Senior Security Program Manager

Microsoft, Newtown, Cambridge

Senior Security Program Manager

Salary Not Specified

Microsoft, Newtown, Cambridge

  • Full time
  • Permanent
  • Onsite working

Posted 2 weeks ago, 7 Nov | Get your application in now before you miss out!

Closing date: Closing date not specified

job Ref: 2ee251aa79d14a989a0f4e7c576df19c

Full Job Description

Microsoft Azure Edge + Platform (E+P) is a globally distributed team of engineers, architects, program managers, product managers, business program managers, business administrators, user experience researchers and designers who are responsible for the platform for Microsoft and for delivering Microsoft's edge vision. We create the most reliable and trustworthy OS and platform services to empower Microsoft and our customers to achieve more. We unlock the next wave of opportunity at the edge through an at-scale ecosystem driving widespread adoption of our Microsoft cloud services., Microsoft's Edge + Platform Security Fundamentals (EPSF) team is looking for a Senior Security Program Manager to join our Microsoft Offensive Research & Security Engineering (MORSE) team. The MORSE team is responsible for securing the Windows client and server operating systems, used by billions of customers every day in businesses and across Azure. This team performs security design reviews, code reviews, and penetration testing on key features of Windows and Azure to make sure they meet the highest possible security standards, as well as defines security requirements and best practices that all of our platforms must adhere to. Our platforms serve as the foundation for nearly everything the company builds. From Windows Client and Server to edge devices to Azure and Xbox - the security of everything built on top of our platforms relies on the premise that the platform itself is secure.,

  • Identify and mitigate risk in Microsoft products in close partnership with MORSE engineers including design reviews, code reviews, and fuzzing
  • Be the security contact for teams building new innovative products and technologies in the next version of Windows, Azure, and devices
  • Leverage a broad and current understanding of security to envision new protections
  • Interact with the external security community and security researchers
  • Collaborate with product teams to improve security, and articulate the business value of security investments
  • Partner with teams inside and outside EPSF toward building security and compliance early in the product development process and in developing born secure, born compliant products.
  • Define objectives and key results (OKRs) to measure product success and track progress against goals, iterating and optimizing as necessary.
  • Embody our Culture (https://careers.microsoft.com/v2/global/en/culture) & Values (https://www.microsoft.com/en-us/about/corporate-values)

    In this impactful role, you will partner with engineering and PM teams inside and outside EPSF to secure the operating systems built at Microsoft. The ideal candidate will have experience with native code (C/C++), penetration testing (code audit, writing fuzzers, finding creative ways to break assumptions), a clear understanding of OS (Operating System) security fundamentals, solid computer science skills, and a passion for keeping Microsoft customers safe., Bachelor's or Master's degree in Computer Science, Information Security, or an equivalent experience.
  • At least 3 years of experience as a program manager, product manager, dev lead, or cybersecurity professional (can sum up these roles to 3 years), Substantial experience in cybersecurity assurance and program management preferably including platform & operating system development.
  • Knowledge of the internals of Windows and/or Linux operating systems.
  • Strategic thinking and problem-solving skills, with the ability to develop and execute research & development strategies that support product development objectives.
  • Experience with defining and tracking OKRs and KPIs to measure program performance.
  • Excellent communication and collaboration skills, with the ability to effectively interact with stakeholders at all levels of the organization.
  • Customer feedback and data driven.
  • Entrepreneurial mindset, self-starter, "getting things done" attitude
  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to, the following specialized security screenings:
  • Microsoft Cloud Background Check : This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
  • #AEPJobs