The Microsoft Red Team (MRT) attacks Microsoft services and technologies to identify critical and systemic security risks, demonstrate authentic attack paths, and help engineering teams, investigators, and incident responders improve their ability to protect, detect, investigate, and respond to real attacks. Red Team operations create a unique security engineering challenge. Authorized operators use many of the same techniques as sophisticated adversaries across complex cloud, identity, endpoint, network, and application environments. Microsoft must be able to observe those operations, protect and manage the infrastructure that enables them, and distinguish authorized activity from genuine adversary activity without weakening either offensive realism or defensive response. As a Principal Security Architect in Microsoft Red Team Engineering, you will serve as the “blue team to the Red Team.” You will set technical direction and deliver critical capabilities that make Red Team operations observable, secure, reliable, and safely distinguishable from real attacks at scale. This is a Principal individual-contributor role focused on the telemetry, detections, monitoring, deconfliction, and operational infrastructure surrounding Red Team engagements, rather than on executing the engagements themselves. You will work at the intersection of offense and defense, partnering closely with Red Team operators, software engineers, detection engineers, security researchers, threat intelligence, incident response, and platform and telemetry teams across Microsoft. As a peer to Red Team operators, you will define what effective visibility looks like for adversarial operations, drive the right telemetry into centralized monitoring, and design and implement detections that distinguish authorized operations from real attacks using the same tradecraft. You will shape the architecture and strategy for Red Team telemetry, monitoring, detection, alerting, deconfliction, and operational security, while working with engineers and partner teams to turn that strategy into durable production capabilities. The role requires deep security expertise, strong software and systems engineering judgment, and the ability to move between architecture and implementation, solve ambiguous cross-organization problems, and enable others to deliver at greater scale.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Principal