Microsoft Sr Director, Security Strategy & Operations

New job, posted less than a week ago!

Job Details

Posted date: Sep 25, 2026

Category: Technical Solution Management

Location: Multiple Locations, Multiple Locations

Estimated salary: $217,250
Range: $130,900 - $303,600

Employment type: Full-Time

Work location type: 0 days / week in-office – remote

Role: People Manager


Description

Overview

The Office of the CTO (OCTO) for MCAPS-Core drives technical strategy and execution, operational efficiencies, scaling solutions that accelerate customer outcomes, and deliver innovation across AI cloud quality, and security.

Within OCTO, the Sr Director for Security Strategy & Operations is pivotal in defining and driving the end-to-end security strategy for MCAPS-Core while minimizing operational disruptions to the business and our customers. This leader will directly report to the MCAPS-Core Chief Technology Officer and oversee a dedicated team responsible for driving critical programs identifying, mitigating, and responding to security needs, ensuring rapid response and mitigation, and maintaining rigorous compliance with Microsoft standards.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

Define the strategic vision for a highly complex portfolio of security initiatives, ensuring alignment with overarching company objectives and customer value delivery. Provide technical leadership and strategic oversight for developing comprehensive governance frameworks and technical plans and roadmaps; driving program execution and continuously raising the bar for our security practices across the organization. Oversees multiple teams in orchestrating large-scale security reviews, including architectural and design reviews, and strategically develop processes to scale findings and recommendations across the organization. Establishes and disseminates a strategic vision and service model to improve security operations cross-organizationally. Develops and communicates the strategy to executive-level stakeholders within the respective suppliers and internal clients. Provides leadership and direction to the internal organization and supplier partners. Accepts accountability for annual operating expense budgets, including oversight on areas of spending, accountability of actuals versus forecasted, and approval of all expenses. Drives innovation and technology improvements in partnership with engineering, including applications for AI, to develop new security-related applications and processes to advance security operations and support the security initiative's strategic vision for resilient, future-ready security programs with impact across Microsoft. Partners with executive leaders to develop and implement comprehensive security policies and practices across the organization without disruption to the business and our customers. This includes executive and senior leaders across Microsoft, including the CISO team, Engineering, Product Groups, and MCAPS-Core teams to identify and propose potential business opportunities, services, and/or product offerings. Acts as an escalation point for highly complex obstacles identified by teams to ensure business outcomes are met. Serves as the representative in leadership forums, communicating progress, advocating for resources, and facilitating the prioritization of work in response to emerging demands, threats, and technological innovation. Facilitates partnerships with senior leaders to synchronize project priorities and ensure alignment of resources. Determines guidelines for defining success criteria and performance metrics for a highly complex, high-impact solution. Facilitates team understanding and identification of operational and performance key performance indicators (KPIs), objectives and key results (OKRs), and success measures (e.g., adoption percentage, engagement, latency) for improving solutions. Reviews and communicates status updates of initiatives in flight to senior leadership and stakeholders to drive alignment and mitigate delays with stakeholders. Oversees teams in meeting collective security requirements and providing security capabilities. Advises the organization and stakeholders on industry best practices related to risk mitigation and threats. Develops and oversees the implementation of enterprise-wide risk management frameworks for identifying and controlling security risks across the Microsoft portfolio. Drives risk management rhythm and training programs to increase risk awareness among service teams and stakeholders. Ensures teams summarize, report, and communicate risk analysis findings to internal and external stakeholders and leaders. Provides expertise in developing a strategy to mitigate and respond to residual risks based on its team's anticipation of global insecurity and physical disruption (e.g., life safety, business operations, reputation) within Microsoft. Oversees teams to identify security threats by gathering, analyzing, and evaluating information about existing, or potential threats to determine the likelihood of a Microsoft infrastructure, business, people, and assets, being targeted. Creates predictive models for high-risk scenarios (e.g., civil unrest, insider threats, natural disasters). Incorporates artificial intelligence (AI)-powered threat intelligence platforms to proactively identify and assess risks to Microsoft infrastructure, business, people, and assets across organizations. Develops strategy to monitor current, emerging, and evolving threats with the likelihood to impact Microsoft infrastructure, business, people, and assets using automated analytics and machine learning models to enhance detection and response capabilities. Provides strategic guidance to teams to identify assets or operations where security is not adequate and can be exploited by a threat. Oversees teams evaluating geopolitical activities and events, and synthesizes key intelligence to inform internal and external stakeholder constituents or employees of potential threats. Develops guidelines for teams to inform and escalate the risks to appropriate teams. Holds accountability for production of executive-ready risk assessment reports with actionable insights. Work closely with individual business units to understand the unique challenges and security needs of different areas. This collaboration will help tailor solutions, translating plans into execution to close readiness gaps, and sequencing adoption so controls land without disrupting customers or operational readiness of the business. Ensures work of the team upholds standards of analysis and design. Recognizes and conveys the impact of security problems, threats, and risks. Provides thought leadership across teams, maintains knowledge of industry trends, and creates mechanisms for best practice sharing and strategic impact of insights generated by analyses. Drives Microsoft to be a visible leader in security expertise. Champions high-impact contributions to internal and external communities through publications, white papers, seminars, or conferences, broadening organizational influence and reputation and shaping understanding of threat protection in real-world impact and storytelling.

People Management

Managers deliver success through empowerment and accountability by modeling, coaching, and caring. Model: Live our culture. Embody our values. Practice our leadership principles. Coach: Define team objectives and outcomes. Enable success across boundaries. Help the team adapt and learn. Care: Attract and retain great people. Know each individual’s capabilities and aspirations. Invest in the growth of others.

Qualifications

Required/minimum qualificationsMaster's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 6+ years experience in project management, operations, or engineering OR Bachelor's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 8+ years experience in project management, operations, or engineering OR equivalent experience. Other RequirementsMicrosoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter. Additional or preferred qualificationsMaster's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 12+ years experience in project management, operations, or engineering OR Bachelor's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 15+ years experience in project management, operations, or engineering OR equivalent experience.5+ years people management experience.8+ years experience in security program OR Experience in Cyber Security, or Experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection.

Technical Solution Management M6 - The typical base pay range for this role across the U.S. is USD $130,900 - $277,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $165,600 - $303,600 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.



Email job link for Sr Director, Security Strategy & Operations at Microsoft

Provide your email address to receive a message with the job link and details.

Check out other jobs at Microsoft.