OA-Senior Security Product Manager

1 Day ago • 5-7 Years • Cyber Security

About the job

Job Description

Microsoft's Application Security Team seeks a Senior Security Product Manager in Redmond, WA to contribute to their Secure Futures Initiative. The role involves collaborating with product engineering to improve the security of Microsoft AI offerings. Responsibilities include acting as the security contact for new services, specifying security controls, conducting threat modeling, researching new technologies, driving a security-focused culture, training engineers, and working with security engineering and product teams to implement controls and automation. The ideal candidate possesses extensive experience in security development, the SDL, security assessments, and threat modeling, along with strong collaboration and communication skills.
Must have:
  • 5+ years in security development/engineering
  • 5+ years experience with SDL
  • Experience with threat modeling
  • Security assessments on web/mobile apps and cloud services
  • Knowledge of OWASP, ASVS, CWE
  • Strong collaboration skills
Good to have:
  • Experience managing security compliance programs
  • Familiarity with Burp, OWASP ZAP, or Fiddler
  • Coding skills (Java, Ruby, etc.)
  • Experience with GraphQL, REST
Perks:
  • Industry-leading healthcare
  • Educational resources
  • Product and service discounts
  • Savings and investment programs
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Networking opportunities

Overview

Our Application Security Team is currently hiring a Senior Security Product Manager in Redmond, WA.

 

Security is foundational to all product and service offerings from Microsoft. Microsoft’s Secure Futures Initiative is the number one priority for the company. We need an experienced security professional with a deep-rooted passion in identifying security issues before they impact millions of users. As part of the Microsoft AI Security team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape. 

Application Security team, advises on critical security design elements, proactively identifying architectural vulnerabilities and collaborates on solutions and design modifications to improve the overall security posture of Microsoft AI (Artificial Intelligence) offerings.

This team partners with product engineering, penetration testers and security personnel,

Team members are subject matter experts and are a mentor to others on the security discipline. 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

 

Start your journey with Microsoft AI, Microsoft Edge, Microsoft Search and Bing, Microsoft News, Microsoft Maps and Microsoft Advertising today! 

Qualifications

Required/Minimum Qualifications:

  • Bachelor’s Degree AND 5+ years experience in product/service/project/program management or software development
    • OR equivalent experience
  • 5+ years experience in security development and engineering, security consulting, or application penetration testing. 
  • 5+ years of hands-on and strong experience with the Security Development Lifecycle (SDL). 

Additional or Preferred Qualifications 

  • Bachelor's Degree AND 7+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • Experience with Security threat modeling for new features.  
  • Experience conducting security assessments on Web Applications, Mobile Applications, Cloud Services running on variety of operating systems including containers. 
  • Experience with application security standards such as OWASP(Open Web Application Security Project ASVS (Application Security Verification Standard)/Top 10, CWE (Common Weakness Enumeration) 25.  
  • Experience with common security libraries, security controls, and common security flaws.   
  • Outstanding collaboration and partnership skills, with proven ability to drive results across teams.  
  • Coding skills in one or more general purpose scripting languages.
  • Experience managing security compliance related engineering programs. 
  • Familiarity with web proxies such as Burp, OWASP ZAP (Zed Attack Proxy) or Fiddler.  
  • Development or scripting experience. Java, Ruby, Ruby on Rails, GraphQL, REST.  
  • Demonstrated experience in successfully designing, delivering, and iterating on complex projects with a diverse set of stakeholders

 

Product Management IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until September 8, 2024. 

 

 

 

#Search# #MAI# #Security# #ApplicationSecurity# #MAIFundamentals# //platformjobs

Responsibilities

  • Be the security contact for teams building new innovative services and technologies in the next version of Microsoft AI. 
  • Specify new security controls needed to reduce risks identified from security reviews and threat modelling exercises or from security incidents and specify these new controls as requirements to be added the organization’s SDL process. 
  • Proactively research new technologies, make technology recommendations. 
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice. 
  • Work with our security engineering team and product teams to identify, define and implement security controls and automation 
  • Leverage a broad and current understanding of security to envision new protections and baseline secure by design behavior 

Other

  • Embody our    
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect
View Full Job Description
$117.2K - $229.2K/yr (Outscal est.)
$173.2K/yr avg.
Redmond, Washington, United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Cambridge, Massachusetts, United States (On-Site)

Redmond, Washington, United States (On-Site)

Redmond, Washington, United States (On-Site)

London, England, United Kingdom (On-Site)

Redmond, Washington, United States (On-Site)

Bengaluru, Karnataka, India (On-Site)

Santiago, Santiago Metropolitan Region, Chile (On-Site)

Redmond, Washington, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Similar Jobs

Cadence - Principal Cloud Engineer

Cadence, India (On-Site)

Next Level Business Services - JAVA DEVELOPER

Next Level Business Services, United States (On-Site)

Cognitree - Senior Software Engineer

Cognitree, India (Hybrid)

Infoblox - Senior Staff Resident Engineer

Infoblox, United States (On-Site)

Palosade - Founding Threat Research Engineer

Palosade, India (Hybrid)

Razer - Senior Cybersecurity Specialist

Razer, Malaysia (On-Site)

Rackspace Technology - GRC Governance Specialist

Rackspace Technology, Mexico (Remote)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Rockstar Games - Senior Build & Release Engineer

Rockstar Games, United States (On-Site)

Nagarro - Staff Engineer, Java Fullstack

Nagarro, India (Remote)

DigitalOcean - Senior Software Engineer (Hyderabad)

DigitalOcean, India (Hybrid)

Info Stretch - Graduate Software Engineer

Info Stretch, United Kingdom (On-Site)

Zuora - Econometric Data Scientist

Zuora, India (Hybrid)

Luxoft - Senior Angular/Java Full-Stack Developer

Luxoft, United States (Remote)

Nielsen Holdings - SENIOR SOFTWARE DEVELOPER

Nielsen Holdings, India (Hybrid)

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Netflix - Manager, Threat Management & Investigations

Netflix, United States (On-Site)

Unity - IT Operations Specialist

Unity, United States (On-Site)

Netflix - Production Health & Safety Manager - Albuquerque

Netflix, United States (On-Site)

Patel greene - Drainage Group Leader

Patel greene, United States (On-Site)

Activision - Staff Backend Engineer - Activision Blizzard Media

Activision, United States (On-Site)

eBay - ML Staff Software Engineer - Risk

eBay, United States (Hybrid)

Onward Search - Inside Sales Manager

Onward Search, United States (On-Site)

Warner Bros Discovery - Assistant Manager, Brand + Activation, TNT Live Events

Warner Bros Discovery, United States (On-Site)

IGN - Senior Full Stack Software Engineer

IGN, United States (Hybrid)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Get notifed when new similar jobs are uploaded