Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
The mission of Microsoft Digital Security & Resilience (DSR) is to enable Microsoft to build the most trusted devices and services, while keeping our company safe and our data protected. As part of the Microsoft Security organization, and a steward of Microsoft and our customer's data, a core function of Microsoft DSR is ensuring the security of every aspect of the business.
The DSR team is seeking a Senior Director, Security & Resilience Compliance. In this role, you will be responsible for driving our ability to meet our increasing regulatory compliance requirements for security and resilience across the Microsoft enterprise. You will be empowered to help the team drive change and innovation while partnering with other risk and compliance teams around the company. Your ability to seek solutions to risk and compliance challenges and staying abreast of current industry trends, and regulatory changes will be required to adapt to quickly evolving business needs and organizational changes.
Responsibilities
Work with our Legal organization to understand regulatory changes and how they impact the Digital Security and Resilience organization and then develop a plan for implementation.
Coordinate across the Microsoft enterprise with other teams on the implementation of compliance programs, including with other program leaders for Enterprise Resilience and various Security programs.
Establish and monitor key performance indicators and metrics to measure and report on the effectiveness of security and resiliency compliance activities. Anticipate future data and measurement needs.
Identify, raise awareness, and mitigate key risks in partnership with other organizations.
Coordinate activities with our external auditors including quarterly meetings, updates on incidents and other activities to meet 10K, SOX and other audit requirements.
Coordinate with other auditors to meet our regulatory obligations (e.g., DFARS, CMMC, etc.)
Drive internal security maturity assessment program (NIST) and provide insights and recommendations to our CISO and input into our top risks.
Provide guidance and support to business units and stakeholders on security and resiliency compliance matters.
Determine resourcing needs for new regulations (both for your team and other teams who will have to implement controls and other efforts to meet the regulations).
Stay abreast of emerging security and resiliency trends, threats, and regulations and provide recommendations for improvement and innovation.
Implement and implement opportunities for efficiencies and how technology (e.g., generative AI) can be used to improve our services.
People Management - Managers deliver success through empowerment and accountability by modeling, coaching, and caring.
Qualifications
Required Qualifications:
Bachelor's Degree in Science, Business, Engineering, or related field AND 8+ years experience in business, legal/regulatory, compliance, audit/consulting firmo OR equivalent experience.
8+ years of people management experience
8+ years of experience in compliance, risk management, or security
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Citizenship & Citizenship Verification: This position requires verification of U.S citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport.
Microsoft Cloud Background Check. This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
Familiarity with Agile methodologies, engineering practices, and the security and engineering lifecycle.
Knowledge of cloud technologies and their impact on security, resilience, and compliance.
Experience with continuous monitoring and auditing of IT systems for compliance purposes.
Experience working in defense, aerospace, or related industries.
Supplier/supply chain experience
Compliance M6 - The typical base pay range for this role across the U.S. is USD $124,800 - $266,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $159,000 - $292,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay
#DSR
#MSFTSecurity
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations (https://careers.microsoft.com/v2/global/en/accessibility.html) .