This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Microsoft 365 Copilot is the AI platform that will transform how work gets done. It’s rapidly becoming the central entry point across Word, Excel, PowerPoint, Outlook, Teams, and agents driving AI-led productivity for every business. AI security is a critical challenge Microsoft must tackle to earn our customer trust. The Microsoft 365 Copilot Security Team (SPEAR) was formed to strengthen the security posture of M365 Copilot’s agentic and autonomous systems across the Microsoft ecosystem. SPEAR provides shared security services, delivers common capabilities, and standardizes security practices across all M365 Copilot teams. Its charter is to protect Copilot apps and features by embedding agentic security throughout the ecosystem and the core Copilot architecture stack. As a Senior Product Manager on the SPEAR team, you will drive initiatives that help ensure M365 customers get the most out of Copilot on the most secure platform in the industry. You will set product vision and strategy for shared security services, deliver common security capabilities, and help standardize security practices across M365 Copilot teams. You will collaborate with applied scientists, engineers, security experts, and product managers across Microsoft to shape the strategy and roadmap. We are looking for a Senior Product Manager with a deep curiosity for cybersecurity and experience shaping AI-driven products. In this role, you will own key problem areas, define product strategy and priorities, and drive outcomes that measurably improve M365 Copilot and customer security posture. You will leverage M365’s security ecosystem (e.g., Defender, Purview, Safe Links, Intune) to translate threat patterns and XPIA risks into durable product and engineering systems that embed agentic security across the M365 Copilot architecture. You will partner closely with engineering and applied science to deliver high-quality, scalable capabilities that harden Microsoft’s agentic and autonomous AI stack.
Job Responsibility:
Own a defined security problem space end-to-end, setting product vision, strategy, and roadmap grounded in attacker behavior, customer risk, and business priorities
Translate cybersecurity signals (telemetry, threat intelligence, research, and customer feedback) into clear product decisions, prioritizing investments for measurable security impact
Partner with incident response and customer-facing teams to learn from real-world cases, communicate customer impact, and drive product changes that reduce recurrence and time-to-mitigate
Define product requirements for shared security services and leverage telemetry to identify defect patterns, abuse/misuse trends, and systemic gaps across Copilot experiences
Define and own security success metrics and validation plans (including evaluation signals) to detect, prevent, and quickly remediate security regressions
Requirements:
Bachelor's Degree AND 5+ years experience in product/service/program management or software development OR equivalent experience
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role
Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter
Nice to have:
Bachelor's Degree AND 8+ years experience in product/service/program management or software development OR equivalent experience
2+ years experience taking a product, feature, or experience to market (e.g., design, addressing product market fit, and launch, internal tool/framework)
4+ years experience improving product metrics for a product, feature, or experience in a market (e.g., growing customer base, expanding customer usage, avoiding customer churn)
4+ years experience disrupting a market for a product, feature, or experience (e.g., competitive disruption, taking the place of an established competing product)
2+ years demonstrated technical depth with LLM Systems and agent orchestration
3+ years demonstrated experience driving security initiatives, implementing robust security measures, and ensuring the protection of products and customer data
Track record of delivering complex, cross-team initiatives with measurable customer and/or security impact
Written and verbal communication skills, with the ability to influence and align senior stakeholders across engineering and business
Demonstrated ability to operate independently, manage multiple workstreams, and drive execution in a fast-paced environment
Technical depth across Microsoft Security products (e.g., Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps) and how customers deploy them in enterprise environments
Understanding of agentic AI risks (e.g., jailbreaks, prompt injection, toolchain misuse) and threat-driven engineering practices
Prior experience in cybersecurity (e.g., detection/response, security engineering, offensive security, red teaming, or penetration testing)