Principal Security Engineer

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Software Engineering

In short

Microsoft is seeking a Principal Security Engineer for its Cloud & AI organization to lead AI-driven red team operations. This role involves full-scope adversary emulation against customer environments, designing and directing autonomous agents to discover and exploit vulnerabilities at scale, and acting as a technical authority for customers and internal teams.

Responsibilities

  • Execute CyberShield red team operations end-to-end, including initial access, privilege escalation, lateral movement, persistence, objective completion, and reporting against Microsoft and customer environments.
  • Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate advanced adversary capabilities.
  • Lead agentic red team operations by designing and directing AI agents for reconnaissance, vulnerability discovery, exploitation, and post-exploitation.
  • Discover and exploit security vulnerabilities across application, cloud, identity, network, hardware, and operational security layers, chaining findings into realistic attack paths.
  • Serve as the forward-deployed technical lead with customers, briefing CISOs and security leaders, and translating findings into actionable narratives.
  • Prototype and productionize tools, agents, and techniques to scale offensive emulation and vulnerability discovery.
  • Collaborate with Blue Teams, adversary hunting organizations (GHOST), threat intelligence centers (MSTIC), and service teams to improve defender readiness.
  • Set operational standards and playbooks for CyberShield engagements, mentoring senior operators.
  • Advocate for security change across Microsoft and its customers by building partnerships and communicating risk impact.

Requirements

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years of experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years of experience in security or related field OR equivalent experience.
  • Ability to meet Microsoft, customer and/or government security screening requirements.
  • Microsoft Cloud Background Check required.
  • Operators in customer environments may require additional customer- or government-directed vetting.

Desired Qualifications

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years of experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years of experience in security or related field OR equivalent experience.
  • 6+ years of experience planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Demonstrated hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
  • Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.
  • 8+ years of experience identifying and exploiting security vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware.
  • Experience designing multi-agent or autonomous systems using large language models – orchestration frameworks, tool use, agent evaluation, and safety guardrails – applied to offensive security.
  • 6+ years of experience with coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, Rust, or other comparable programming languages, including building and maintaining offensive tooling.
  • Experience in customer-facing or consulting roles delivering red team results to executive audiences.
  • Blue team, detection engineering, or incident response experience.
  • Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (e.g., TIBER-EU, CBEST, DORA).
  • Recognized contributions to the security community: research, open-source tooling, conference talks, or CVEs.

Benefits

  • This position will be open for a minimum of 5 days.
  • Applications accepted on an ongoing basis until the position is filled.
  • Access to a link for additional benefits and pay information: https://careers.microsoft.com/us/en/us-corporate-pay

Skills

PythonC#C++GoPowerShell.NETRustAzureAWSGCPEntra IDActive DirectoryWindowsLinux
#security#cloud#AI#penetration testing#red team#adversary emulation#vulnerability discovery#exploitation#autonomous agents#MITRE ATT&CK
Microsoft Logo

About Microsoft

Empowering every person and organization on the planet to achieve more

Every company has a mission. What's ours? To empower every person and every organization to achieve more. We believe technology can and should be a force for good and that meaningful innovation contributes to a brighter world in the future and today. Our culture doesn’t just encourage curiosity; it embraces it. Each day we make progress together by showing up as our authentic selves. We show up with a learn-it-all mentality. We show up cheering on others, knowing their success doesn't diminish our own. We show up every day open to learning our own biases, changing our behavior, and inviting…

Microsoft Logo

Company

Microsoft

Job Posted

20 hours ago

Employment Type

Full Time

Work mode

Remote

Salary

US$165,600–296,400 · Negotiable

Experience Level

Mid-Senior

Locations

United States

Qualification

Master, Bachelor

Applicants

Be an early applicant