This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Microsoft Windows Security team is responsible for protecting billions of Windows devices by driving platform‑level security, risk reduction, and resilient-by-design engineering across the Windows ecosystem. We are seeking a Principal Security Program Manager to lead our end‑to‑end security assurance effort including security compliance, risk assessment, and supporting our vulnerability research and security tooling efforts across Windows. This role sits at the intersection of platform security architecture, threat intelligence, vulnerability discovery, and execution, with broad influence across Windows engineering and other internal and external security assurance and research partners. This is a principal level individual contributor role with wide organizational scope, high executive visibility, and responsibility for shaping how Windows identifies, prioritizes, and mitigates security risks at scale.
Job Responsibility:
Own the Windows EnS security risk assessment framework, driving systematic identification, prioritization, and tracking of security risks across OS, firmware, silicon, drivers, and ecosystem dependencies
Partner with engineering, architecture, and threat intelligence teams to translate emerging threats, vulnerability trends, and attacker techniques into actionable platform investments
Develop and drive the security assurance process for Windows teams utilizing a shared responsibility approach that supports the scale of the Windows org while ensuring broad compliance and a risk based approach towards scaling security review and depth engagement
Act as virtual lead for a small security PM team by managing PM coverage across the team’s charter, leading planning and engagement with EnS security engineering, and owning key cross team partnerships
Requirements:
Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
OR equivalent experience
Nice to have:
Ability to create clarity, energy, and cohesion across the team
Ability to influence and drive security initiatives across groups
10+ years of experience in a software engineering or security-related engineering
Demonstrated experience in security research, especially around vulnerability discovery
Experience exploiting bugs and bypassing security mitigations in operating systems