CybersecurityJobs.io
← Back to all jobs

Job Description

Principal-level operator role focused on planning and executing end-to-end adversary emulation and leading agentic, AI-driven red team operations.

  • Own end-to-end CyberShield red team engagements covering initial access, privilege escalation, lateral movement and pivoting, persistence, objective completion, and reporting
  • Validate detection, investigation, and response using real-world adversary tactics, techniques, and procedures across Microsoft’s own environment and selected external customer environments
  • Build custom tooling and tradecraft (including implants) to evade modern defenses and emulate advanced adversary capabilities
  • Lead agentic red team operations by designing and directing AI agents that autonomously handle reconnaissance, vulnerability discovery, exploitation, and post-exploitation
  • Define guardrails, oversight, and human-in-the-loop checkpoints for autonomous execution
  • Drive the shift from human-led execution to continuous, software-driven, agentic analysis
  • Discover and exploit vulnerabilities end-to-end across application, cloud, identity, network, hardware, and operational security layers
  • Chain findings into realistic attack paths that demonstrate business impact
  • Serve as forward-deployed technical lead with customers by briefing CISOs and security leaders, translating findings into actionable narratives, and delivering lightweight defensive engineering guidance
  • Prototype and productionize tools, agents, and techniques that scale offensive emulation and vulnerability discovery
  • Feed requirements back to the offensive AI platform engineering team based on what works in real environments
  • Collaborate with Blue Teams, GHOST (adversary hunting and response), MSTIC (threat intelligence), and internal service teams to convert findings into product hardening and improved defender readiness
  • Set operational standards and playbooks for CyberShield engagements
  • Mentor senior operators and virtual-team specialists drawn from across MRT
  • Advocate for security change across Microsoft and customers through partnerships and clear communication of risk impact
  • Embody the company Culture and Values

Requirements

  • Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field
  • OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
  • OR equivalent experience
  • Ability to meet Microsoft, customer, and/or government security screening requirements, including but not limited to Microsoft Cloud Background Check (required to pass upon hire/transfer and every two years thereafter)
  • Possible additional customer- or government-directed vetting

Additional or Preferred Qualifications

  • Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field
  • OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in security or related field
  • OR equivalent experience
  • 6+ years planning and leading red team or adversary emulation operations against enterprise or cloud environments
  • Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations
  • Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus
  • 8+ years identifying and exploiting vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware
  • Experience designing multi-agent or autonomous systems using large language models, including orchestration frameworks, tool use, agent evaluation, and safety guardrails applied to offensive security
  • 6+ years coding or scripting with Python, C#, C++, Go, PowerShell, .NET, Rust, or comparable languages, including building and maintaining offensive tooling
  • Customer-facing or consulting experience delivering red team results to executive audiences, with ability to connect technical detail to business impact
  • Blue team, detection engineering, or incident response experience
  • Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (TIBER-EU, CBEST, DORA)
  • Recognized community contributions such as research, open-source tooling, conference talks, or CVEs

Technologies

  • Python
  • C#
  • C++
  • Go
  • PowerShell
  • .NET
  • Rust
  • Azure
  • AWS
  • GCP
  • Entra ID
  • Active Directory
  • Windows
  • Linux
  • MITRE ATT&CK
  • TIBER-EU
  • CBEST
  • DORA

Location: United States (onsite)

Salary range: USD 142,800 - 304,200 per year

Experience minimum: 4 years

Education: Master’s Degree in Statistics, Mathematics, Computer Science, or related field

Similar Jobs