Principal Security Engineer

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Software Engineering

In short

Principal Security Engineer at Microsoft's Cloud & AI organization, specifically within the Microsoft Red Team (MRT) CyberShield program. This role focuses on leading agentic, AI-driven adversary emulation operations for external customers, moving beyond traditional human-led engagements to a software-driven, continuous model. You will plan and execute full-scope red team operations, develop custom tooling, and serve as a technical authority for customers and peers.

Responsibilities

  • Execute CyberShield red team operations end-to-end: initial access, privilege escalation, lateral movement, pivoting, persistence, objective completion, and reporting against Microsoft's and select customer environments.
  • Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate advanced adversary capabilities.
  • Lead agentic red team operations: design and direct AI agents for autonomous reconnaissance, vulnerability discovery, exploitation, and post-exploitation with defined guardrails and human oversight.
  • Discover and exploit vulnerabilities across application, cloud, identity, network, hardware, and operational security layers, chaining findings into realistic attack paths.
  • Serve as the forward-deployed technical lead with customers, briefing CISOs and security leaders, and translating findings into actionable narratives.
  • Prototype and productionize tools, agents, and techniques that scale offensive emulation and vulnerability discovery.
  • Collaborate with Blue Teams, GHOST (adversary hunting), MSTIC (threat intelligence), and internal service teams to improve product hardening and defender readiness.
  • Set operational standards and playbooks for CyberShield engagements; mentor senior operators.
  • Advocate for security change across Microsoft and its customers by building partnerships and communicating risk impact.

Requirements

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years of experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years of experience in security or related field OR equivalent experience.
  • Ability to meet Microsoft, customer, and/or government security screening requirements, including Microsoft Cloud Background Check.
  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years of experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years of experience in security or related field OR equivalent experience.
  • 6+ years of experience planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Demonstrated hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
  • 8+ years of experience identifying and exploiting security vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware.
  • 6+ years of experience with coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, Rust, or other comparable programming languages.
  • Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (e.g., TIBER-EU, CBEST, DORA).

Desired Qualifications

  • Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.
  • Experience designing multi-agent or autonomous systems using large language models – orchestration frameworks, tool use, agent evaluation, and safety guardrails – applied to offensive security.
  • Experience in customer-facing or consulting roles delivering red team results to executive audiences.
  • Blue team, detection engineering, or incident response experience.
  • Recognized contributions to the security community: research, open-source tooling, conference talks, or CVEs.

Benefits

  • Typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year.
  • For specific work locations within the San Francisco Bay area and New York City metropolitan area, the base pay range is USD $188,000 - $304,200 per year.
  • Certain roles may be eligible for benefits and other compensation.
  • Applications accepted on an ongoing basis until the position is filled.
#Security Engineering#Penetration Testing#Cloud#AI#Red Team#Adversary Emulation#Agentic Red Teaming#Vulnerability Discovery#Exploitation#Customer Engagements
Microsoft Logo

Company

Microsoft

Job Posted

1 day ago

Employment Type

Full Time

WorkMode

Remote

Experience Level

Senior

Locations

United States

Qualification

Master, Bachelor

Applicants

Be an early applicant