Principal Security Engineer
Active Directory
Agent
Agentic Ai Security
Ai Security
Application Security
Azure
Cbest
Cloud Native
Cloud Operations
Cloud Platform
Cloud Platforms
Cloud Platforms Cloud Platforms
Cybersecurity Tools
Data Security
Dora
Engineer
Engineering
Google Cloud
Identity and Access Management
Information Security
InfoSec
Mitre Att&ck
Offensive Security
Project Management
Risk Management
Security
Security Automation
Security Operations
Security Testing
Software Engineering
Software Security
Technical Lead
Tiber Eu
Job Description
Principal-level operator role focused on planning and executing end-to-end adversary emulation and leading agentic, AI-driven red team operations.
- Own end-to-end CyberShield red team engagements covering initial access, privilege escalation, lateral movement and pivoting, persistence, objective completion, and reporting
- Validate detection, investigation, and response using real-world adversary tactics, techniques, and procedures across Microsoft’s own environment and selected external customer environments
- Build custom tooling and tradecraft (including implants) to evade modern defenses and emulate advanced adversary capabilities
- Lead agentic red team operations by designing and directing AI agents that autonomously handle reconnaissance, vulnerability discovery, exploitation, and post-exploitation
- Define guardrails, oversight, and human-in-the-loop checkpoints for autonomous execution
- Drive the shift from human-led execution to continuous, software-driven, agentic analysis
- Discover and exploit vulnerabilities end-to-end across application, cloud, identity, network, hardware, and operational security layers
- Chain findings into realistic attack paths that demonstrate business impact
- Serve as forward-deployed technical lead with customers by briefing CISOs and security leaders, translating findings into actionable narratives, and delivering lightweight defensive engineering guidance
- Prototype and productionize tools, agents, and techniques that scale offensive emulation and vulnerability discovery
- Feed requirements back to the offensive AI platform engineering team based on what works in real environments
- Collaborate with Blue Teams, GHOST (adversary hunting and response), MSTIC (threat intelligence), and internal service teams to convert findings into product hardening and improved defender readiness
- Set operational standards and playbooks for CyberShield engagements
- Mentor senior operators and virtual-team specialists drawn from across MRT
- Advocate for security change across Microsoft and customers through partnerships and clear communication of risk impact
- Embody the company Culture and Values
Requirements
- Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in security or related field
- OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
- OR equivalent experience
- Ability to meet Microsoft, customer, and/or government security screening requirements, including but not limited to Microsoft Cloud Background Check (required to pass upon hire/transfer and every two years thereafter)
- Possible additional customer- or government-directed vetting
Additional or Preferred Qualifications
- Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field
- OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in security or related field
- OR equivalent experience
- 6+ years planning and leading red team or adversary emulation operations against enterprise or cloud environments
- Hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations
- Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus
- 8+ years identifying and exploiting vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware
- Experience designing multi-agent or autonomous systems using large language models, including orchestration frameworks, tool use, agent evaluation, and safety guardrails applied to offensive security
- 6+ years coding or scripting with Python, C#, C++, Go, PowerShell, .NET, Rust, or comparable languages, including building and maintaining offensive tooling
- Customer-facing or consulting experience delivering red team results to executive audiences, with ability to connect technical detail to business impact
- Blue team, detection engineering, or incident response experience
- Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (TIBER-EU, CBEST, DORA)
- Recognized community contributions such as research, open-source tooling, conference talks, or CVEs
Technologies
- Python
- C#
- C++
- Go
- PowerShell
- .NET
- Rust
- Azure
- AWS
- GCP
- Entra ID
- Active Directory
- Windows
- Linux
- MITRE ATT&CK
- TIBER-EU
- CBEST
- DORA
Location: United States (onsite)
Salary range: USD 142,800 - 304,200 per year
Experience minimum: 4 years
Education: Master’s Degree in Statistics, Mathematics, Computer Science, or related field