New job, posted less than a week ago!
Job Details
Posted date: Sep 02, 2025
Category: Program Management
Location: Redmond, WA
Estimated salary: $188,900
Range: $119,800 - $258,000
Employment type: Full-Time
Travel amount: 25.0%
Work location type: Up to 100% work from home
Role: Individual Contributor
Description
The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.The Office of the Chief Information Security Officer (OCISO) is accountable for managing and prioritizing cybersecurity risk for Microsoft. This team oversees the company’s overall cyber defense, including the security of Microsoft products and business operations, and collaborates with Engineering teams to advance Secure Future Initiative (SFI) objectives. The Chief Information Security Office (CISO) Governance, Risk, and Compliance (GRC) team, a key function within OCISO, focuses on ensuring regulatory compliance and effectively mitigating and reducing risk.
The CISO GRC team is seeking a dedicated Senior Technical Program Manager - Cybersecurity Risk Analyst to strengthen enterprise cybersecurity risk management through exception oversight. This role will focus on reviewing and analyzing risk associated with exception management, evaluating high-risk scenarios, and driving program enablement across the CISO organization. Success in this role requires deep technical acumen, proficient risk analysis capabilities, and close collaboration with stakeholders across engineering, compliance, and governance teams to ensure exception-related risks are identified, assessed, and addressed effectively.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Perform risk assessments by analyzing submitted documentation and exception requests, focusing on identifying inherent and residual risks without relying on proposed future controls.Lead risk evaluation sessions with stakeholders (e.g., risk owners, subject matter experts), facilitating discussions around control gaps, data exposure, and mitigation strategies.Apply structured risk scoring methodologies (e.g., impact, likelihood, control effectiveness) in alignment with enterprise risk frameworks and tools such as risk calculators or assessment platforms.Document and monitor risk decisions, approvals, and remediation timelines using standardized templates and tracking systems, ensuring adherence to service-level expectations.Collaborate across teams to validate risk findings, support mitigation planning, and ensure consistency with internal control frameworks and compliance requirements.Drive accountability for risk disposition and remediation, including renewal or closure workflows, and provide timely follow-up based on leadership input or audit findings.Embody our Culture and Values
Qualifications
Required Qualifications:Bachelor's Degree AND 4+ years’ experience in engineering, product/technical program management, risk analysis, or cybersecurity operations OR equivalent experience2+ years of experience managing cross-functional and/or cross-team projects.4+ years of experience evaluating and managing cybersecurity risk, with a focus on exception handling and high-risk scenarios3+ years of experience driving program enablement and governance frameworks across cross-functional technical teams2+ years of experience collaborating with engineering and compliance stakeholders to address root-cause exception drivers (e.g., tools, processes, control gaps)
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter. Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. 1324b(a)(3)) for assessment of eligibility to access the export controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.Citizenship Verification: This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport.
Preferred Qualifications:
Bachelor's or Master's Degree AND 6+ years’ experience in engineering, product/technical program management, risk analysis, or cybersecurity operations OR equivalent experienceCertified Risk Professional (CRISP) certification or equivalent credentials demonstrating proficiency in ISO 31000, ISO/IEC 27001, and ISO 22301-aligned risk frameworks.Technical background in security and network architecture, with the ability to assess vulnerabilities and control effectiveness.Deep understanding of risk management practices, including: Risk identification and scoring, prioritization and mitigation planning.4+ years of experience collaborating with cross-functional technical teams, including engineering, product, and compliance stakeholders.Demonstrated ability to influence accountability across dependent teams and drive resolution of exception-related risks at the source. 6+ years of experience managing cross-functional and/or cross-team projects.1+ year(s) of experience reading and/or writing code (e.g., sample documentation, product demos).
Technical Program Management IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $158,400 - $258,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications for the role until September 16, 2025.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
#MSFTSecurity
Check out other jobs at Microsoft.