Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
Microsoft CISO Organization’s Governance, Risk Management, and Compliance team is seeking a Director, Security Risk & Compliance to focus on enhancing Microsoft’s security ecosystem by bringing design and process implementation and oversight to risk management practices. This role will be heavily pivoted towards an understanding and leverage of cybersecurity industry standards, like NIST CSF 800-53. This candidate will have regulatory industry engagement and be an integral part of the preparation and readiness of Microsoft security risk management program. This is a fast-paced, exciting role with an opportunity to bring your leadership, energy, and ideas into one of the most critical priorities for the Microsoft and industry.
We are seeking a highly-motivated individual who is passionate about modern, technical solutions to risk and compliance challenges and is hungry to contribute with both depth and breadth, navigating often from leadership oversight to hands on execution. The ideal candidate will possess experience in managing or contributing to the management of enterprise-scale compliance, risk and operational business process and programs, along with experience designing and operating programs at scale, agile methodologies, industry standards within the security space, knowledge of software engineering processes, and has experience delivering results in a complex and matrixed organization. You will help the team drive change and innovation while partnering with other risk and compliance teams around the company, delivering results across multiple engineering partners. Commitment to staying abreast of current industry trends, regulatory changes and the ability to adapt to quickly evolving business needs and organizational changes is a must.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Successful candidates can be located anywhere in the U.S.
- Design of governance, risk management, and compliance risk management services and capabilitie, implement and drive adoption of these designs in the form of requirements and process.
- Drive (design and execution) cross-enterprise security risk assessments, such as NIST CSF, and provide insights and recommendations to our Deputy CISOs, plus understanding and guiding mitigation of our top risks.
- Plan, implement, and oversee execution of risk management processes, including scaling as-is processes for increased coverage, quality, speed, and output using operational and technology-based approaches.
- Embody our culture and values
Required Qualifications:
- Bachelor’s degree in Engineering, Information Systems, Law, Criminology/Criminal Justice, Finance or related field AND 8+ years of experience in security, risk management, compliance, security, resilience or related fields
- OR equivalent experience.
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- 5+ years of experience in cybersecurity risk management and compliance, including regulation readiness, frontline engagement with regulators, and process design.
- analytical, problem-solving, and decision-making skills, including ability to pull business insights and trends from risk management data and information.
- Experience working in cross-functional teams and collaborating with multiple internal organizations.
- Knowledge of risk management practices, including ability to understand risk, support prioritization, and ensure accountability for risk disposition and mitigation.
- Project management skills, with the ability to prioritize work efforts, manage multiple tasks simultaneously, and drive accountability across project teams.
- Knowledge of cloud technologies and their impact on security, resilience and compliance.
- Experience with continuous monitoring, assurance of IT systems, and audit practices for compliance purposes.
- Leadership and team management skills
Business Program Management IC6 - The typical base pay range for this role across the U.S. is USD $129,200 - $273,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $162,000 - $299,400 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
Microsoft will accept applications for the role until January 3, 2025
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
#cisoorg #mssecurity #compliance #riskmanagement #nist