Senior Security Product Manager

1 Month ago • 5-7 Years • Cyber Security • $117,200 PA - $250,200 PA

Job Summary

Job Description

The Senior Security Product Manager at Microsoft's AI Security team in Redmond, WA, will be the security contact for teams developing innovative AI services. Responsibilities include specifying new security controls, conducting threat modeling, proactively researching new technologies, driving a positive security culture, training engineering teams, and collaborating with security and product teams to implement security controls and automation. This role requires strong security development lifecycle (SDL) experience, knowledge of security standards (OWASP, ASVS, CWE), and experience with security assessments across various platforms. The ideal candidate will possess outstanding collaboration skills, coding proficiency, and experience managing security compliance programs.
Must have:
  • 5+ years security development/engineering experience
  • 5+ years SDL experience
  • Security threat modeling
  • Security assessments (Web, Mobile, Cloud)
  • OWASP, ASVS, CWE knowledge
  • Collaboration and partnership skills
Good to have:
  • Experience with security libraries and controls
  • Experience with Burp, OWASP ZAP, or Fiddler
  • Java, Ruby, Ruby on Rails, GraphQL, REST experience
  • Managing security compliance programs
Perks:
  • Industry-leading healthcare
  • Educational resources
  • Product and service discounts
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Networking opportunities

Job Details

Overview

Our Application Security Team is currently hiring a Senior Security Product Manager in Redmond, WA.

 

Security is foundational to all product and service offerings from Microsoft. Microsoft’s Secure Futures Initiative is the number one priority for the company. We need an experienced security professional with a deep-rooted passion in identifying security issues before they impact millions of users. As part of the Microsoft AI Security team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape. 

Application Security team, advises on critical security design elements, proactively identifying architectural vulnerabilities and collaborates on solutions and design modifications to improve the overall security posture of Microsoft AI (Artificial Intelligence) offerings.

This team partners with product engineering, penetration testers and security personnel,

Team members are subject matter experts and are a mentor to others on the security discipline. 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

 

Start your journey with Microsoft AI, Microsoft Edge, Microsoft Search and Bing, Microsoft News, Microsoft Maps and Microsoft Advertising today! 

Qualifications

Required/Minimum Qualifications:

  • Bachelor’s Degree AND 5+ years experience in product/service/project/program management or software development
    • OR equivalent experience
  • 5+ years experience in security development and engineering, security consulting, or application penetration testing. 
  • 5+ years of hands-on and strong experience with the Security Development Lifecycle (SDL). 

Additional or Preferred Qualifications 

  • Bachelor's Degree AND 7+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • Experience with Security threat modeling for new features.  
  • Experience conducting security assessments on Web Applications, Mobile Applications, Cloud Services running on variety of operating systems including containers. 
  • Experience with application security standards such as OWASP(Open Web Application Security Project ASVS (Application Security Verification Standard)/Top 10, CWE (Common Weakness Enumeration) 25.  
  • Experience with common security libraries, security controls, and common security flaws.   
  • Outstanding collaboration and partnership skills, with proven ability to drive results across teams.  
  • Coding skills in one or more general purpose scripting languages.
  • Experience managing security compliance related engineering programs. 
  • Familiarity with web proxies such as Burp, OWASP ZAP (Zed Attack Proxy) or Fiddler.  
  • Development or scripting experience. Java, Ruby, Ruby on Rails, GraphQL, REST.  
  • Demonstrated experience in successfully designing, delivering, and iterating on complex projects with a diverse set of stakeholders

 

Product Management IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until September 8, 2024. 

 

 

 

#Search# #MAI# #Security# #ApplicationSecurity# #MAIFundamentals# //platformjobs

Responsibilities

  • Be the security contact for teams building new innovative services and technologies in the next version of Microsoft AI. 
  • Specify new security controls needed to reduce risks identified from security reviews and threat modelling exercises or from security incidents and specify these new controls as requirements to be added the organization’s SDL process. 
  • Proactively research new technologies, make technology recommendations. 
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice. 
  • Work with our security engineering team and product teams to identify, define and implement security controls and automation 
  • Leverage a broad and current understanding of security to envision new protections and baseline secure by design behavior 

Other

  • Embody our    
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect

Similar Jobs

Microsoft - Software Engineering II

Microsoft

Hyderabad, Telangana, India (On-Site)
1 Month ago
Sinch - Senior Java Backend Developer - Malmö - Onsite

Sinch

Malmö, Skåne County, Sweden (On-Site)
4 Months ago
Next Level Business Services - Web SDLC

Next Level Business Services

Redmond, Washington, United States (On-Site)
4 Months ago
Google - Software Engineer, PhD, Early Career, Campus, 2025 Start

Google

Atlanta, Georgia, United States (On-Site)
3 Months ago
GoTo Group - Android Engineer - Comms Platform

GoTo Group

Bengaluru, Karnataka, India (On-Site)
3 Months ago
PwC - IN_Associate_IA_Internal Audit Services_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago
PwC - IN-Senior Associate_Tech Lead_FS Tech_Advisory _Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
2 Months ago
undefined - Senior Application Security Engineer

Bengaluru, Karnataka, India (On-Site)
4 Months ago
ByteDance - Data Security Manager -Security Governance and Compliance- San Jose

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
Postman - Senior Security Engineer, Detection & Response

Postman

Bengaluru, Karnataka, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

PwC - Senior Associate _ Automation Tester_ Emerging  Technologies_ Advisory_ Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
N-iX - Senior Fullstack Engineer

N-iX

Ukraine (Flexible)
1 Month ago
Life church - Core Services Staff Engineer

Life church

Edmond, Oklahoma, United States (On-Site)
4 Months ago
Google - Software Engineer, Payments

Google

(On-Site)
3 Months ago
ByteDance - Senior Solutions Engineer (Multiple Positions)

ByteDance

San Jose, California, United States (On-Site)
2 Months ago
ICIMS - Sr. Software Engineer

ICIMS

Hyderabad, Telangana, India (On-Site)
4 Months ago
PwC - IN-Senior Associate_ JAVA_Utility Transformation _Advisory_Kolkata

PwC

Kolkata, West Bengal, India (On-Site)
2 Months ago
ByteDance - Backend Software Engineer Graduate (Global E-commerce-US) - 2025 Start (BS/MS)

ByteDance

Seattle, Washington, United States (On-Site)
3 Months ago
AppLovin - Software Engineer

AppLovin

Toronto, Ontario, Canada (On-Site)
3 Months ago
PwC - Analityk biznesowy z językiem niemieckim (freelance)

PwC

Warsaw, Masovian Voivodeship, Poland (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Nintendo - Intern - Competitive Play

Nintendo

Redmond, Washington, United States (On-Site)
3 Months ago
Microsoft - Software Engineer - Fullstack, Redmond

Microsoft

Redmond, Washington, United States (On-Site)
1 Month ago
Mattel  Inc  - American Girl Los Angeles  Cook Part Time

Mattel Inc

California, United States (On-Site)
2 Months ago
Life church - Senior Program Manager

Life church

Edmond, Oklahoma, United States (On-Site)
4 Months ago
Modulate - Senior Data Engineer

Modulate

Somerville, Massachusetts, United States (Hybrid)
1 Month ago
Rackspace Technology - Practice Head - Cloud Application Services

Rackspace Technology

United States (Remote)
3 Months ago
Morning Star - Senior Software Engineer

Morning Star

Chicago, Illinois, United States (Hybrid)
4 Months ago
Scientific Games  - Tableau Architect

Scientific Games

Alpharetta, Georgia, United States (On-Site)
5 Months ago
Hedra - Research Scientist

Hedra

New York, New York, United States (On-Site)
5 Months ago
Google - Student Researcher, PhD, Winter/Summer 2025

Google

Ann Arbor, Michigan, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - CD-Cyber Security-GRC Tech-Servicenow Now GRC Developer-Senior Associate-Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Deliveroo - Software Engineer, Security

Deliveroo

Hyderabad, Telangana, India (On-Site)
4 Months ago
Wind River Systems - Star Lab - Field Applications Engineer, System Architect

Wind River Systems

Huntsville, Ontario, Canada (Hybrid)
3 Months ago
PwC - ETIC, Winter Internship Program - Cybersecurity

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
3 Months ago
InMobiInMobi - Senior Information Security Analyst (Security Operations/Incident Management)

InMobiInMobi

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Varonis  - Security Operations Center (SOC) Expert

Varonis

Morrisville, North Carolina, United States (On-Site)
3 Months ago
PwC - Associate - Kolkata Y-14 - Technology Consulting

PwC

Kolkata, West Bengal, India (On-Site)
4 Months ago
Palo Alto Networks - Prisma Cloud Solution Architect

Palo Alto Networks

Baton Rouge, Louisiana, United States (Remote)
3 Months ago
Playtech - Application Security Engineer

Playtech

Sofia, Sofia City Province, Bulgaria (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

London, England, United Kingdom (On-Site)

Mountain View, California, United States (Hybrid)

Mountain View, California, United States (Hybrid)

Mountain View, California, United States (Hybrid)

New York, New York, United States (Hybrid)

Mountain View, California, United States (Hybrid)

Mountain View, California, United States (Hybrid)

London, England, United Kingdom (On-Site)

Dublin, County Dublin, Ireland (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug