Senior Security Product Manager

23 Minutes ago • 5-7 Years • Cyber Security • $117,200 PA - $250,200 PA

Job Summary

Job Description

Microsoft's Application Security Team seeks a Senior Security Product Manager in Redmond, WA. This role requires a deep understanding of security development and the Security Development Lifecycle (SDL). Responsibilities include acting as the security contact for new AI services, specifying security controls, conducting threat modeling, proactively researching new technologies, driving a security culture within engineering teams, training developers, and working with security engineering and product teams to implement security controls and automation. The ideal candidate will have a strong background in application security, threat modeling, security assessments, and collaboration. Experience with OWASP, CWE, and common security libraries is crucial. This is a full-time position.
Must have:
  • 5+ years experience in security development/engineering
  • Strong experience with SDL
  • Security threat modeling experience
  • Experience with security assessments
  • Knowledge of OWASP, CWE
  • Excellent collaboration skills
Good to have:
  • Experience with security compliance programs
  • Familiarity with web proxies (Burp, ZAP, Fiddler)
  • Coding skills (Java, Ruby, etc.)
  • Experience managing complex projects

Job Details

Overview

Our Application Security Team is currently hiring a Senior Security Product Manager in Redmond, WA.

 

Security is foundational to all product and service offerings from Microsoft. Microsoft’s Secure Futures Initiative is the number one priority for the company. We need an experienced security professional with a deep-rooted passion in identifying security issues before they impact millions of users. As part of the Microsoft AI Security team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape. 

Application Security team, advises on critical security design elements, proactively identifying architectural vulnerabilities and collaborates on solutions and design modifications to improve the overall security posture of Microsoft AI (Artificial Intelligence) offerings.

This team partners with product engineering, penetration testers and security personnel,

Team members are subject matter experts and are a mentor to others on the security discipline. 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

 

Start your journey with Microsoft AI, Microsoft Edge, Microsoft Search and Bing, Microsoft News, Microsoft Maps and Microsoft Advertising today! 

Qualifications

Required/Minimum Qualifications:

  • Bachelor’s Degree AND 5+ years experience in product/service/project/program management or software development
    • OR equivalent experience
  • 5+ years experience in security development and engineering, security consulting, or application penetration testing. 
  • 5+ years of hands-on and strong experience with the Security Development Lifecycle (SDL). 

Additional or Preferred Qualifications 

  • Bachelor's Degree AND 7+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • Experience with Security threat modeling for new features.  
  • Experience conducting security assessments on Web Applications, Mobile Applications, Cloud Services running on variety of operating systems including containers. 
  • Experience with application security standards such as OWASP(Open Web Application Security Project ASVS (Application Security Verification Standard)/Top 10, CWE (Common Weakness Enumeration) 25.  
  • Experience with common security libraries, security controls, and common security flaws.   
  • Outstanding collaboration and partnership skills, with proven ability to drive results across teams.  
  • Coding skills in one or more general purpose scripting languages.
  • Experience managing security compliance related engineering programs. 
  • Familiarity with web proxies such as Burp, OWASP ZAP (Zed Attack Proxy) or Fiddler.  
  • Development or scripting experience. Java, Ruby, Ruby on Rails, GraphQL, REST.  
  • Demonstrated experience in successfully designing, delivering, and iterating on complex projects with a diverse set of stakeholders

 

Product Management IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until September 8, 2024. 

 

 

 

#Search# #MAI# #Security# #ApplicationSecurity# #MAIFundamentals# //platformjobs

Responsibilities

  • Be the security contact for teams building new innovative services and technologies in the next version of Microsoft AI. 
  • Specify new security controls needed to reduce risks identified from security reviews and threat modelling exercises or from security incidents and specify these new controls as requirements to be added the organization’s SDL process. 
  • Proactively research new technologies, make technology recommendations. 
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice. 
  • Work with our security engineering team and product teams to identify, define and implement security controls and automation 
  • Leverage a broad and current understanding of security to envision new protections and baseline secure by design behavior 

Other

  • Embody our    

Similar Jobs

Google - Customer Engineer, Google Maps, Geo Enterprise Sales

Google

London, England, United Kingdom (On-Site)
20 Hours ago
ByteDance - Senior Software Engineer - Developer Infrastructure

ByteDance

San Jose, California, United States (On-Site)
3 Weeks ago
NVIDIA - Senior Site Reliability Engineer - GPU Cloud

NVIDIA

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Meta - Production Engineering

Meta

Fremont, California, United States (On-Site)
5 Months ago
Canva - Senior Backend Engineer (Java) Design at Scale - Teams and Education

Canva

Sydney, New South Wales, Australia (Remote)
1 Month ago
Microsoft - Principal Product Manager

Microsoft

Redmond, Washington, United States (On-Site)
1 Day ago
The Walt Disney Company - Information Security and Compliance Analyst

The Walt Disney Company

Hong Kong (On-Site)
5 Months ago
CloudLinux - Senior Python Developer with Security Expertise

CloudLinux

Sofia City Province, Bulgaria (Remote)
3 Weeks ago
PwC - IN-Senior Manager – ERP - Sales-Ms Dynamics– Advisory  - Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Maliyo Games - Unity Game Developer

Maliyo Games

Nigeria (On-Site)
5 Months ago
Google - Software Engineer III, Front End, Google Cloud

Google

San Francisco, California, United States (On-Site)
20 Hours ago
Google - Software Engineer III, Android Partner Engineering

Google

Warsaw, Masovian Voivodeship, Poland (On-Site)
19 Hours ago
Riot Games - Staff Software Engineer (Services) - League of Legends, Motivations

Riot Games

Dublin, County Dublin, Ireland (On-Site)
5 Months ago
Google - Software Engineering Manager II, Google Cloud Compute

Google

Kirkland, Washington, United States (On-Site)
21 Hours ago
Microsoft - Senior Software Engineer - C/C++

Microsoft

Hyderabad, Telangana, India (On-Site)
1 Day ago
ByteDance - Backend Software Engineer - Global E-Commerce Supply Chain Inventory

ByteDance

San Jose, California, United States (On-Site)
5 Months ago
Playrix - Lead SDET

Playrix

Montenegro (Remote)
5 Months ago
Microsoft - Member of Technical Staff, AI - Pre-Training

Microsoft

Redmond, Washington, United States (On-Site)
3 Weeks ago
Microsoft - Senior Software Engineer - Optical Network Agents & Automation Platforms

Microsoft

Redmond, Washington, United States (On-Site)
38 Minutes ago

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Rocket Science - Bookkeeper (Part-Time)

Rocket Science

Albany, New York, United States (Hybrid)
2 Weeks ago
Trek - Service Technician (Part-Time)

Trek

Alamo, California, United States (On-Site)
2 Months ago
Google - Senior Interaction Designer, Google Cloud, Networking UX

Google

Kirkland, Washington, United States (On-Site)
21 Hours ago
NVIDIA - Senior Software Engineer, VLSI Design Tools

NVIDIA

Austin, Texas, United States (On-Site)
1 Month ago
NVIDIA - Senior Industrial Designer

NVIDIA

Santa Clara, California, United States (On-Site)
6 Days ago
Meta - Technical Game Designer

Meta

San Francisco, California, United States (Remote)
5 Months ago
Backbone - Senior Consumer Insights Marketing Researcher

Backbone

Atherton, California, United States (Hybrid)
9 Months ago
Ness Digital - Senior Kubernetes Engineer

Ness Digital

United States (Remote)
1 Week ago
ByteDance - Student Researcher (Doubao (Seed) - Foundation Model - MultiModal Generative Model)

ByteDance

San Jose, California, United States (On-Site)
3 Weeks ago
Wind River Systems - Star Lab - Principal Technologist - Embedded Security Professional Services

Wind River Systems

United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Data Protection Expert

PwC

Prague, Prague, Czechia (Hybrid)
4 Months ago
PwC - Senior Security Engineers (Entra ID/AD)

PwC

Sofia, Sofia City Province, Bulgaria (On-Site)
6 Months ago
Google - Senior Product Manager, Cloud Networking

Google

Sunnyvale, California, United States (On-Site)
19 Hours ago
Microsoft - Senior Software Engineer - CTO Office of Microsoft Security

Microsoft

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Day ago
Google - Software Engineer III, Security/Privacy, Production PKI

Google

Kirkland, Washington, United States (On-Site)
22 Hours ago
Google - Senior Analyst, Mandiant Intelligence Delivery

Google

Tokyo, Japan (On-Site)
20 Hours ago
PwC - Manager - System and Process Assurance

PwC

Colombo, Western Province, Sri Lanka (On-Site)
6 Months ago
Imagineio - Senior IT Specialist

Imagineio

New Delhi, Delhi, India (On-Site)
1 Month ago
PwC - Consultoría I Consultor Senior Ciberseguridad OT

PwC

Madrid, Community Of Madrid, Spain (On-Site)
6 Months ago
PwC - IN-Associate_Salesforce _ Enterprise Apps SFDC_Advisory_ Pan India

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Redmond, Washington, United States (On-Site)

Hyderabad, Telangana, India (On-Site)

São Paulo, State Of São Paulo, Brazil (On-Site)

Redmond, Washington, United States (On-Site)

Prague, Prague, Czechia (On-Site)

Beijing, Beijing, China (On-Site)

Redmond, Washington, United States (On-Site)

Stockholm, Stockholm County, Sweden (On-Site)

Sydney, New South Wales, Australia (On-Site)

Mountain View, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug