Skip to content

Open nowPosted 41 hours ago

Principal Security Architect

Microsoft563 open roles

Pay
$142,800 – $274,800 a year
Where
Redmond, WA, United States, United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Security ArchitectMicrosoft · Redmond, WA, United States, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Microsoft's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Microsoft postings stay open a median of 25 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.9%7 days
  4. 14.2%14 days
  5. 34.1%30 days
This job: posted 41 hours ago

Microsoft median: 25 days open

The posting

Overview

The Microsoft Red Team (MRT) attacks Microsoft services and technologies to identify critical and systemic security risks, demonstrate authentic attack paths, and help engineering teams, investigators, and incident responders improve their ability to protect, detect, investigate, and respond to real attacks.

Red Team operations create a unique security engineering challenge. Authorized operators use many of the same techniques as sophisticated adversaries across complex cloud, identity, endpoint, network, and application environments. Microsoft must be able to observe those operations, protect and manage the infrastructure that enables them, and distinguish authorized activity from genuine adversary activity without weakening either offensive realism or defensive response.

As a Principal Security Architect in Microsoft Red Team Engineering, you will serve as the “blue team to the Red Team.” You will set technical direction and deliver critical capabilities that make Red Team operations observable, secure, reliable, and safely distinguishable from real attacks at scale. This is a Principal individual-contributor role focused on the telemetry, detections, monitoring, deconfliction, and operational infrastructure surrounding Red Team engagements, rather than on executing the engagements themselves.

You will work at the intersection of offense and defense, partnering closely with Red Team operators, software engineers, detection engineers, security researchers, threat intelligence, incident response, and platform and telemetry teams across Microsoft. As a peer to Red Team operators, you will define what effective visibility looks like for adversarial operations, drive the right telemetry into centralized monitoring, and design and implement detections that distinguish authorized operations from real attacks using the same tradecraft.

You will shape the architecture and strategy for Red Team telemetry, monitoring, detection, alerting, deconfliction, and operational security, while working with engineers and partner teams to turn that strategy into durable production capabilities. The role requires deep security expertise, strong software and systems engineering judgment, and the ability to move between architecture and implementation, solve ambiguous cross-organization problems, and enable others to deliver at greater scale.

Responsibilities

• Define and drive the technical strategy and architecture for Red Team visibility, telemetry, detection, deconfliction, and operational security. • Use live Red Team operations, security incidents, threat intelligence, and adversary activity to identify systemic visibility and control gaps and translate them into prioritized engineering investments. • Architect and build scalable services and data pipelines that collect, normalize, enrich, and correlate Red Team telemetry to make the right signals available to defenders. • Drive the development of monitoring, hunting, detection, and alerting capabilities that help contextualize Red Team activity, identify unexpected or unauthorized behavior, and distinguish authorized operations from genuine adversary activity. • Build durable deconfliction capabilities that combine operational context, asset and identity information, infrastructure signals, and behavioral telemetry while protecting sensitive Red Team information. • Own and evolve the authoritative inventory of Red Team operational assets, ensuring infrastructure, tooling, identities, and related metadata are accurate, automated, auditable, and usable by monitoring and deconfliction systems. • Raise the engineering bar across Red Team systems through strong patterns for testing, reliability, observability, secure development, deployment, and infrastructure lifecycle management. • Provide hands-on technical leadership through architecture, implementation, reviews, debugging, operational response, and mentorship, while influencing engineering teams and roadmaps across Microsoft. • Help ensure Microsoft can conduct authentic Red Team operations with strong visibility, control, and confidence in its defensive response.

Qualifications

Required/minimum qualifications

  • Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.

Other Requirements

  • Ability to meet Microsoft, customer, and/or government security screening requirements is required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.

Additional or preferred qualifications

  • Master's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR Bachelor's Degree in Computer Science or related technical field AND 12+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience.
  • Experience in cybersecurity, including one or more areas such as security telemetry, detection engineering, security monitoring, incident response, threat analytics, cloud security, identity security, endpoint security, or offensive security infrastructure.
  • Experience designing distributed services, data pipelines, automation, or large-scale security platforms.
  • Demonstrated ability to set technical direction in ambiguous problem spaces, identify systemic risks, and translate complex security challenges into durable engineering solutions.
  • Proven ability to influence architecture, priorities, and execution across multiple teams and organizations, and to communicate effectively with engineers, security practitioners, and senior technical leaders.

Software Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Microsoft's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Microsoft's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Microsoft's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.