Senior Security Product Manager

53 Minutes ago • 5-10 Years • Cyber Security

About the job

Job Description

The Senior Security Product Manager at Microsoft AI (MAI) will collaborate with product engineering to innovate software design, defending against emerging threats. This role requires advising teams on security design, proactively identifying vulnerabilities, and collaborating on solutions. The ideal candidate will partner with engineering, pen testers, and security personnel, acting as a subject matter expert and mentor. Responsibilities include being the security contact for new services, specifying new security controls, researching new technologies, driving a positive security culture, training engineering teams, and working with security engineering to implement controls and automation. Experience with the Security Development Lifecycle (SDL), security assessments on web and mobile applications, and cloud services is crucial. The role involves working on products like Edge, Microsoft Search, Bing, News, Maps, and Advertising.
Must have:
  • 5+ years in product/program management or software development
  • 5+ years in security development/engineering
  • 5+ years hands-on experience with SDL
  • Experience conducting security assessments
  • Security Development Lifecycle (SDL) expertise
Good to have:
  • OWASP ASVS/Top 10, CWE 25 experience
  • Experience with security libraries and controls
  • Familiarity with web proxies (Burp, ZAP, Fiddler)
  • Java, Ruby, Ruby on Rails, GraphQL, REST experience
Perks:
  • Industry-leading healthcare
  • Educational resources
  • Discounts on products and services
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Networking opportunities

Overview

Security is foundational to all product and service offerings from Microsoft. MAI needs an experienced Senior Security Product Manager with a deep-rooted passion in identifying security issues before they impact millions of users. As part of the Microsoft AI (MAI) Security team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape.


As a core member of the Application Security team, you will advise teams on critical security design elements, proactively identify architectural vulnerabilities and collaborate on solutions and design modifications to improve the overall security posture of MAI offerings. You will partner with product engineering, pen testers and security personnel, acting as a subject matter expert and mentor to others on the security discipline.

Start your journey with Edge, Microsoft Search and Bing, Microsoft News, Microsoft Maps and Microsoft Advertising today!

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Qualifications

Required Qualifications

  • Bachelor's Degree AND 5+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • 5+ years experience in security development and engineering, security consulting, or application penetration testing.
  • 5+ years of hands-on and strong experience with the Security Development Lifecycle (SDL.)
  • Experience conducting security assessments on Web Applications, Mobile Applications, Cloud Services running on variety of operating systems including containers.

Preferred Qualifications

  • Experience with application security standards such as OWASP ASVS/Top 10, CWE 25.
  • Experience with common security libraries, security controls, and common security flaws.
  • Familiarity with web proxies such as Burp, OWASP ZAP or Fiddler.
  • Development or scripting experience. Java, Ruby, Ruby on Rails, GraphQL, REST.

 

Product Management IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.


Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: 

Microsoft will accept applications and process offers for these roles on an ongoing basis. 

 

 

 

#ApplicationSecurity

Responsibilities

  • Be the security contact for teams building new innovative services and technologies in the next version of Microsoft AI.
  • Specify new security controls needed to reduce risks identified from security reviews and threat modelling exercises or from security incidents and specify these new controls as requirements to be added the organization’s SDL process.
  • Proactively research new technologies, make technology recommendations.
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice.
  • Work with our security engineering team and product teams to identify, define and implement security controls and automation.
  • Leverage a broad and current understanding of security to envision new protections.
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect
View Full Job Description
$117.2K - $229.2K/yr (Outscal est.)
$173.2K/yr avg.
Redmond, Washington, United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Barcelona, Catalonia, Spain (On-Site)

New York, New York, United States (On-Site)

Mountain View, California, United States (On-Site)

Redmond, Washington, United States (On-Site)

Redmond, Washington, United States (On-Site)

Redmond, Washington, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Similar Jobs

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Microsoft - Senior Engineering Manager

Microsoft, India (On-Site)

White Hat Gaming  - Scala Developer

White Hat Gaming , (Remote)

Luxoft - GCP Senior DevOps Engineer

Luxoft, India (Remote)

Interactive Brokers - Data Engineer

Interactive Brokers, Hungary (Hybrid)

Meta - Software Engineer, Infrastructure

Meta, United States (Remote)

Google - Software Engineer, Google Ads

Google, India (On-Site)

Luxoft - Senior Java Developer

Luxoft, Ukraine (Remote)

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Mashgin - Senior QA Engineer

Mashgin, United States (Hybrid)

Xsolla - Technical Support Specialist

Xsolla, United States (On-Site)

Lionsgate Games - Manager, Post Production

Lionsgate Games, United States (On-Site)

The Walt Disney Company - Disney Store: Sales Associate (PT)

The Walt Disney Company, United States (On-Site)

Axon - Senior Privacy Engineer

Axon, United States (Hybrid)

Magnopus - Technical Artist - Generative AI

Magnopus, United States (On-Site)

Meta - Software Engineer (Android OS - Embedded)

Meta, United States (On-Site)

Trek - Production Tech

Trek, United States (On-Site)

Match Group - Sr. Product Manager, Safety Experience

Match Group, United States (Hybrid)

Get notifed when new similar jobs are uploaded