Senior Application Security Engineer

Microsoft empowers every person and organization on the planet to achieve more through innovative software solutions.
$117,200 - $229,200
Security
Senior Software Engineer
Hybrid
4+ years of experience
Enterprise SaaS
This job posting may no longer be active. You may be interested in these related jobs instead:
Senior Software Engineer

Senior Software Engineer role at Microsoft Security, focusing on protecting services against cyberattacks through security monitoring and analysis.

Senior Security Engineer

Senior Security Engineer role at Microsoft focusing on Intune service security, combining software engineering with cybersecurity expertise to protect enterprise cloud services and customer data.

Senior Software Engineer

Senior Software Engineer role at Microsoft Security Response Center (MSRC) focusing on full-stack development and AI solutions to protect customers from online threats. Competitive salary and comprehensive benefits.

Senior Security Software Engineer

Senior Security Software Engineer role at Microsoft focusing on Azure cloud security, vulnerability assessment, and mitigation. Hybrid role in Redmond, WA.

Senior Software Engineer

Senior Software Engineer role at Microsoft Security focusing on cloud security, identity management, and threat detection, offering competitive pay and hybrid work environment.

Description For Senior Application Security Engineer

Microsoft is seeking a Senior Application Security Engineer for their Viva Trust team, focusing on Viva Engage (formerly Yammer). This role is crucial in securing new features, ensuring compliance with global regulations, and integrating privacy considerations early in the development process. The Viva Trust team is responsible for enabling Security, Privacy, Responsible AI, and Compliance for one of the world's top networks.

As a Senior Application Security Engineer, you will:

  • Conduct privacy and security assessments of platforms, data, and clients through code reviews and automation
  • Implement privacy, responsible AI, and security controls in the software development lifecycle
  • Collaborate with engineering and product teams on threat modeling and security architecture reviews
  • Help teams understand security, responsible AI, compliance, and privacy requirements
  • Provide on-call support for escalations
  • Implement defense-in-depth mechanisms to prevent security and privacy vulnerabilities

The ideal candidate will have:

  • 4+ years of experience in application security engineering/privacy engineering
  • Experience with application security standards like OWASP ASVS/Top 10 and CWE 25
  • Knowledge of common security libraries, controls, and flaws
  • Experience in security and privacy threat modeling
  • Understanding of responsible AI, privacy, and compliance regulations (e.g., GDPR, CPRA, SOC 2, ISO27k)
  • Familiarity with web proxies and development experience in languages like Java, Ruby, GraphQL, and REST

This role offers a unique opportunity to impact millions of users worldwide, working in a diverse, inclusive, and high-energy culture. The position combines the innovation of a startup with the resources of a leading software company, focusing on mission-driven work that has become increasingly important in the post-Covid world.

Last updated 6 months ago

Responsibilities For Senior Application Security Engineer

  • Privacy and Security assessments of platform, data and clients, through code reviews and automation.
  • Implement Privacy, Responsible AI and Security controls and checkpoints to detect and prevent issues early in the software development lifecycle.
  • Work with engineering and product teams in the design phase of products and features, conducting threat modeling and performing security architecture and design reviews.
  • Help engineering and product teams to understand Security, Responsible AI, Compliance and Privacy requirements.
  • On-call support for escalations.
  • Implement defense in depth mechanisms to prevent Security and Privacy vulnerabilities.
  • Embody Microsoft's culture and values.

Requirements For Senior Application Security Engineer

Java
JavaScript
TypeScript
Ruby
  • Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or TypeScript. OR equivalent experience.
  • 4+ years of experience in application Security engineering/Privacy engineering
  • 1+ years of experience with application security standards such as The Open Worldwide Application Security Project (OWASP ASVS)/Top 10, Common Weakness Enumeration (CWE 25).
  • 1+ years experience with common security libraries, security controls, and common security flaws.
  • Ability to meet Microsoft, customer and/or government security screening requirements
  • Pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter

Benefits For Senior Application Security Engineer

Medical Insurance
Education Budget
Parental Leave
  • Industry leading healthcare
  • Educational resources
  • Discounts on products and services
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Opportunities to network and connect

Interested in this job?