Microsoft

Principal Security Engineer

Microsoft
Apply
19 hours ago
Remote, United StatesStaff+
H1B sponsor

Base Salary

$143k - $304k/yr

Responsibilities

  • Execute full-scope CyberShield red team operations, including initial access, privilege escalation, lateral movement, persistence, objective completion, and reporting.
  • Develop custom tooling, implants, and tradecraft to evade defenses and emulate advanced adversaries.
  • Design, direct, and supervise AI agents for reconnaissance, vulnerability discovery, exploitation, and post-exploitation with defined guardrails and human-in-the-loop checkpoints.
  • Identify and exploit vulnerabilities across application, cloud, identity, network, hardware, endpoint, and operational security layers.
  • Serve as a forward-deployed technical lead by briefing CISOs and security leaders and translating findings into business-impact narratives and defensive guidance.
  • Prototype and productionize offensive tools, agents, and techniques and provide requirements to the offensive AI platform engineering team.
  • Collaborate with Blue Teams, GHOST, MSTIC, and internal service teams to improve hardening, detection, and defender readiness.
  • Set CyberShield operational standards and playbooks, mentor operators, and advocate for security improvements.

Requirements

  • Master's degree in Statistics, Mathematics, Computer Science, or a related field plus 4+ years of security or related experience, or bachelor's degree in one of those fields plus 6+ years of experience, or equivalent experience.
  • Ability to pass Microsoft Cloud, customer, and/or government security screening requirements.
  • Preferred: master's degree plus 8+ years or bachelor's degree plus 12+ years of security or related experience, or equivalent experience.
  • 6+ years planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling.
  • 8+ years identifying and exploiting vulnerabilities across Azure, AWS, GCP, Entra ID or Active Directory, Windows, Linux, networks, and hardware.
  • Experience designing multi-agent or autonomous systems using large language models, including orchestration, tool use, evaluation, and safety guardrails.
  • 6+ years coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, or Rust, including offensive tooling development and maintenance.
  • Experience delivering red team results to executive audiences in customer-facing or consulting roles.
  • Blue team, detection engineering, or incident response experience.
  • Familiarity with MITRE ATT&CK, threat-informed defense, and frameworks such as TIBER-EU, CBEST, and DORA.
  • Recognized security-community contributions such as research, open-source tooling, conference talks, or CVEs; active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.

Tech Stack

Categories

Microsoft

About Microsoft

10,000+ employees

Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.

Contact me