{"id":1965228,"url":"https://alion.io/job/microsoft-principal-security-operations-engineer-3","title":"Principal Security Operations Engineer","company":{"id":18,"name":"Microsoft","domain":"microsoft.com","url":"https://alion.io/company/microsoft","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Eightfold","truth_index":{"grade":"B","score":75,"open_postings":59,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-07T05:47:15Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":93500,"max":161800,"currency":"GBP","period":"year","gross":null,"usd_annual":214658},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"CI/CD","optional":false},{"name":"Defense in Depth","optional":false},{"name":"DNS","optional":false},{"name":"Function Calling","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM Evaluation","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"Tool Use","optional":false},{"name":"Azure","optional":true},{"name":"Docker","optional":true},{"name":"Kubernetes","optional":true},{"name":"Linux","optional":true},{"name":"Windows","optional":true},{"name":"Zero Trust","optional":true}],"status":"live","first_seen_at":"2026-09-24T23:20:14Z","employer_posted_date":"2026-10-06","last_verified_at":"2026-10-08T02:17:29Z","board_verified":true,"closed_at":null,"days_open":13,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":13},"description":"OverviewPrimary Charter\nDesign, build, and secure realistic, reproducible cyber ranges that enable rigorous offensive evaluations of frontier AI systems while safely containing model and agent activity.\nOverview\nThe Cloud & AI organization accelerates Microsoft’s mission to secure digital technology platforms, devices, clouds, and AI systems across customers’ heterogeneous environments and Microsoft’s own internal estate. Our culture is centered on a growth mindset, inspiring excellence, and helping teams and leaders bring their full potential every day.\nMicrosoft Red Team (MRT) emulates real-world advanced persistent threats against Microsoft and an ecosystem of external customers. As frontier AI systems become increasingly capable of reasoning, coding, tool use, exploitation, and autonomous execution, understanding when and how these systems materially increase offensive cyber capabilities is becoming an increasingly important component of Microsoft’s AI security mission.\nMRT Strategic AI is seeking an AI Security Engineer focused on Cyber Range Engineering. This is a hands-on systems and security engineering role responsible for designing, building, hardening, and operating realistic cyber ranges where frontier AI models and agents can be safely evaluated against offensive objectives.\nThis role operates at the intersection of cyber-range engineering, cloud and virtualization infrastructure, offensive security, and agentic AI safety. The role involves translating evaluation requirements into production-like environments with realistic identities, hosts, services, trust relationships, attack paths, telemetry, validation, and reset mechanisms.\nA critical aspect of the role is understanding the offensive evaluations that the ranges support and engineering appropriate security boundaries around them. This includes authorization, credentials and secrets, execution isolation, network egress, orchestration, monitoring, interruption, recovery, and forensic evidence.\nCyber-capable models may probe the evaluation harness, exploit unintended paths, seek external connectivity, or act outside the intended task. The role therefore requires a focus on containment, monitoring, and secure-by-design engineering.\nThis opportunity is suited to candidates with experience in cyber-range and platform security, combined with offensive security knowledge. Key responsibilities include building high-fidelity, reproducible environments, applying defense-in-depth and least-privilege principles, independently instrumenting and monitoring activity, continuously validating containment, and designing ranges that can fail safely, be rapidly revoked or rebuilt, and support detailed investigation when required.\nResponsibilities\nDesign, build, and operate realistic, versioned, infrastructure-as-code cyber ranges spanning cloud, identity, endpoint, network, application, container, and multi-host attack surfaces.\nModel production-like organizations, architectures, products, configurations, trust relationships, user behavior, data, and telemetry so evaluations require authentic multi-step offensive reasoning.\nTranslate evaluation objectives into repeatable scenarios with explicit prerequisites, authorized boundaries, expected attack paths, ground-truth validation, scoring signals, and automated reset contracts.\nEngineer reliable lifecycle automation for provisioning, validation, execution, teardown, sanitization, and recovery across concurrent evaluation runs.\nDesign defense-in-depth controls for cyber-capable models and agents, including identity and authorization boundaries, least-privilege credentials, secrets isolation, capability-gated tools, workload isolation, and fail-closed enforcement.\nControl and observe all network paths, including default-deny egress, approved destinations, DNS and traffic inspection, rate and scope controls, and automated interruption when activity crosses policy or range boundaries.\nBuild independent telemetry across model calls, agent trajectories, tool invocations, process execution, filesystem changes, identity use, network traffic, and control-plane activity; produce attributable, tamper-resistant evidence for investigation and scoring.\nContinuously test the range and evaluation harness for sandbox escape, lateral movement, prompt or tool injection, credential exposure, supply-chain risk, benchmark cheating, persistence, and unintended access to evaluator or production infrastructure.\nDefine operational controls for emergency stop, credential revocation, workload quarantine, evidence preservation, incident response, and rapid rebuild; exercise these controls before enabling higher-capability models.\nPartner with evaluation researchers, red-team operators, cloud and platform teams, and security response functions to convert new evaluation needs and observed failure modes into durable range capabilities and controls.\nDocument threat models, architecture decisions, control assumptions, operating procedures, residual risk, and evidence of containment for each range and model-access tier.\nQualifications\nRequired Qualifications:\nBachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field AND relevant experience in security engineering, cloud or platform engineering, cyber-range development, or equivalent practical experience.\nDeep hands-on experience designing and operating cyber ranges, security labs, testbeds, vulnerable environments, or other adversarial infrastructure at meaningful scale.\nSolid systems and network security expertise across identity, access control, operating systems, cloud control planes, virtualization, containers, applications, secrets, segmentation, egress control, logging, and incident response.\nSolid programming and automation ability, particularly in Python, plus experience with infrastructure as code, CI/CD, orchestration, configuration management, and repeatable environment lifecycle operations.\nDemonstrated ability to threat-model hostile or autonomous workloads and translate risks into layered preventive, detective, and responsive controls.\nWorking knowledge of offensive-security concepts, attack paths, exploitation, lateral movement, persistence, and post-exploitation sufficient to build credible environments and recognize unintended behavior.\nAbility to partner with evaluation experts to understand task intent, preserve experimental validity, and distinguish model capability from environmental or harness failure.\nPreferred Qualifications:\nExperience engineering cyber ranges across Azure, Kubernetes, Docker, hypervisors, Windows, and Linux with solid tenant, network, workload, and data isolation.\nExperience securing agentic or tool-using AI systems, evaluation harnesses, autonomous code-execution platforms, malware-analysis systems, or similarly hostile workloads.\nExperience building network and host telemetry pipelines, security analytics, detection logic, automated policy enforcement, and forensic workflows for ephemeral environments.\nExperience with zero-trust design, non-human identities, short-lived credentials, secrets management, software supply-chain security, image provenance, and artifact signing.\nExperience designing realistic enterprise attack environments, including identity, cloud, endpoint, application, network, container, or operational-technology scenarios and multi-stage attack chains.\nFamiliarity with frontier-model cyber evaluations, benchmark design, agent trajectories, ground-truth validation, scoring, contamination, reproducibility, and evaluation-specific cheating or reward hacking.\nExperience conducting architecture reviews, adversarial testing, containment validation, incident exercises, and risk acceptance for high-consequence research environments.\nPublication, conference, open-source, or community contributions in cyber ranges, cloud security, platform security, offensive security, AI security, or adjacent technical fields.\nSecurity Operations Engineering IC5 - The typical base pay range for this role across United Kingdom is £ 93,500.00 - £ 161,800.00 per year. Certain roles may be eligible for benefits and other compensation.\nFind additional benefits and pay information here:\nhttps://careers.microsoft.com/v2/global/en/corporate-pay/united-kingdom-corporate-pay.html\nThis position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.\nMicrosoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.","description_format":"text","description_chars":9208,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Console Games","Cloud Platforms (IaaS & PaaS)","Gaming Consoles","Developer Tools"],"lifecycle":[{"event":"open","at":"2026-10-06T17:01:03Z"}],"visa":[],"liveness":{"score":57,"band":"ok","label":"Likely open","p_open":1,"p_active":0.631,"p_room":0.9,"age_days":12,"expected_fill_days":20,"reasons":["conf:2","stale_co","wave","velocity","win:mid","comp:brand"],"computed_at":"2026-10-07T05:47:15Z"},"pay":{"stated_usd_annual":214658,"is_top_pay":true},"html_url":"https://alion.io/job/microsoft-principal-security-operations-engineer-3","json_url":"https://alion.io/job/microsoft-principal-security-operations-engineer-3.json","meta":{"generated_at":"2026-10-08T02:30:55Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4345,"day_limit":5000,"remaining_today":655,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":18},"rest":"https://alion.io/mcp/rest/get_company?id=18"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fmicrosoft-principal-security-operations-engineer-3"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fmicrosoft-principal-security-operations-engineer-3"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fmicrosoft-principal-security-operations-engineer-3"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/microsoft-principal-security-operations-engineer-3\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fmicrosoft-principal-security-operations-engineer-3"}]}