Principal Software Engineer
Indexed description
The Azure Key Management team is part of Azure Security and builds foundational, cloud-scale key management services that help protect the most sensitive cryptographic keys across Azure. Our team delivers Azure Key Vault Keys and single-tenant Hardware Security Module (HSM) offerings, including Managed HSM, Cloud HSM, Payment HSM, and BareMetal HSM services, serving both external customers and internal Azure services that rely on trusted key management at cloud scale.
We are looking for a Principal Software Engineer to provide technical leadership for the next generation of Azure key management and HSM platform capabilities. In this role, you will shape architecture, drive end-to-end engineering execution, and help support post-quantum cryptography across these cloud services, enabling Azure and our customers to move toward quantum-safe security. You will partner across Azure and the HSM ecosystem to deliver secure, compliant, highly available, and scalable services for regulated and mission-critical workloads and provide primitives to make them post quantum safe.
If you’re passionate about security, love solving complex problems, and thrive in a collaborative environment, this is your chance to make a global impact.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
- Lead architecture and technical strategy for Azure Key Management, including scalable, secure, and reliable services for external customers and internal Azure services.
- Drive end-to-end design, hands-on implementation, coding quality, and operational readiness across control plane, data plane, secure hardware, and networking boundaries.
- Advance post-quantum cryptography readiness by shaping service architecture, integration patterns, and implementing engineering execution plans.
- Partner across Azure, Microsoft Security, and the HSM vendor ecosystem to deliver cohesive platform solutions for regulated and mission-critical workloads.
- Improve platform availability, resiliency, scalability, and diagnosability through production-focused architecture and engineering excellence.
- Provide technical mentorship and architectural guidance while raising the quality, maintainability, and long-term extensibility of the engineering system.
- Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR equivalent experience.
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- BS degree in Computer Science, Electrical and Computer Engineering, or equivalent experience.
- 10+ years of experience designing and building cryptographic systems, including deep understanding of cryptographic primitives, protocols (e.g., TLS, PKI), and their application in real-world systems.
- 15+ years of hands-on experience in security and systems programming, with demonstrated application of security principles such as threat modeling, secure design, and vulnerability analysis.
- Expert-level experience coding in C/C++ with strong programming, design, problem-solving, quality, and engineering excellence skills.
- Proven experience building and operating cloud-scale, distributed services.
- Experience working with Linux and Open-Source Software (OSS) technologies.
- Experience with Trusted Execution Environments (TEEs) such as Intel SGX, AMD SEV, or similar enclave-based technologies.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search