This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join Microsoft Entra’s Global Secure Access (GSA) engineering organization, where we build security for modern work and AI-powered experiences at global scale. Our charter spans cloud-delivered networking and security capabilities aligned to Secure Access Service Edge (SASE), including identity-aware access, policy enforcement, and high-performance datapath services. We are looking for a Principal Software Engineer to be a technical visionary in the SASE space. In this role, you will shape the architecture and technical roadmap for critical secure access capabilities, drive engineering standards and operational excellence across teams, and accelerate responsible AI adoption (including Copilot and AI-assisted engineering workflows) to improve developer productivity, reliability, and customer outcomes. You will lead by example through technical depth, clear communication, and sustained mentoring—raising the technical bar for the engineers you guide across the organization.
Job Responsibility:
Own and evolve the end-to-end architecture for SASE capabilities (e.g., secure web gateway, ZTNA, identity-aware proxying, traffic steering, policy enforcement) across multiple services and teams
Set technical direction and multi-release roadmap in partnership with Product Management, Security Research, and cross-organization engineering leaders
identify dependencies and drive crisp, durable design decisions
Lead design reviews for high-impact systems and drive engineering standards across the product lifecycle (security, privacy, safety, accessibility, performance, reliability, and cost)
Write proof-of-concept code and/or deliver production code for critical path investments
actively troubleshoot difficult and complex issues in distributed, high-scale networking systems
Drive operational excellence for live services, including telemetry strategy, incident response mechanisms, DR readiness, and post-incident learning to improve resilience and customer trust
Accelerate responsible AI adoption across engineering (AI-assisted design, coding, testing, and operations)
establish best practices, guardrails, and success metrics to measurably improve outcomes
Mentor and sponsor engineers across levels
raise the bar through coaching, code and design feedback, and cultivating an inclusive culture that inspires technical excellence
Requirements:
Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role
These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter
Nice to have:
Experience designing, building, and operating cloud services and distributed systems at scale, including reliability, observability, and live-site operations
Deep understanding of networking and network security fundamentals, including TCP/IP, HTTP/HTTPS, TLS, routing, and proxy-based architectures
Proven technical leadership influencing architecture and engineering practices across teams (e.g., driving design reviews, setting standards, mentoring, and aligning stakeholders)
Experience building security products or platforms in areas relevant to SASE (e.g., secure web gateway, ZTNA, VPN replacement, identity-aware access, policy enforcement, traffic inspection)
Demonstrated industry leadership in SASE (e.g., published technical work, open-source contributions, standards participation, conference talks, patents, or externally visible technical leadership)
Hands-on experience with high-performance datapaths and L7 proxies (e.g., Envoy, NGINX, HAProxy) and/or packet processing (e.g., eBPF, DPDK, XDP)
Experience with Zero Trust policy systems, identity integration, and secure access architectures spanning users, devices, and workloads
Experience driving adoption of AI-assisted engineering and/or applying ML/AI techniques to security telemetry, anomaly detection, or automation
Experience leading cross-organization technical initiatives, influencing roadmaps, and delivering outcomes across multiple product lines
C++, C#, Java, Go, Rust
OR equivalent experience
2 years Kubernetes, 3 years of Network protocols or Software Firewall, Proxy development