Microsoft
Principal Security Engineer
Microsoft is hiring a Principal Security Engineer in US. Posted September 16, 2026.
Job at a glance
- Company
- Microsoft
- Location
- US
- Workplace
- On-site
- Employment
- Full-time
- Sector
- Engineering & Technology
- Posted
- September 16, 2026
- Apply by
- March 15, 2027
About the job
Develop custom tooling, implants, and tradecraft to evade modern defenses and emulate the capabilities of advanced adversaries. Lead agentic red team operations: design and direct AI agents that autonomously perform reconnaissance, vulnerability discovery, exploitation, and post-exploitation; define guardrails, oversight, and human-in-the-loop checkpoints; and drive the shift from human-led execution to continuous, software-driven, agentic analysis. Discover and exploit vulnerabilities end-to-end across application, cloud, identity, network, hardware, and operational security layers, chaining findings into realistic attack paths that demonstrate business impact. Serve as the forward-deployed technical lead with customers: brief CISOs and security leaders, translate findings into actionable narratives, and deliver lightweight defensive engineering guidance alongside offensive results. Prototype and productionize tools, agents, and techniques that scale offensive emulation and vulnerability discovery, and feed requirements back to our offensive AI platform engineering team based on what works in real environments. Set operational standards and playbooks for CyberShield engagements; mentor senior operators and virtual-team specialists drawn from across MRT. Embody our Culture and Values. Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field OR equivalent experience. Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in security or related field OR equivalent experience. 6+ years of experience planning and leading red team or adversary emulation operations against enterprise or cloud environments. Demonstrated hands-on experience building, directing, or operating AI-driven or agentic offensive security tooling in real operations. Active U.S. Government TS//SCI clearance with full-scope polygraph is a strong plus, enabling immediate work with our most sensitive customers. 8+ years of experience identifying and exploiting security vulnerabilities across cloud (Azure, AWS, GCP), identity (Entra ID / Active Directory), Windows and Linux endpoints, network, and hardware. Experience designing multi-agent or autonomous systems using large language models - orchestration frameworks, tool use, agent evaluation, and safety guardrails - applied to offensive security. 6+ years of experience with coding or scripting in languages such as Python, C#, C++, Go, PowerShell, .NET, Rust, or other comparable programming languages, including building and maintaining offensive tooling. Experience in customer-facing or consulting roles delivering red team results to executive audiences; ability to move fluently between deep technical detail and business impact. Blue team, detection engineering, or incident response experience - you understand how defenders think and can help them get better. Familiarity with MITRE ATT&CK, threat-informed defense, and regulated red team frameworks (e.g., TIBER-EU, CBEST, DORA). Recognized contributions to the security community: research, open-source tooling, conference talks, or CVEs.