Principal Security Engineer
Active Directory
Agent
Agentic Ai Security
Ai Security
Application Security
Azure
Cbest
Cloud Native
Cloud Operations
Cloud Platform
Cloud Platforms
Cloud Platforms Cloud Platforms
Cybersecurity Tools
Data Security
Dora
Engineering
Google Cloud
Identity and Access Management
Information Security
InfoSec
Mitre Att&ck
Offensive Security
Project Management
Risk Management
Security
Security Automation
Security Operations
Security Testing
Software Engineering
Software Security
Technical Lead
Tiber Eu
Job Description
The Principal Security Engineer serves as a principal-level operator for CyberShield, planning and executing end-to-end adversary emulation while leading agentic, AI-driven red team operations. This forward-deployed role supports defenders by partnering with customer and internal security organizations to improve threat detection, investigation quality, and security hardening.
Responsibilities
- Execute CyberShield red team operations end-to-end, including initial access, privilege escalation, lateral movement and pivoting, persistence, objective completion, and reporting, against Microsoft’s own environment and select external customer environments.
- Validate detection, investigation, and response using real-world adversary tactics, techniques, and procedures.
- Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate advanced adversary capabilities.
- Lead agentic red team operations by designing and directing AI agents that autonomously perform reconnaissance, vulnerability discovery, exploitation, and post-exploitation. Define guardrails, oversight, and human-in-the-loop checkpoints to enable a shift from human-led execution to continuous software-driven, agentic analysis.
- Discover and exploit vulnerabilities end-to-end across application, cloud, identity, network, hardware, and operational security layers, chaining findings into realistic attack paths that show business impact.
- Act as a forward-deployed technical lead with customers, including briefing CISOs and security leaders, translating findings into actionable narratives, and delivering lightweight defensive engineering guidance alongside offensive results.
- Prototype and productionize tools, agents, and techniques that scale offensive emulation and vulnerability discovery, and feed what works back to the offensive AI platform engineering team.
- Collaborate with Blue Teams, GHOST (Microsoft adversary hunting), MSTIC (Microsoft Threat Intelligence Center), and internal Microsoft service teams to convert findings into product hardening and improved defender readiness.
- Set operational standards and playbooks for CyberShield engagements, including mentoring senior operators and virtual-team specialists drawn from across MRT.
- Advocate for security change across Microsoft and its customers by building partnerships and clearly communicating the impact of risk.
- Embody Microsoft’s Culture and Values.
Required Qualifications
-
Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field
OR
Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
OR
equivalent experience. - Ability to meet Microsoft, customer and/or government security screening requirements for the role, including the Microsoft Cloud Background Check (required to pass upon hire/transfer and every two years thereafter) and possible additional customer- or government-directed vetting.
Technologies
- Python, C#, C++, Go, PowerShell, .NET, Rust
- Azure, AWS, GCP
- Entra ID, Active Directory
- Windows, Linux
- MITRE ATT&CK, TIBER-EU, CBEST, DORA
Additional / Preferred Qualifications
-
Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field
OR
Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in security or related field
OR
equivalent experience. - 6+ years of experience planning and leading red team or adversary emulation operations against enterprise or cloud environments.
- Demonstrated hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations.
- Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus, enabling immediate work with the most sensitive customers.
- 8+ years of experience identifying and exploiting security vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware.
- Experience designing multi-agent or autonomous systems using large language models, including orchestration frameworks, tool use, agent evaluation, and safety guardrails applied to offensive security.
- 6+ years of experience with coding or scripting in Python, C#, C++, Go, PowerShell, .NET, Rust, or comparable programming languages, including building and maintaining offensive tooling.
- Experience in customer-facing or consulting roles delivering red team results to executive audiences, with the ability to move between deep technical detail and business impact.
- Blue team, detection engineering, or incident response experience.
- Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (e.g., TIBER-EU, CBEST, DORA).
- Recognized contributions to the security community, such as research, open-source tooling, conference talks, or CVEs.
Position Details
- Location: United States (onsite)
- Compensation: USD 142,800 - 304,200 per year
- Minimum Experience: 4 years
- Role Focus: CyberShield adversary emulation and agentic, AI-driven red team operations