This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Microsoft Windows Security team is responsible for protecting billions of Windows devices by driving platform‑level security, risk reduction, and resilient-by-design engineering across the Windows ecosystem. We are seeking a Senior Security Program Manager to lead our end‑to‑end security assurance effort including security compliance, risk assessment, and supporting our vulnerability research and security tooling efforts across Windows. This role sits at the intersection of platform security architecture, threat intelligence, vulnerability discovery, and execution, with broad influence across Windows engineering and other internal and external security assurance and research partners. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Job Responsibility:
Drive the Windows EnS security risk assessment framework by executing systematic identification, prioritization, and tracking of security risks across OS, firmware, silicon, drivers, and ecosystem dependencies
Partner deeply with engineering, architecture, and threat intelligence teams to translate emerging threats, vulnerability trends, and attacker techniques into clear, actionable insights and platform improvements
Execute and evolve the security assurance process for Windows teams, enabling a scalable, risk-based approach that supports shared responsibility while ensuring consistent security review coverage and compliance
Lead cross-team security initiatives and coordination by driving planning, aligning stakeholders, and ensuring effective PM coverage across key areas of the team’s charter
Influence without authority by building solid partnerships across EnS security engineering and partner teams, ensuring alignment on priorities, risks, and mitigation strategies
Deliver end-to-end execution on high-impact security efforts, from problem definition through implementation, tracking measurable outcomes and continuously improving processes
Requirements:
Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 3+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
OR equivalent experience
Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field
OR equivalent experience
Ability to create clarity, energy, and cohesion across the team
Ability to influence and drive security initiatives across groups
10+ years of experience in a software engineering or security-related engineering
Demonstrated experience in security research, especially around vulnerability discovery
Experience exploiting bugs and bypassing security mitigations in operating systems
Familiarity with Microsoft Windows architecture
Nice to have:
Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in security or related field
OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in security or related field
OR equivalent experience
Ability to create clarity, energy, and cohesion across the team
Ability to influence and drive security initiatives across groups
10+ years of experience in a software engineering or security-related engineering
Demonstrated experience in security research, especially around vulnerability discovery
Experience exploiting bugs and bypassing security mitigations in operating systems
Familiarity with Microsoft Windows architecture
What we offer:
Certain roles may be eligible for benefits and other compensation