7 days ago
Base Salary
$166k - $331k/yr
Responsibilities
- Execute end-to-end red team and adversary emulation operations across Microsoft and selected customer environments.
- Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate advanced adversaries.
- Design, direct, and supervise AI-driven agents for reconnaissance, vulnerability discovery, exploitation, and post-exploitation.
- Identify and chain vulnerabilities across application, cloud, identity, network, hardware, and operational security layers.
- Serve as a forward-deployed technical lead by briefing CISOs and security leaders and delivering actionable defensive guidance.
- Prototype and productionize offensive security tools, agents, and techniques for continuous emulation and vulnerability discovery.
- Collaborate with blue teams, GHOST, MSTIC, and internal service teams to improve hardening and defender readiness.
- Set CyberShield operational standards and playbooks, mentor operators, and communicate security risk to stakeholders.
Requirements
- A master's degree in Statistics, Mathematics, Computer Science, or a related field plus 6+ years of security or related experience, or a bachelor's degree in one of those fields plus 8+ years of experience, or equivalent experience.
- Ability to pass Microsoft Cloud Background Checks and any required customer or government security screenings.
- Preferred experience includes 6+ years planning and leading red team or adversary emulation operations against enterprise or cloud environments.
- Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
- Experience identifying and exploiting vulnerabilities across Azure, AWS, GCP, Entra ID, Active Directory, Windows, Linux, network, and hardware environments.
- Experience designing multi-agent or autonomous systems using large language models, including orchestration, tool use, evaluation, and safety guardrails.
- 6+ years of coding or scripting experience with languages such as Python, C#, C++, Go, PowerShell, .NET, or Rust, including offensive tooling development.
- Customer-facing or consulting experience delivering red team results to executive audiences.
- Blue team, detection engineering, or incident response experience.
- Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks such as TIBER-EU, CBEST, and DORA.
- Recognized security community contributions such as research, open-source tooling, conference talks, or CVEs; an active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.
Benefits
- The role may be eligible for benefits and other compensation.
- Applicants must meet Microsoft, customer, and/or government security screening requirements, including recurring Microsoft Cloud Background Checks and possible additional customer or government vetting.
- The position is open for a minimum of 5 days, with applications accepted on an ongoing basis until filled.
Categories
About Microsoft
Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.
