Microsoft

Principal Security Engineer

Microsoft
Apply
19 hours ago
Remote, United StatesStaff+
H1B sponsor

Base Salary

$166k - $331k/yr

Responsibilities

  • Execute end-to-end red team and adversary emulation operations across Microsoft and select customer environments.
  • Develop custom tooling, implants, tradecraft, agents, and techniques to evade defenses and scale offensive security operations.
  • Design, direct, and supervise AI agents performing reconnaissance, vulnerability discovery, exploitation, and post-exploitation with defined guardrails and human checkpoints.
  • Identify and exploit vulnerabilities across application, cloud, identity, network, endpoint, hardware, and operational security layers.
  • Serve as a forward-deployed technical lead by briefing CISOs and security leaders and delivering actionable defensive guidance.
  • Prototype and productionize offensive security tools and agents and provide requirements to the offensive AI platform engineering team.
  • Collaborate with Blue Teams, GHOST, MSTIC, and internal service teams to improve hardening, detection, and defender readiness.
  • Set operational standards and playbooks, mentor operators, and communicate security risk to Microsoft and customer stakeholders.

Requirements

  • A master’s degree in Statistics, Mathematics, Computer Science, or a related field plus 6+ years of security or related experience, or a bachelor’s degree in one of these fields plus 8+ years of experience, or equivalent experience.
  • Ability to pass Microsoft, customer, and/or government security screening requirements, including the Microsoft Cloud Background Check.
  • Preferred advanced experience includes a master’s degree plus 8+ years or a bachelor’s degree plus 12+ years of security or related experience, or equivalent experience.
  • 6+ years of experience planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
  • 8+ years of experience identifying and exploiting vulnerabilities across Azure, AWS, GCP, identity systems, Windows and Linux endpoints, networks, and hardware.
  • Experience designing multi-agent or autonomous systems using large language models, including orchestration, tool use, evaluation, and safety guardrails.
  • 6+ years of coding or scripting experience with languages such as Python, C#, C++, Go, PowerShell, .NET, Rust, or comparable languages.
  • Experience delivering red team results to executive audiences in customer-facing or consulting roles.
  • Blue team, detection engineering, or incident response experience, plus familiarity with MITRE ATT&CK, threat-informed defense, TIBER-EU, CBEST, or DORA.
  • Recognized security-community contributions such as research, open-source tooling, conference talks, or CVEs; an active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.

Benefits

  • Certain roles may be eligible for benefits and other compensation.
  • The position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until filled.

Tech Stack

Categories

Microsoft

About Microsoft

10,000+ employees

Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.

Contact me