Director of Security

3 Days ago • 8-14 Years • Cyber Security

About the job

Job Description

The Director of Security leads Microsoft AI's security program, managing cybersecurity risks, operational strategies, and large-scale security projects. This role requires deep security expertise, managing teams, and working with engineering to implement and evolve security posture across products like Consumer Copilot, Bing, MSN, and Microsoft Advertising. Responsibilities include application and operational security assurance, establishing security baselines, mitigating risks, and providing technical support to engineering teams. The ideal candidate possesses strong management skills, a deep understanding of the threat landscape, and experience implementing robust security measures. They will create actionable guidance, secure configurations, and ensure adequate resources are dedicated to fixing vulnerabilities.
Must have:
  • 8+ years experience in security
  • 4+ years people management
  • 6+ years cybersecurity experience
  • 4+ years experience establishing security baselines
  • Azure cloud infrastructure experience
  • Application & Operational Security expertise
Good to have:
  • CISSP or Security+ Certification
  • Experience managing large-scale cybersecurity programs
  • OWASP ASVS/Top 10, CWE 25 experience
  • Experience with common security libraries and controls
Perks:
  • Industry-leading healthcare
  • Educational resources
  • Discounts on products and services
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Networking opportunities

Overview

We are seeking a highly skilled and experienced Director of Security to lead the Microsoft AI security program. This role is pivotal in understanding new and emerging cybersecurity risks, enhancing the execution of operational security strategies, and managing large-scale rollouts of security projects. As manager of the team, you will scale your deep security expertise and knowledge outwards via the Application and Operational security teams, delivering impact through assurance programs and continuous monitoring of the divisional security posture.

 

You will own Application and Operational Security assurance and work directly with Engineering to implement and evolve the security posture of the organization and all of its products, including Consumer Copilot, Bing, MSN and Microsoft Advertising. The ideal candidate will have a deep understanding of the evolving threat landscape and a proven track record in implementing robust security measures. You will be a proven manager, capable of defining vision and executing technical security strategy through your leads and individual contributors.

You will be accountable for creating actionable guidance, secure baseline configuration and assist engineering teams in the deployment and ongoing management of a standard and secure infrastructure. You will ensure adequate resources and attention is dedicated to fixing vulnerabilities which expose the organization to increased risk of malicious activities.

Why Join Us:

  • Be part of a team that is at the forefront of cybersecurity innovation. Own the strategy and vision for the security of large scale consumer products from Microsoft.
  • Contribute to the protection of Microsoft’s digital ecosystem and earn the trust of our customers.
  • Work in a dynamic and collaborative environment with opportunities for growth and development.
  • If you are passionate about cybersecurity and have the expertise to drive strategic security initiatives, we encourage you to apply for this exciting opportunity.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Qualifications

Required Qualifications:

  • Bachelor's Degree AND 8+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • 4+ years people management experience.
  • 6+ years of experience in cybersecurity, with a focus on planning and execution of security assurance programs (application and operational).
  • 4+ years of experience in establishing security baselines for infrastructure, identifying and mitigating operational security risk
  • 4+ years of experience with implementation, coding, scripting and automating Azure (or equivalent) cloud infrastructure and services.

Preferred Qualifications:

  • Certified Information Systems Security Professional (CISSP) Certification, Security+ Certification, or relevant certification.
  • Experience managing large scale cybersecurity assurance and operational security programs preferably including online service development.
  • Experience with application security standards such as OWASP ASVS/Top 10, CWE 25.
  • Experience with common security libraries, security controls, and common security flaws.

Product Management M5 - The typical base pay range for this role across the U.S. is USD $137,600 - $267,000 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $180,400 - $294,000 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until January 7, 2025. 

 

 

#MicrosoftAI

Responsibilities

  • Application and Operational Security Execution: Assist in the development and implementation of comprehensive security strategies aligned with the Secure Future Initiative (SFI) and beyond. Manage a team to deliver technical execution with engineering, set policy and build tooling and automation to enforce Security by Default baselines within Microsoft AI environments. Identify opportunities to continuously improve controls and monitoring for Secure Operations. Lead direction on the assurance programs that align with Microsoft’s Security Development Lifecycle, evolving the existing programs in a more modern security direction.
  • Security Project Orchestration: Oversee large-scale security project rollouts across the organization. Coordinate with various teams to ensure seamless execution of security initiatives. You will own management of security baseline design and execution, providing direct technical support and advice to engineering, providing reporting and summaries to leadership and generally delivering on projects to identify and mitigate security risks.
  • Cybersecurity and Operational Program: Adopt and oversee cybersecurity guidelines and standards, coordinate with compliance teams, and execute attestations. Ensuring the adoption of Implementation Guidance issued through the Regulatory Governance program, as well as other compliance guidance, Council decisions, and applicable standards and controls. Including oversight of and coordination with compliance teams, and execution of necessary attestations and related records.
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect
View Full Job Description
$137.6K - $294.0K/yr (Outscal est.)
$215.8K/yr avg.
Redmond, Washington, United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Dublin, County Dublin, Ireland (On-Site)

Beijing, Beijing, China (On-Site)

Taipei City, Taiwan (On-Site)

Redmond, Washington, United States (On-Site)

San José, San José Province, Costa Rica (On-Site)

Vancouver, British Columbia, Canada (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Similar Jobs

Microsoft - Legal Counsel Intern

Microsoft, France (On-Site)

ARHS - IT Support Officer

ARHS, Netherlands (On-Site)

Infoworksio - Software Development Engineer in Test

Infoworksio, India (On-Site)

Smart Working - UI Developer

Smart Working, India (Remote)

Enphase Energy - Staff Engineer, Embedded Security

Enphase Energy, India (On-Site)

Microsoft - Product Manager

Microsoft, (On-Site)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Varonis  - Security Operations Center (SOC) Expert

Varonis , United States (On-Site)

Enphase Energy - Sr. Staff Engineer Cloud

Enphase Energy, India (On-Site)

PepsiCo - Release Manager Global IBP

PepsiCo, India (On-Site)

Ziff Davis - Senior Software Engineer, Backend - Lose It!

Ziff Davis, United States (On-Site)

Patterned Learning Career - Junior Python Developer

Patterned Learning Career, (Remote)

Blazesoft - DevOps engineer

Blazesoft, Canada (On-Site)

Harness - Senior Software Engineer_CD Backend

Harness, India (On-Site)

Demonware - Associate Principal Software Engineer

Demonware, United States (On-Site)

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

The Walt Disney Company - Network Operations II

The Walt Disney Company, United States (On-Site)

Sleeper - User Researcher (UX)

Sleeper, United States (On-Site)

Google - Partner Engineer, gUP Gemini and Assistant

Google, United States (On-Site)

Info Stretch - Sr. .NET Developer

Info Stretch, United States (On-Site)

Hasbro - Principal Business Analyst

Hasbro, United States (On-Site)

IGT - Temporary Information System Engineer

IGT, United States (On-Site)

Barbaricum - Vehicle Electronics Engineer

Barbaricum, United States (Hybrid)

Zoox - Senior Staff People Partner, Product

Zoox, United States (Hybrid)

VX Media - Video Editor

VX Media, United States (On-Site)

Microsoft - Senior Software Engineer - ML Focused

Microsoft, United States (On-Site)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Logifuture - Information Security Manager

Logifuture, Malta (Hybrid)

Skyhigh Security - Senior Software Development Engineer

Skyhigh Security, India (On-Site)

Anavation - Cloud Security Architect

Anavation, United States (On-Site)

Sumo Logic - Senior Application Security Engineer-I

Sumo Logic, India (Remote)

Google - Technical Program Manager II, Compliance, CISO

Google, United States (On-Site)

Egnyte - Sr Solutions Engineer - AEC

Egnyte, United States (On-Site)

Get notifed when new similar jobs are uploaded