Overview
We are looking for a highly motivated and passionate Security Cloud Solution Architect (CSA) to drive customer transformation on the Microsoft Azure Platform. This is a customer-facing role, owning the overall technical relationship and strategy between the customer and Microsoft. You will own the Azure Security customer engagements, including architecture, implementation, and production. Microsoft provides the most comprehensive, innovative, flexible, and Secure cloud platforms today. Microsoft is hiring security professionals to drive customer cloud security adoption for customers around the world. The ideal candidate will have experience in customer-facing roles and success in leading in-depth technical security architecture discussions with senior customer executives, Enterprise Security Architects, Enterprise Architects, IT Management, and Developers to drive the holistic Security conversation as an enabler forCloudworkloads.
Responsibilities
Microsoft Federal is seeking individuals passionate about advancing cybersecurity readiness through immersive, hands-on exercises that strengthen operational resilience for U.S. Federal agencies. Ideal candidates for this role will demonstrate technical expertise, strong facilitation skills, and a commitment to driving measurable security outcomes. As a Security Cloud Solution Architect (L64) focused on Cyber Exercises, you will support the planning, facilitation, and delivery of immersive cybersecurity exercises for U.S. Federal customers. Working alongside senior CSAs, you will help design scenarios, operationalize technical solutions, and drive measurable security outcomes through hands-on engagement and collaboration. Responsibilities include:
- Adversary Emulation Leadership
Author and govern adversary scenario developmentusing industry standard frameworks (e.g., MITRE ATT&CK), including adversary goals, TTP chains, inject timelines, success criteria,and safety boundaries.
Align exercise scope, objectives, and communicationswith accountteam, customer,and delivery stakeholders; coordinatecontrolcell and intelligenceforinjects; managered team operationsschedule.
Lead collaborationwith Microsoft sales, engineering, and account teams to trackdelivery metrics, securityimpact,productusageoutcomes, and return on investment.
Build scenario artifacts that enhance realism (e.g., simulated phishing, OAuth abuse, identity compromise, lateral movement narratives, and supporting evidence) while maintaining safe exercise guardrails.
Qualifications
Required Qualifications
- Bachelor's Degree in Computer Science, Information Technology, Engineering, Business, Liberal Arts, or related field AND 4+ years experience in cloud/infrastructure technologies, information technology (IT) consulting/support, systems administration, network operations, software development/support, technology solutions, practice development, architecture, and/or consulting OR equivalent experience.
Other Requirements
Security Clearance Requirements: Candidates must be able to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
- The successful candidate must have an active U.S. Government Top Secret Security Clearance. Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. Failure to maintain or obtain the appropriate clearance and/or customerscreening requirements may result in employment action up to and including termination.
- Clearance Verification: This position requires successful verification of the stated security clearance to meet federal government customer requirements. You will be asked to provide clearance verification information prior to an offer of employment.
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- Citizenship & Citizenship Verification:This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance
Preferred Qualifications
-
Bachelor's Degree in Computer Science, Information Technology, Engineering, Business, Liberal Arts, or related field AND 8+ years experience in cloud/infrastructure technologies, information technology (IT) consulting/support, systems administration, network operations, software development/support, technology solutions, practice development, architecture, and/or consulting OR Master's Degree in Computer Science, Information Technology, Engineering, Business, Liberal Arts, or related field AND 6+ years experience in cloud/infrastructure technologies, technology solutions, practice development, architecture, and/or consulting OR equivalent experience. -
4+ years experience working in a customer-facing role (e.g., internal and/or external).
Ability to build reusable adversary playbooks and scenarios aligned with real-world and fictional threat actorsincluding success criteria, inject timelines, and mapped TTPs for repeatable delivery at scale.
Demonstrated hands-on experience executing full attack chains (initial access,persistence,privilege escalation,lateral movement,cloud workload impact) in realistic enterprise environments.
Expert-level experience withattack paths across Entra ID, Microsoft 365, and Azure. Including token theft/reuse, app consent abuse, conditional access bypass, device identity abuse, andAI-enabled tradecraft.
Strong understanding of hybrid identity attack techniques including Kerberos/NTLM, AD CS/PKI relay, ADFS, and lateral movement to cloud workloads.
Experience with cloud persistence and privilege escalation techniques including service principal abuse, application registrations, federated identity credentials, and managed identity abuse.
Experience with Azure IaaS compromise and lateral movement including Azure VM access, credential harvesting, automation account abuse, and storage/key access paths (Key Vault, Storage Accounts, SAS tokens).
Ability to develop detection recommendations mapped directly to exercise TTPs, including suggested telemetry sources, logging gaps, and validation steps.
Familiarity with modern open-source red team tooling such as Havoc, Sliver, Mythic, Impacket, BloodHound, and related tradecraft ecosystems.
Experience leading red team operations with multiple junior operators, including tasking, quality control, safety oversight, and operational coaching.
- Travel is an integral part of this position. You should be willing to travel as is demanded by the needs of our customers and our business. This position requires approximately50-75% overnight travel.
Cloud Solution Architecture IC4 - The typical base pay range for this role across the U.S. is USD $106,400 - $203,600 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $137,600 - $222,600 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
|