Principal Penetration Tester
Microsoft
Principal Penetration Tester
Multiple Locations, United States
Save
Overview
Team Description:
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
The Security Engineering team within Microsoft Security helps to identify threats and gaps in the very tools that protect the planet's largest, most influential organizations from cyberattacks.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Qualifications
Required Qualifications
- 7+ years’ experience in identifying security vulnerabilities, software development lifecycle, large-scale computing, modeling, cyber security, and anomaly detection.
- At least 7 years of experience in penetration testing, red teaming, identifying or offensive security
- Deep understanding of OWASP Top 10, fuzz testing, port scanning, and exploit development
- Experience with cloud platforms (Azure preferred), identity systems, and large-scale distributed systems.
Preferred Qualifications
- Experience in leading offensive security teams, especially in cross functional organizations
- Experience working with AI Red Teams on AI platform and agent testing
- Experience with regulatory frameworks and compliance-driven testing (e.g., FedRAMP, DORA)
- Strong communication skills and ability to influence engineering and executive stakeholders
Penetration Testing IC5 - The typical base pay range for this role across the U.S. is USD $139,900 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications and processes offers for these roles on an ongoing basis.
#MSFTSecurity #MSFTSecurity #MSFTSecurity #PenetrationTesting #Pentest #CybersecurityCareers #RedTeamJobs #SecurityEngineering #EthicalHackingJobs
"Ability to meet Microsoft, customer, and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter."
Responsibilities
As a Principal Penetration Tester, you will lead offensive security engagements that simulate real-world attacks on Microsoft Security’s products, services, and infrastructure. You will be responsible for identifying systemic vulnerabilities across application, network, cloud and operational domains, and for partnering with engineering and security teams to drive remediation at scale. This role is critical to ensuring the security of Microsoft’s entire security suite.
Additionally, as a senior member of the team, you will be responsible for fostering the team's growth both technically and culturally, as we build and retain the next generation of top talent at Microsoft.