protection, artificial intelligence security, identity, networking, and secure engineering. Your work will directly contribute to reducing risk and improving security accountability across Microsoft Marketing
Execute security assurance activities for assigned Microsoft Marketing services and engineering programs, with a focus on scalable, automated, and data-driven review practices. · Support and independently conduct security reviews, threat-modeling engagements, Secure Development Lifecycle assessments, and automated security-analysis workflows. · Review service architecture, data flows, trust boundaries, cloud resources, identities, endpoints, network configurations, privileged access, code-security signals, data-protection signals, and supporting evidence. · Build and maintain scripts, queries, APIs, and automation that collect security evidence, analyze technical signals, identify potential control gaps, and reduce manual review effort. · Develop repeatable methods for automatically assessing service configurations, cloud resources, identity and access controls, vulnerabilities, sensitive-data exposure, and other security signals. · Use Microsoft security requirements, secure engineering guidance, automated analysis, and AI-assisted techniques to identify potential threats and security gaps. · Validate automated and AI-generated findings by investigating false positives, correlating signals across data sources, confirming affected scope, and gathering supporting evidence. · Integrate security-review activities with engineering systems and workflows to automate evidence collection, finding creation, remediation tracking, notifications, and reporting where appropriate. · Document findings with clear technical descriptions, affected components, recommended remediation, ownership, and required closure evidence. · Create and maintain security findings in engineering tracking systems and monitor progress toward remediation. · Work directly with service owners and developers to clarify requirements, answer security questions, and help teams prepare effective mitigation evidence. · Review submitted remediation evidence against established acceptance criteria and escalate complex or disputed decisions to senior reviewers. · Support security assurance for tenant migrations, new technologies, artificial intelligence solutions, platform changes, and emerging engineering patterns. · Build queries, reports, and automated monitoring to identify review coverage gaps, overdue findings, recurring control weaknesses, and other program-health indicators. · Contribute reusable security checks, review templates, automation components, technical documentation, security guidance, training materials, and knowledge-management practices. · Continuously identify opportunities to replace repetitive manual activities with standardized evidence, automated controls, APIs, agentic or AI-assisted workflows, and engineering solutions. · Test and improve security-review automation by evaluating accuracy, false positives, evidence quality, coverage, reliability, and operational effectiveness. · Participate in review calibration, technical learning, and mentoring activities to deepen security, software engineering, and automation expertise. · Collaborate with engineering, compliance, privacy, data protection, and security teams to support secure and compliant service operations at scale.
Software Engineering IC3 - The typical base pay range for this role across the U.S. is USD $102,100 - $202,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $133,800 - $219,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Every company has a mission. What's ours? To empower every person and every organization to achieve more. We believe technology can and should be a force for good and that meaningful innovation contributes to a brighter world in the future and today. Our culture doesn’t just encourage curiosity; it embraces it. Each day we make progress together by showing up as our authentic selves. We show up with a learn-it-all mentality. We show up cheering on others, knowing their success doesn't diminish our own. We show up every day open to learning our own biases, changing our behavior, and inviting in differences. Because impact matters.
Microsoft operates in 190 countries and is made up of approximately 228,000 passionate employees worldwide.