Назад
1 день назад

Principal Security Operations Engineer (AI)

142 800 - 274 800$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Operations Engineer (AI): Building Microsoft AI's security telemetry, SIEM, detection, SOAR, incident-response, and AI-native security operations capabilities with an accent on production monitoring, automation, and protection for model, training, data, and infrastructure systems. Focus on designing evaluated security agents, reliable telemetry pipelines, detection lifecycle engineering, and safe automated investigation and response.

Location: Mountain View, New York, or Redmond, United States

Salary: USD $142,800–$274,800 per year across the U.S.; USD $188,000–$304,200 per year in the San Francisco Bay Area and New York City metropolitan area.

Company

Microsoft AI develops and operates first-party models and the infrastructure supporting products including Foundry, Copilot, Microsoft 365, and MDASH.

What you will do

  • Define and build security observability across identities, endpoints, hosts, workloads, containers, networks, cloud control planes, developer systems, model infrastructure, data systems, and business applications.
  • Design reliable telemetry pipelines, deploy collection agents such as AzSecPack, and establish coverage, health, data-quality, access-control, resilience, and cost-management standards.
  • Build SIEM, detection-engineering, threat-hunting, SOAR, case-management, incident-response, containment, recovery, and corrective-action capabilities.
  • Create AI-native security operations using evidence-grounded evaluators, judges, and narrowly scoped agents for investigation and response.
  • Develop evaluation sets, adversarial tests, replay environments, quality measures, human-review mechanisms, guardrails, and rollback processes for automated security actions.
  • Set technical direction, build prototypes and production systems in code, establish a multi-year roadmap, and mentor engineers and incident responders across partner organizations.

Requirements

  • Doctorate with 3+ years, master's degree with 4+ years, bachelor's degree with 6+ years, or equivalent experience in software development, large-scale computing, threat modeling, cybersecurity, anomaly detection, SIEM, or incident response.
  • Extensive experience designing, building, and operating security monitoring, detection, or response systems in complex production environments.
  • Strong software-engineering experience with production code, distributed systems, testing, deployment, debugging, and operational ownership.
  • Experience with telemetry and collection, SIEM and detection engineering, SOAR and response automation, incident leadership, or security infrastructure for AI and machine-learning systems.
  • Experience building and evaluating production or near-production statistical, machine-learning, large-language-model, or agentic systems for operational or security use cases.
  • Experience with Azure security telemetry, Microsoft Sentinel, Defender platforms, Kusto Query Language, AzSecPack, or comparable technologies; certifications such as CISSP, CISA, CISM, SANS, OSCP, or Security+ are preferred.

Nice to have

  • Experience with adversary simulation, purple teaming, threat-informed defense, or detection coverage mapping.
  • Experience securing AI or machine-learning infrastructure, large-scale compute, model-development systems, sensitive research environments, or high-value intellectual property.
  • Experience creating a new security-operations capability where ownership, architecture, and processes were not previously settled.
  • Evidence of technical influence through platforms, standards, open-source work, publications, incident leadership, or widely adopted engineering practices.

Culture & Benefits

  • Principal individual-contributor role with influence through architecture, code, technical judgment, prototypes, production ownership, and cross-team collaboration.
  • Focus on measurable coverage, explicit residual risk, accountable ownership, evidence-grounded decisions, and reliable production systems.
  • Opportunity to influence Microsoft-scale security, identity, cloud, threat-intelligence, research, and AI-safety capabilities.
  • Benefits and additional compensation may be available depending on the role and work location.

Hiring process

  • Applications are accepted on an ongoing basis until the position is filled, with the posting open for at least five days.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →