Director, Security Risk & Compliance

1 Month ago • 8-13 Years • Cyber Security • $129,200 PA - $299,400 PA

Job Summary

Job Description

The Director, Security Risk & Compliance at Microsoft will enhance the company's security ecosystem by designing, implementing, and overseeing risk management practices. This role requires strong understanding of cybersecurity standards (like NIST CSF 800-53), regulatory engagement, and preparing for Microsoft's security risk management program. Responsibilities include designing risk management services, conducting enterprise-wide security risk assessments, implementing risk management processes, and collaborating with cross-functional teams. The ideal candidate possesses extensive experience in cybersecurity risk management, compliance, and regulatory readiness, alongside strong analytical, problem-solving, and leadership skills. Experience with cloud technologies and agile methodologies is also crucial.
Must have:
  • 8+ years experience in security/risk management
  • NIST CSF knowledge
  • Regulatory engagement experience
  • Risk assessment & mitigation
  • Process design & implementation
  • Cross-functional team collaboration
Good to have:
  • Cloud technology knowledge
  • Agile methodologies experience
  • Continuous monitoring experience
  • IT system assurance & audit practices
Perks:
  • Industry leading healthcare
  • Educational resources
  • Discounts on products and services
  • Savings and investments
  • Maternity and paternity leave
  • Generous time away
  • Giving programs
  • Networking opportunities

Job Details

Overview

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.

 

Microsoft CISO Organization’s Governance, Risk Management, and Compliance team is seeking a Director, Security Risk & Compliance to focus on enhancing Microsoft’s security ecosystem by bringing design and process implementation and oversight to risk management practices. This role will be heavily pivoted towards an understanding and leverage of cybersecurity industry standards, like NIST CSF 800-53. This candidate will have regulatory industry engagement and be an integral part of the preparation and readiness of Microsoft security risk management program. This is a fast-paced, exciting role with an opportunity to bring your leadership, energy, and ideas into one of the most critical priorities for the Microsoft and industry.

 

We are seeking a highly-motivated individual who is passionate about modern, technical solutions to risk and compliance challenges and is hungry to contribute with both depth and breadth, navigating often from leadership oversight to hands on execution. The ideal candidate will possess experience in managing or contributing to the management of enterprise-scale compliance, risk and operational business process and programs, along with experience designing and operating programs at scale, agile methodologies, industry standards within the security space, knowledge of software engineering processes, and has experience delivering results in a complex and matrixed organization.  You will help the team drive change and innovation while partnering with other risk and compliance teams around the company, delivering results across multiple engineering partners. Commitment to staying abreast of current industry trends, regulatory changes and the ability to adapt to quickly evolving business needs and organizational changes is a must.


Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

 

Successful candidates can be located anywhere in the U.S.

Qualifications

Required Qualifications:

  • Bachelor’s degree in Engineering, Information Systems, Law, Criminology/Criminal Justice, Finance or related field AND 8+ years of experience in security, risk management, compliance, security, resilience or related fields
    • OR equivalent experience.

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: 

  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Preferred Qualifications: 

  • 5+ years of experience in cybersecurity risk management and compliance, including regulation readiness, frontline engagement with regulators, and process design.
  • analytical, problem-solving, and decision-making skills, including ability to pull business insights and trends from risk management data and information.
  • Experience working in cross-functional teams and collaborating with multiple internal organizations.
  • Knowledge of risk management practices, including ability to understand risk, support prioritization, and ensure accountability for risk disposition and mitigation.
  • Project management skills, with the ability to prioritize work efforts, manage multiple tasks simultaneously, and drive accountability across project teams.
  • Knowledge of cloud technologies and their impact on security, resilience and compliance.
  • Experience with continuous monitoring, assurance of IT systems, and audit practices for compliance purposes.
  • Leadership and team management skills

Business Program Management IC6 - The typical base pay range for this role across the U.S. is USD $129,200 - $273,400 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $162,000 - $299,400 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until January 3, 2025

 

#cisoorg #mssecurity #compliance #riskmanagement #nist

Responsibilities

  • Design of governance, risk management, and compliance risk management services and capabilitie, implement and drive adoption of these designs in the form of requirements and process.
  • Drive (design and execution) cross-enterprise security risk assessments, such as NIST CSF, and provide insights and recommendations to our Deputy CISOs, plus understanding and guiding mitigation of our top risks.
  • Plan, implement, and oversee execution of risk management processes, including scaling as-is processes for increased coverage, quality, speed, and output using operational and technology-based approaches.
  • Embody our and
Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect

Similar Jobs

GameDuell - Game Producer (LiveOps) - Mobile Games (f/m/d)

GameDuell

Berlin, Berlin, Germany (Hybrid)
3 Months ago
NetApp - Principal Software Engineer (UI Architect)

NetApp

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Captions - Research Engineer, Machine Learning

Captions

New York, New York, United States (On-Site)
1 Month ago
Sling TV - Staff Engineer - Site Reliability Engineer

Sling TV

Hyderabad, Telangana, India (On-Site)
4 Months ago
ZeroFox - Physical Security Analyst

ZeroFox

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Google - Security Engineer, Cloud Detection

Google

(On-Site)
1 Month ago
Hasbro - Global Security Auditor

Hasbro

Shenzhen, Guangdong Province, China (On-Site)
2 Months ago
Axinous - Principal Software Development Engineer

Axinous

Bengaluru, Karnataka, India (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Google - Silicon Test Engineering Manager

Google

(On-Site)
1 Month ago
PwC - AES SAP OTC -DSD Manager Operate

PwC

Hyderabad, Telangana, India (On-Site)
3 Months ago
Info Stretch - QA Engineer (Manual)

Info Stretch

Canada (On-Site)
1 Month ago
Worlds - Motion Graphics Artist

Worlds

(Remote)
5 Months ago
Nissan - Field Quality Engineer 1

Nissan

Smyrna, Tennessee, United States (On-Site)
2 Months ago
Tsavorite Scalable Intelligence - Hiring Software, Firmware, RTL, Verification, FPGA and Physical Design Engineers

Tsavorite Scalable Intelligence

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Match Group - Process Lead, Global Escalations

Match Group

New York, New York, United States (Hybrid)
3 Months ago
The Walt Disney Company - Sr Software Engineer (Roku/BrightScript/SceneGraph)

The Walt Disney Company

Santa Monica, California, United States (On-Site)
2 Months ago
Magic Media - Business Development Manager

Magic Media

Prague, Prague, Czechia (Remote)
2 Months ago
Saviynt - Senior Integration Engineer

Saviynt

Bengaluru, Karnataka, India (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in undefined

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Cyber Security Jobs

ByteDance - Data Security Manager -Security Governance and Compliance- San Jose

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
PwC - Penetration Tester

PwC

Prague, Prague, Czechia (On-Site)
3 Months ago
PwC - IN_Associate_SmartCitiesGIS _Cities_Advisory_Ahmedabad

PwC

Ahmedabad, Gujarat, India (On-Site)
2 Months ago
PwC - Senior Associate - Risk Assurance - IT Cybersecurity

PwC

Jakarta, Jakarta, Indonesia (On-Site)
4 Months ago
Palo Alto Networks - Solutions Consultant - Strategic Accounts

Palo Alto Networks

London, England, United Kingdom (On-Site)
2 Months ago
Luxoft - Splunk SME

Luxoft

(Remote)
1 Month ago
Omnissa - Member of technical staff (Appsecurity, Pentesting)

Omnissa

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
PwC - Auditor Riesgo y Cumplimiento

PwC

Managua, Managua, Nicaragua (On-Site)
4 Months ago
PwC - IN_Associate_SOC L1/L2_Managed Services_Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago
Palo Alto Networks - Domain Consultant - Security Operations Transformation

Palo Alto Networks

New York, New York, United States (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Milan, Lombardy, Italy (On-Site)

Gurugram, Haryana, India (On-Site)

Prague, Prague, Czechia (On-Site)

Montreal, Quebec, Canada (On-Site)

Dublin, County Dublin, Ireland (On-Site)

London, England, United Kingdom (On-Site)

Virginia, United States (On-Site)

Hyderabad, Telangana, India (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug