Microsoft's US Public Sector Industries team partners with more than 18,500 law enforcement agencies across the United States, and the justice organizations they work with, to modernize public safety securely on Azure Government, Microsoft 365 Government, and Microsoft's AI platform.
As Microsoft's Principal Criminal Justice Information Services (CJIS) Lead, you will be the CJIS authority for the company: the voice that speaks for Microsoft on CJIS Security Policy obligations with the FBI CJIS Division, the U.S. Department of Justice, state CJIS Systems Agencies, and the agencies we serve. You will help shape CJIS policy as it evolves, translate it into clear, defensible guidance for Microsoft's engineering, compliance, legal, and field teams, and stand behind Microsoft's position in audits, agreements, and customer engagements. This opportunity will allow you to influence national policy at the intersection of public safety and cloud, partner with Microsoft's compliance, legal, and engineering leaders, and set the standard for how a hyperscale cloud provider serves the criminal justice community. This role is US-based with location flexibility and includes travel to state agencies, the FBI CJIS Division, and industry events.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
- Serve as Microsoft's designated CJIS authority and primary contact for the FBI CJIS Division, the Department of Justice, and state CJIS Systems Officers and Information Security Officers; represent Microsoft in the CJIS Advisory Policy Board process, working groups, and industry forums to help shape the CJIS Security Policy.
- Own Microsoft's interpretation of the CJIS Security Policy across Azure Government, Microsoft 365 Government Community Cloud (GCC), Dynamics 365, and Microsoft AI services; maintain shared-responsibility guidance, National Institute of Standards and Technology (NIST) IST SP 800-53 control mappings, and policy-to-product crosswalks for engineering, compliance, legal, and field teams.
- Partner with Microsoft's legal and compliance organizations on the CJIS Security Addendum, Management Control Agreements, and state-specific agreements, advising on acceptable language, state exceptions, personnel screening, and audit obligations.
- Lead Microsoft's response to state and FBI CJIS audits and formal inquiries, coordinating evidence on encryption, advanced authentication, audit logging, incident response, and personnel screening.
- Serve as the field's escalation point for complex CJIS questions from agencies and partners; brief chiefs, sheriffs, and CJIS Systems Officers; and keep Microsoft's public CJIS documentation accurate and current.
- Build Microsoft's CJIS knowledge base and readiness program for sellers, solution engineers, partners, and support, and drive product feedback to engineering on control gaps and roadmap priorities.
Monitor CJIS Security Policy releases, NIST and Federal Information Processing Standards (FIPS) transitions, and state legislation, and publish thought leadership that positions Microsoft as a trusted partner for public safety and justice.
Qualifications
Required Qualifications:
- Bachelor's Degree in Criminal Justice, Information Security, Computer Science, or related field AND 8+ years experience in program management, process management, or process improvement
- OR equivalent experience.
Other Qualification:
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- Citizenship & Citizenship Verification: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance.
- CJIS Personnel Screening: Ability to complete and maintain state fingerprint-based background checks and CJIS Security Awareness Training as required by the CJIS Security Policy.
Preferred Qualifications:
Proven demonstrated expertise in the FBI CJIS Security Policy (versions 5.9.x through 6.x) and its Requirements Companion Document, including the CJIS Security Addendum,
Management Control Agreements, personnel screening, security awareness training, and the audit process.Experience working directly with the FBI CJIS Division, a state CJIS Systems Agency, or the CJIS Advisory Policy Board process, and communicating complex security and policy requirements to executive, legal, and technical audiences.
Current or former State CJIS Systems Officer (CSO), CJIS Information Security Officer (ISO), CSA auditor, or FBI CJIS Division experience, including participation in Advisory Policy Board working groups or the Compact Council.
Working knowledge of cloud technical controls and compliance programs across major platforms (Microsoft Azure and Azure Government, AWS, Google Cloud), including FedRAMP High, StateRAMP, NIST SP 800-53 Rev. 5, FIPS 140-3 encryption and key management, identity and multifactor authentication, logging and monitoring, and shared-responsibility models.
Industry certifications such as CISSP, CISM, CISA, CCSP, or CRISC, and familiarity with adjacent public sector frameworks such as IRS Publication 1075, HIPAA, and the NIST Cybersecurity Framework.
Established credibility across the criminal justice community (for example IACP, National Sheriffs' Association, Major Cities Chiefs Association, SEARCH, IJIS Institute, and Nlets) and a record of shaping policy, publishing, or speaking on criminal justice information security, with the ability to influence across legal, engineering, compliance, and sales organizations.
Business Program Management IC6 - The typical base pay range for this role across the U.S. is USD $130,900 - $277,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $165,600 - $303,600 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- Bachelor's degree in Criminal Justice, Information Security, Computer Science, or a related field, plus 8 or more years of experience in program management, process management, or process improvement; equivalent experience accepted.
- Pass the Microsoft Cloud background check upon hire or transfer and every two years thereafter.
- Verify U.S. citizenship due to citizenship-based legal restrictions.
- Complete and maintain state fingerprint-based background checks and CJIS Security Awareness Training as required.
- Demonstrated expertise in the FBI CJIS Security Policy versions 5.9.x through 6.x and its Requirements Companion Document.
- Experience working directly with the FBI CJIS Division, a state CJIS Systems Agency, or the CJIS Advisory Policy Board process.
- Experience communicating complex security and policy requirements to executive, legal, and technical audiences.
- Current or former State CJIS Systems Officer, CJIS Information Security Officer, CSA auditor, or FBI CJIS Division experience.
- Working knowledge of cloud technical controls and compliance programs across Azure, Azure Government, AWS, and Google Cloud.
- Knowledge of FedRAMP High, StateRAMP, NIST SP 800-53 Revision 5, FIPS 140-3 encryption and key management, identity and multifactor authentication, logging and monitoring, and shared-responsibility models.
- Industry certification such as CISSP, CISM, CISA, CCSP, or CRISC.
- Familiarity with IRS Publication 1075, HIPAA, and the NIST Cybersecurity Framework.
- Established credibility across the criminal justice community and a record of shaping policy, publishing, or speaking on criminal justice information security.
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.








