Microsoft Logo

Microsoft

Principal Security Architect

Reposted 10 Hours Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
143K-304K Annually
Senior level
In-Office or Remote
Hiring Remotely in United States
143K-304K Annually
Senior level
Leads architecture and implementation of Microsoft Red Team visibility, telemetry, monitoring, detection, alerting, deconfliction, and operational security capabilities. Designs scalable services and data pipelines, maintains authoritative operational asset inventories, identifies systemic security gaps, and drives durable engineering solutions. Provides hands-on technical leadership, architecture reviews, debugging, incident response, mentorship, and cross-organizational influence while enabling authentic Red Team operations with strong defensive visibility and control.
The summary above was generated by AI
Overview

The Microsoft Red Team (MRT) attacks Microsoft services and technologies to identify critical and systemic security risks, demonstrate authentic attack paths, and help engineering teams, investigators, and incident responders improve their ability to protect, detect, investigate, and respond to real attacks.

Red Team operations create a unique security engineering challenge. Authorized operators use many of the same techniques as sophisticated adversaries across complex cloud, identity, endpoint, network, and application environments. Microsoft must be able to observe those operations, protect and manage the infrastructure that enables them, and distinguish authorized activity from genuine adversary activity without weakening either offensive realism or defensive response.

As a Principal Security Architect in Microsoft Red Team Engineering, you will serve as the “blue team to the Red Team.” You will set technical direction and deliver critical capabilities that make Red Team operations observable, secure, reliable, and safely distinguishable from real attacks at scale. This is a Principal individual-contributor role focused on the telemetry, detections, monitoring, deconfliction, and operational infrastructure surrounding Red Team engagements, rather than on executing the engagements themselves.

You will work at the intersection of offense and defense, partnering closely with Red Team operators, software engineers, detection engineers, security researchers, threat intelligence, incident response, and platform and telemetry teams across Microsoft. As a peer to Red Team operators, you will define what effective visibility looks like for adversarial operations, drive the right telemetry into centralized monitoring, and design and implement detections that distinguish authorized operations from real attacks using the same tradecraft.

You will shape the architecture and strategy for Red Team telemetry, monitoring, detection, alerting, deconfliction, and operational security, while working with engineers and partner teams to turn that strategy into durable production capabilities. The role requires deep security expertise, strong software and systems engineering judgment, and the ability to move between architecture and implementation, solve ambiguous cross-organization problems, and enable others to deliver at greater scale.


Responsibilities

•    Define and drive the technical strategy and architecture for Red Team visibility, telemetry, detection, deconfliction, and operational security.
•    Use live Red Team operations, security incidents, threat intelligence, and adversary activity to identify systemic visibility and control gaps and translate them into prioritized engineering investments.
•    Architect and build scalable services and data pipelines that collect, normalize, enrich, and correlate Red Team telemetry to make the right signals available to defenders.
•    Drive the development of monitoring, hunting, detection, and alerting capabilities that help contextualize Red Team activity, identify unexpected or unauthorized behavior, and distinguish authorized operations from genuine adversary activity.
•    Build durable deconfliction capabilities that combine operational context, asset and identity information, infrastructure signals, and behavioral telemetry while protecting sensitive Red Team information.
•    Own and evolve the authoritative inventory of Red Team operational assets, ensuring infrastructure, tooling, identities, and related metadata are accurate, automated, auditable, and usable by monitoring and deconfliction systems.
•    Raise the engineering bar across Red Team systems through strong patterns for testing, reliability, observability, secure development, deployment, and infrastructure lifecycle management.
•    Provide hands-on technical leadership through architecture, implementation, reviews, debugging, operational response, and mentorship, while influencing engineering teams and roadmaps across Microsoft.
•    Help ensure Microsoft can conduct authentic Red Team operations with strong visibility, control, and confidence in its defensive response.


Qualifications
Required/minimum qualifications
  • Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
Other Requirements
  • Ability to meet Microsoft, customer, and/or government security screening requirements is required for this role. These requirements include, but are not limited to the following specialized security screenings: 
    • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.  
Additional or preferred qualifications
  • Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
  • Experience in cybersecurity, including one or more areas such as security telemetry, detection engineering, security monitoring, incident response, threat analytics, cloud security, identity security, endpoint security, or offensive security infrastructure.
  • Experience designing distributed services, data pipelines, automation, or large-scale security platforms.
  • Demonstrated ability to set technical direction in ambiguous problem spaces, identify systemic risks, and translate complex security challenges into durable engineering solutions.
  • Proven ability to influence architecture, priorities, and execution across multiple teams and organizations, and to communicate effectively with engineers, security practitioners, and senior technical leaders.

Software Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Similar Jobs

26 Days Ago
Remote
Minnesota, USA
111K-221K Annually
Expert/Leader
111K-221K Annually
Expert/Leader
Healthtech • Logistics • Pharmaceutical
Defines and governs enterprise cybersecurity architecture across cloud, infrastructure, applications, data, AI, identity, and cyber defense. Establishes security principles, reference architectures, standards, roadmaps, and Zero Trust patterns; influences technology strategy, architecture decisions, modernization, integrations, and build-versus-buy choices. Partners with engineering, enterprise architecture, risk, legal, and business teams to implement scalable security capabilities, improve resilience, reduce architectural complexity, and address emerging threats across complex enterprise environments.
Top Skills: APIsAWSAws Well-Architected FrameworkAzureCi/CdCis ControlsCloud Security AllianceDevsecopsDlpEncryptionGCPGenerative AiGoogle Cloud Architecture FrameworkHitrustIamInfrastructure-As-CodeIso/Iec 27001Key ManagementKubernetesMachine LearningMicrosoft Azure Well-Architected FrameworkNist Cybersecurity FrameworkNist Sp 800-53Ot/IotOwaspRagSaaSServerlessTokenizationZero Trust
6 Days Ago
Remote
United States
135K-216K Annually
Expert/Leader
135K-216K Annually
Expert/Leader
Aerospace • Information Technology • Security • Cybersecurity • Defense
Leads OT/ICS and enterprise cybersecurity architecture for a federal critical-infrastructure modernization program. Responsibilities include requirements development, NERC CIP traceability, market research, RFI and vendor evaluation, lab testing, alternatives analysis, product recommendations, and executive briefings. The role bridges utility operational technology and IT security, covering access control, monitoring, asset management, vulnerability management, SCADA environments, and industrial systems. It is fully remote in the U.S. with up to 25% domestic travel and requires Public Trust eligibility.
Top Skills: Cisa Zero Trust ArchitectureConfiguration ManagementCyber-Asset ManagementData DiodesDodafEnterprise It CybersecurityFismaIcsIdentity And Access ManagementIndustrial ProtocolsLog MonitoringNerc CipNetwork MonitoringNist RmfOtPacket CapturePatch ManagementPivPrivileged Access ManagementProtective RelaysRtusScadaThreat VisibilityVulnerability Management
One Month Ago
Remote or Hybrid
United States
162K-273K Annually
Expert/Leader
162K-273K Annually
Expert/Leader
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead the development of SailPoint’s cybersecurity architecture practice. Create holistic and reference architectures, define security domains, develop strategic roadmaps, identify security gaps, and translate architectural concepts into viable engineering solutions. Partner with leadership to prioritize initiatives, secure funding, and operationalize the practice. The role also includes hands-on security projects, cross-functional collaboration, stakeholder influence, and mentoring architects and engineers across cloud, application, identity, and network security.
Top Skills: AgileApplication SecurityCloud SecurityEnterprise ArchitectureIdentity SecurityIsoNetwork SecurityNistSabsaSecurity Engineering

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account