Microsoft

Principal Security Engineer

Microsoft
Apply
7 days ago
Remote, United StatesStaff+
H1B sponsor

Base Salary

$143k - $304k/yr

Responsibilities

  • Execute full-scope CyberShield red team operations, including initial access, privilege escalation, lateral movement, persistence, objective completion, and reporting.
  • Develop custom tooling, implants, and tradecraft to evade defenses and emulate advanced adversaries.
  • Design, direct, and supervise AI agents for reconnaissance, vulnerability discovery, exploitation, and post-exploitation with guardrails and human-in-the-loop checkpoints.
  • Discover and exploit vulnerabilities across application, cloud, identity, network, hardware, and operational security layers.
  • Lead customer-facing technical engagements, brief CISOs and security leaders, and provide actionable defensive engineering guidance.
  • Prototype and productionize offensive tools, agents, and techniques, and provide requirements to the offensive AI platform engineering team.
  • Collaborate with blue teams, GHOST, MSTIC, and Microsoft service teams to improve hardening and defender readiness.
  • Set engagement standards and playbooks, mentor operators, and communicate security risk to Microsoft and customer stakeholders.

Requirements

  • Bachelor's degree in Statistics, Mathematics, Computer Science, or a related field plus 6+ years of security or related experience, or a master's degree plus 4+ years, or equivalent experience.
  • Ability to pass Microsoft Cloud, customer, and/or government security screening requirements.
  • Preferred qualifications include a master's degree plus 8+ years or bachelor's degree plus 12+ years of security or related experience, or equivalent experience.
  • 6+ years planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
  • 8+ years identifying and exploiting vulnerabilities across Azure, AWS, GCP, Entra ID, Active Directory, Windows, Linux, networks, and hardware.
  • Experience designing multi-agent or autonomous systems using large language models, including orchestration, tool use, evaluation, and safety guardrails.
  • 6+ years coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, or Rust, including offensive tooling development and maintenance.
  • Customer-facing or consulting experience delivering red team results to executive audiences.
  • Blue team, detection engineering, or incident response experience, plus familiarity with MITRE ATT&CK, threat-informed defense, and frameworks such as TIBER-EU, CBEST, and DORA.
  • Recognized security community contributions such as research, open-source tooling, conference talks, or CVEs; active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus.

Benefits

  • The role may be eligible for benefits and other compensation.
  • The position is open for at least five days, with applications accepted on an ongoing basis until filled.

Tech Stack

Categories

Microsoft

About Microsoft

10,000+ employees

Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.

Contact me