Senior Software Engineer
Software Engineering
Redmond, WA, USA
The Agent 365 Foundation team builds and operates the platform layer that keeps agent workloads reliable, secure, and fast at Microsoft scale. Our charter within this group is traffic ingress: every request that reaches our clusters passes through the gateway and edge systems we own. We are the front door, which means we are also the first line of defense and the first place a problem shows up.
A significant part of our current focus is ingress for Dynamics 365 and Power Platform traffic. That work spans routing and gateway policy, connection and protocol handling, tenant isolation, throttling and abuse mitigation, failover behavior across regions, and the observability needed to reason about all of it while it is happening. The scale is large, the traffic patterns are diverse, and the correctness bar is high.
About the Role
We are hiring a Senior Software Engineer to design, build, and operate the gateway and ingress path end to end. This is a hands-on engineering role. You will spend your time in code, in design reviews, and in production — writing services in C# and Go, tuning TLS and HTTP/2 behavior, shaping how gRPC traffic flows through the stack, working with Azure Front Door and our own edge components, and hardening the system against volumetric and application-layer attacks.
You will own outcomes rather than tickets. That means choosing where resiliency belongs in the request path, deciding what a safe failure mode looks like for a given class of traffic, and defending those decisions with data. You will also be part of the on-call rotation for the systems you build, because the fastest way to build a resilient front door is to feel it when it bends.
Who Thrives in This Role
The engineer who does well here is genuinely hands-on. You are comfortable being the person who reads the proxy source, reproduces the failure locally, and lands the fix — seniority here means more time close to the system, not less. You think critically about problems before reaching for a solution, ask what the data actually shows, and are willing to challenge a design, including your own, when the evidence points elsewhere.
You also do not shy away from hard problems. Ambiguous incidents, legacy traffic paths, unfamiliar protocol behavior, and difficult cross-team conversations are part of the work, and you move toward them rather than around them. You are direct, collaborative, and comfortable operating with a high degree of ownership.
Why This Role Matters
Ingress is where reliability and security are decided for everything behind it. The work you do here is visible in the availability numbers of some of Microsoft's largest business platforms, and it is felt immediately by the customers who depend on them. If you want a role where deep networking expertise, sound judgment, and engineering craft compound into real impact, this is it.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
Design, implement, and operate L4 and L7 ingress components — gateways, proxies, load balancing and routing policy — that carry Dynamics 365 and Power Platform traffic into our clusters.
Own the protocol layer: TLS termination and certificate lifecycle, HTTP/2 connection management, gRPC routing and streaming behavior, and the performance characteristics of each.
Build resiliency into the request path through health-based routing, retries and hedging, circuit breaking, load shedding, rate limiting, and regional failover, and prove the behavior through fault injection and load testing.
Strengthen the security posture of the edge, including DDoS detection and mitigation, WAF and abuse-mitigation policy, tenant isolation, and defense against application-layer attack patterns.
Integrate and tune Azure Front Door and related edge services alongside our first-party gateway components, and make deliberate decisions about which layer solves which problem.
Instrument the ingress path so that latency, error, and saturation questions can be answered in minutes, and drive incident response, root-cause analysis, and the follow-through that keeps the same failure from repeating.
Partner with service teams across Dynamics 365, Power Platform, and Agent 365 on onboarding, capacity, and traffic-shaping decisions, and raise the engineering bar through design and code review.
Qualifications
Required Qualifications:
- Bachelor's Degree in Computer Science or related technical field AND 4+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR equivalent experience.
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings:
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python
- OR equivalent experience.
- Proven knowledge of L4 and L7 networking: TCP connection behavior, load balancing, proxying, routing, DNS, and the tradeoffs between transport-level and application-level handling.
- Practical depth in TLS, HTTP/2, and gRPC, including certificate management, handshake and connection tuning, multiplexing behavior, and diagnosing protocol-level failures from packet captures and traces.
- Production experience with C# or Go, and the willingness to work fluently in both.
- Demonstrated experience making services resilient under stress — designing for graceful degradation, and validating it rather than assuming it.
- Experience operating what you build, including on-call ownership, live-site debugging, and post-incident improvement.
- Hands-on experience with Azure Front Door, Azure networking, or comparable CDN and global edge platforms.
- Direct experience with DDoS protection: volumetric and application-layer attack detection, mitigation policy, rate limiting, and bot management.
- Experience running ingress in Kubernetes environments, including service mesh and Envoy-based data planes.
- Familiarity with multi-tenant SaaS traffic patterns, such as those in Dynamics 365 or Power Platform, and the isolation and fairness problems they create.
- Background in performance analysis and capacity planning for high-throughput, low-latency systems.
Software Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.