Microsoft

Principal Security Engineer

Microsoft
Apply
7 days ago
Remote, United StatesStaff+
H1B sponsor

Base Salary

$166k - $331k/yr

Responsibilities

  • Execute end-to-end red team and adversary emulation operations across Microsoft and selected customer environments.
  • Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate advanced adversaries.
  • Design, direct, and supervise AI-driven agents for reconnaissance, vulnerability discovery, exploitation, and post-exploitation.
  • Identify and chain vulnerabilities across application, cloud, identity, network, hardware, and operational security layers.
  • Serve as a forward-deployed technical lead by briefing CISOs and security leaders and delivering actionable defensive guidance.
  • Prototype and productionize offensive security tools, agents, and techniques for continuous emulation and vulnerability discovery.
  • Collaborate with blue teams, GHOST, MSTIC, and internal service teams to improve hardening and defender readiness.
  • Set CyberShield operational standards and playbooks, mentor operators, and communicate security risk to stakeholders.

Requirements

  • A master's degree in Statistics, Mathematics, Computer Science, or a related field plus 6+ years of security or related experience, or a bachelor's degree in one of those fields plus 8+ years of experience, or equivalent experience.
  • Ability to pass Microsoft Cloud Background Checks and any required customer or government security screenings.
  • Preferred experience includes 6+ years planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
  • Experience identifying and exploiting vulnerabilities across Azure, AWS, GCP, Entra ID, Active Directory, Windows, Linux, network, and hardware environments.
  • Experience designing multi-agent or autonomous systems using large language models, including orchestration, tool use, evaluation, and safety guardrails.
  • 6+ years of coding or scripting experience with languages such as Python, C#, C++, Go, PowerShell, .NET, or Rust, including offensive tooling development.
  • Customer-facing or consulting experience delivering red team results to executive audiences.
  • Blue team, detection engineering, or incident response experience.
  • Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks such as TIBER-EU, CBEST, and DORA.
  • Recognized security community contributions such as research, open-source tooling, conference talks, or CVEs; an active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.

Benefits

  • The role may be eligible for benefits and other compensation.
  • Applicants must meet Microsoft, customer, and/or government security screening requirements, including recurring Microsoft Cloud Background Checks and possible additional customer or government vetting.
  • The position is open for a minimum of 5 days, with applications accepted on an ongoing basis until filled.

Tech Stack

Categories

Microsoft

About Microsoft

10,000+ employees

Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.

Contact me