EngineerJobs.io
← Back to all jobs

Job Description

The Principal Security Engineer serves as a principal-level operator for CyberShield, planning and executing end-to-end adversary emulation while leading agentic, AI-driven red team operations. This forward-deployed role supports defenders by partnering with customer and internal security organizations to improve threat detection, investigation quality, and security hardening.

Responsibilities

  • Execute CyberShield red team operations end-to-end, including initial access, privilege escalation, lateral movement and pivoting, persistence, objective completion, and reporting, against Microsoft’s own environment and select external customer environments.
  • Validate detection, investigation, and response using real-world adversary tactics, techniques, and procedures.
  • Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate advanced adversary capabilities.
  • Lead agentic red team operations by designing and directing AI agents that autonomously perform reconnaissance, vulnerability discovery, exploitation, and post-exploitation. Define guardrails, oversight, and human-in-the-loop checkpoints to enable a shift from human-led execution to continuous software-driven, agentic analysis.
  • Discover and exploit vulnerabilities end-to-end across application, cloud, identity, network, hardware, and operational security layers, chaining findings into realistic attack paths that show business impact.
  • Act as a forward-deployed technical lead with customers, including briefing CISOs and security leaders, translating findings into actionable narratives, and delivering lightweight defensive engineering guidance alongside offensive results.
  • Prototype and productionize tools, agents, and techniques that scale offensive emulation and vulnerability discovery, and feed what works back to the offensive AI platform engineering team.
  • Collaborate with Blue Teams, GHOST (Microsoft adversary hunting), MSTIC (Microsoft Threat Intelligence Center), and internal Microsoft service teams to convert findings into product hardening and improved defender readiness.
  • Set operational standards and playbooks for CyberShield engagements, including mentoring senior operators and virtual-team specialists drawn from across MRT.
  • Advocate for security change across Microsoft and its customers by building partnerships and clearly communicating the impact of risk.
  • Embody Microsoft’s Culture and Values.

Required Qualifications

  • Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field
    OR
    Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
    OR
    equivalent experience.
  • Ability to meet Microsoft, customer and/or government security screening requirements for the role, including the Microsoft Cloud Background Check (required to pass upon hire/transfer and every two years thereafter) and possible additional customer- or government-directed vetting.

Technologies

  • Python, C#, C++, Go, PowerShell, .NET, Rust
  • Azure, AWS, GCP
  • Entra ID, Active Directory
  • Windows, Linux
  • MITRE ATT&CK, TIBER-EU, CBEST, DORA

Additional / Preferred Qualifications

  • Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field
    OR
    Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in security or related field
    OR
    equivalent experience.
  • 6+ years of experience planning and leading red team or adversary emulation operations against enterprise or cloud environments.
  • Demonstrated hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
  • Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus, enabling immediate work with the most sensitive customers.
  • 8+ years of experience identifying and exploiting security vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware.
  • Experience designing multi-agent or autonomous systems using large language models, including orchestration frameworks, tool use, agent evaluation, and safety guardrails applied to offensive security.
  • 6+ years of experience with coding or scripting in Python, C#, C++, Go, PowerShell, .NET, Rust, or comparable programming languages, including building and maintaining offensive tooling.
  • Experience in customer-facing or consulting roles delivering red team results to executive audiences, with the ability to move between deep technical detail and business impact.
  • Blue team, detection engineering, or incident response experience.
  • Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (e.g., TIBER-EU, CBEST, DORA).
  • Recognized contributions to the security community, such as research, open-source tooling, conference talks, or CVEs.

Position Details

  • Location: United States (onsite)
  • Compensation: USD 142,800 - 304,200 per year
  • Minimum Experience: 4 years
  • Role Focus: CyberShield adversary emulation and agentic, AI-driven red team operations

Similar Jobs