Senior Security Product Manager

4 Days ago • 5-7 Years • Cyber Security • $117,200 PA - $250,200 PA

Job Summary

Job Description

Microsoft's Application Security Team seeks a Senior Security Product Manager in Redmond, WA. This role requires a deep understanding of security development and the Security Development Lifecycle (SDL). Responsibilities include acting as the security contact for new AI services, specifying security controls, conducting threat modeling, proactively researching new technologies, driving a security culture within engineering teams, training developers, and working with security engineering and product teams to implement security controls and automation. The ideal candidate will have a strong background in application security, threat modeling, security assessments, and collaboration. Experience with OWASP, CWE, and common security libraries is crucial. This is a full-time position.
Must have:
  • 5+ years experience in security development/engineering
  • Strong experience with SDL
  • Security threat modeling experience
  • Experience with security assessments
  • Knowledge of OWASP, CWE
  • Excellent collaboration skills
Good to have:
  • Experience with security compliance programs
  • Familiarity with web proxies (Burp, ZAP, Fiddler)
  • Coding skills (Java, Ruby, etc.)
  • Experience managing complex projects

Job Details

Overview

Our Application Security Team is currently hiring a Senior Security Product Manager in Redmond, WA.

 

Security is foundational to all product and service offerings from Microsoft. Microsoft’s Secure Futures Initiative is the number one priority for the company. We need an experienced security professional with a deep-rooted passion in identifying security issues before they impact millions of users. As part of the Microsoft AI Security team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape. 

Application Security team, advises on critical security design elements, proactively identifying architectural vulnerabilities and collaborates on solutions and design modifications to improve the overall security posture of Microsoft AI (Artificial Intelligence) offerings.

This team partners with product engineering, penetration testers and security personnel,

Team members are subject matter experts and are a mentor to others on the security discipline. 

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

 

Start your journey with Microsoft AI, Microsoft Edge, Microsoft Search and Bing, Microsoft News, Microsoft Maps and Microsoft Advertising today! 

Qualifications

Required/Minimum Qualifications:

  • Bachelor’s Degree AND 5+ years experience in product/service/project/program management or software development
    • OR equivalent experience
  • 5+ years experience in security development and engineering, security consulting, or application penetration testing. 
  • 5+ years of hands-on and strong experience with the Security Development Lifecycle (SDL). 

Additional or Preferred Qualifications 

  • Bachelor's Degree AND 7+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • Experience with Security threat modeling for new features.  
  • Experience conducting security assessments on Web Applications, Mobile Applications, Cloud Services running on variety of operating systems including containers. 
  • Experience with application security standards such as OWASP(Open Web Application Security Project ASVS (Application Security Verification Standard)/Top 10, CWE (Common Weakness Enumeration) 25.  
  • Experience with common security libraries, security controls, and common security flaws.   
  • Outstanding collaboration and partnership skills, with proven ability to drive results across teams.  
  • Coding skills in one or more general purpose scripting languages.
  • Experience managing security compliance related engineering programs. 
  • Familiarity with web proxies such as Burp, OWASP ZAP (Zed Attack Proxy) or Fiddler.  
  • Development or scripting experience. Java, Ruby, Ruby on Rails, GraphQL, REST.  
  • Demonstrated experience in successfully designing, delivering, and iterating on complex projects with a diverse set of stakeholders

 

Product Management IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:

Microsoft will accept applications for the role until September 8, 2024. 

 

 

 

#Search# #MAI# #Security# #ApplicationSecurity# #MAIFundamentals# //platformjobs

Responsibilities

  • Be the security contact for teams building new innovative services and technologies in the next version of Microsoft AI. 
  • Specify new security controls needed to reduce risks identified from security reviews and threat modelling exercises or from security incidents and specify these new controls as requirements to be added the organization’s SDL process. 
  • Proactively research new technologies, make technology recommendations. 
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn to identify security bad practice. 
  • Work with our security engineering team and product teams to identify, define and implement security controls and automation 
  • Leverage a broad and current understanding of security to envision new protections and baseline secure by design behavior 

Other

  • Embody our    

Similar Jobs

Next Level Business Services - Java/J2EE Developer

Next Level Business Services

San Diego, California, United States (On-Site)
6 Months ago
Rackspace Technology - Frontend Engineer (UX-Focused)

Rackspace Technology

Gurugram, Haryana, India (Remote)
3 Weeks ago
Tesla - Senior Automation Engineer, Drive Unit

Tesla

Brandenburg, Germany (On-Site)
2 Months ago
Google - Software Engineer, gReach Program for People with Disabilities

Google

Seoul, South Korea (On-Site)
1 Week ago
Google - Software Engineer III, Engineering Productivity

Google

New York, New York, United States (On-Site)
5 Days ago
ByteDance - Principle Security Engineer, Enterprise Security

ByteDance

San Jose, California, United States (On-Site)
1 Week ago
Google - Senior Security Engineer, Vulnerability Coordination Center

Google

Dublin, County Dublin, Ireland (On-Site)
4 Days ago
Google - Security Engineering Manager, Android Malware Analysis

Google

Bengaluru, Karnataka, India (On-Site)
4 Days ago
FCM Travel - Team Lead, IS Security Lead- Asia

FCM Travel

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Meta - Product Security Engineer

Meta

Washington, District Of Columbia, United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

ION - Software Developer/Engineer - Graduate Development Program

ION

Milan, Lombardy, Italy (On-Site)
6 Months ago
Riot Games - Senior Manager, Software Engineering - League Studio, Build, Test, Ship

Riot Games

Los Angeles, California, United States (On-Site)
4 Weeks ago
CapSpire - Senior Consultant – Endur Technical

CapSpire

Bengaluru, Karnataka, India (Remote)
5 Months ago
Next Level Business Services - UX Developer

Next Level Business Services

Redmond, Washington, United States (On-Site)
6 Months ago
Google - Senior Software Engineering Manager, Google Ads

Google

New York, New York, United States (On-Site)
4 Days ago
Google - Senior Firmware Engineering Manager, GSOC, Platforms Infrastructure Engineering

Google

Warsaw, Masovian Voivodeship, Poland (On-Site)
3 Days ago
Google - Software Engineering Manager II, Google Cloud Compute

Google

Kirkland, Washington, United States (On-Site)
4 Days ago
Epic Games - Senior QA Programmer

Epic Games

Vancouver, British Columbia, Canada (On-Site)
2 Months ago
Google - Software Engineering Manager, AICore, Applied ML

Google

Taipei City, Taiwan (On-Site)
4 Days ago
Google - Software Engineering Intern, 2025

Google

Tokyo, Japan (On-Site)
4 Days ago

Get notifed when new similar jobs are uploaded

Jobs in Redmond, Washington, United States

Inworld AI - Staff C++ Engineer

Inworld AI

Mountain View, California, United States (On-Site)
1 Month ago
Google - Strategy and Operations Senior Associate, Agency and Partner Go-to-Market

Google

New York, New York, United States (On-Site)
4 Days ago
ByteDance - Software Engineer, Distributed Storage System

ByteDance

Seattle, Washington, United States (On-Site)
3 Weeks ago
Nagarro - Associate Staff Consultant, Operations

Nagarro

Atlanta, Georgia, United States (On-Site)
6 Months ago
Warner Bros Games - Lead Environment Artist

Warner Bros Games

Chicago, Illinois, United States (Hybrid)
4 Days ago
Netflix - Product Manager, ML Platform: Training

Netflix

Los Gatos, California, United States (Hybrid)
5 Months ago
The Walt Disney Company - Senior Software Engineer (Swift)

The Walt Disney Company

Seattle, Washington, United States (On-Site)
1 Week ago
Google - Field Sales Representative, Enterprise Greenfield, Healthcare, Google Cloud

Google

New York, New York, United States (On-Site)
1 Day ago
Google - Data Product Manager, Partnership Management, YouTube

Google

New York, New York, United States (On-Site)
4 Days ago
Google - Technical Program Manager II, Hardware Supply Chain, Pixel

Google

Mountain View, California, United States (On-Site)
4 Days ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - ETC, Oracle Technical Consultant - Senior Associate

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
5 Months ago
Microsoft - Site Reliability Engineer

Microsoft

Redmond, Washington, United States (On-Site)
2 Hours ago
CloudLinux - Senior Python/Go Developer for Imunify360

CloudLinux

Masovian Voivodeship, Poland (Remote)
3 Weeks ago
Roofstacks - Senior Cyber Security Engineer

Roofstacks

İstanbul, İstanbul, Türkiye (On-Site)
3 Weeks ago
PwC - Auditor Riesgo y Cumplimiento

PwC

Managua, Managua, Nicaragua (On-Site)
6 Months ago
PwC - Associate - IFS - IT Infrastructure

PwC

Jakarta, Jakarta, Indonesia (On-Site)
4 Months ago
Trend Micro - Automotive Research Engineer - Threat Intelligence & Content Creation (VicOne)

Trend Micro

Taipei City, Taiwan (On-Site)
6 Months ago
PwC - Financial Sector Cyber Security Strategy Manager

PwC

Amsterdam, North Holland, Netherlands (Hybrid)
3 Months ago
N-iX - Senior Cybersecurity Engineer

N-iX

(Remote)
1 Week ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.
View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug