Team Overview:
The mission of the Microsoft CISO Organization is to defend Microsoft, our customers, and our partners from cybersecurity threats. Our strategy is grounded in advanced threat intelligence, proactive threat hunting, resilient security operations, sustainable governance, and use of AI to anticipate, detect, and respond to even the most sophisticated attacks.
The CISO Operations Security Implementation & Capability (OSIC) team plays a critical role in turning the CISO strategy into reality. OSIC is responsible for scaling, systematizing, and operationalizing cybersecurity initiatives across the CISO Organization and across Microsoft. OSIC ensures that cybersecurity programs are well-designed, consistently executed, measurable, and sustainable at Microsoft’s global scale.
Role Overview
We are seeking a Principal Technical Program Manager to join our CISO Operations Security Implementation & Capability (OSIC) team. You will lead complex, cross-organizational cybersecurity programs from problem definition and planning through execution, adoption, and measurable outcomes. You will translate strategic priorities into clear program plans, operating mechanisms, governance, roadmaps, and success measures; use AI, telemetry, and other evidence to improve decisions and delivery; and manage priorities, risks, dependencies, and tradeoffs amid ambiguity. You will partner with technical, business, and senior leadership stakeholders to build alignment, remove blockers, and drive accountability. Your work will establish repeatable capabilities that strengthen CISO operations and scale effective practices across Microsoft.
Responsibilities
Translate CISO strategic priorities into executable programs by framing problems, defining outcomes and success measures, establishing governance, mapping dependencies, and creating clear roadmaps and delivery plans.
Build repeatable processes, automated workflows, and reusable program mechanisms that improve execution across participating teams and can be adopted by adjacent programs.
Lead complex, cross-organization initiatives by aligning engineering, security, operations, risk and compliance, and leadership around shared goals, decisions, dependencies, and measurable outcomes.
Leverage AI, telemetry, and data-driven insights to improve speed, accuracy, and impact of program decisions, execution, and operating mechanisms.
Create executive-ready materials and narratives that synthesize complex technical and operational inputs into clear program status, risks, options, tradeoffs, and recommendations for leadership decisions.
Qualifications
Required Qualifications:
- Bachelor's Degree AND 6+ years experience in engineering, product/technical program management, data analysis, or product development
- OR equivalent experience.
- 3+ years of experience managing cross-functional and/or cross-team projects.
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. 1324b(a)(3)) for assessment of eligibility to access the export controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.
- Citizenship & Citizenship Verification: This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport.
Preferred Qualifications:
Experience implementing security governance, or risk and compliance programs by translating policy, risk assessments, controls, audit requirements, and leadership oversight into scalable operating mechanisms and program execution.
Deep technical fluency in cybersecurity or adjacent technical domains, with the ability to understand architecture and risk, ask informed questions, and translate effectively between technical experts and business stakeholders.
Experience coordinating significant security incident or operational crisis workstreams, including stakeholder communication, cross-team execution, post-incident learning, and delivery of durable remediation.
Demonstrated experience independently leading complex, high-impact, cross-functional programs through ambiguity, competing priorities, and evolving requirements, from problem definition and planning through execution, adoption, and measurable outcomes.
Strong leadership and influence skills, with a demonstrated ability to align senior stakeholders and diverse technical and business teams, resolve conflicting priorities, and drive accountability across organizational boundaries without formal authority.
Strong executive communication capability, including experience framing complex technical and operational program issues, presenting options and tradeoffs, and providing clear recommendations to senior leaders.
Demonstrated ability to diagnose complex and unfamiliar program problems and apply structured thinking, experimentation, and sound judgment to establish a path forward under uncertainty.
Strong analytical and systems-thinking skills, with the ability to identify dependencies, risks, leverage points, and unintended consequences and translate qualitative and quantitative evidence into clear program recommendations.
Demonstrated ability to lead multiple concurrent, related initiatives in a fast-paced environment, managing priorities, dependencies, and resource constraints while sustaining accountability for outcomes.
#OSIC #CISO_Ops
Technical Program Management IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- Bachelor's degree and 6+ years of experience in engineering, product or technical program management, data analysis, or product development, or equivalent experience.
- 3+ years of experience managing cross-functional and/or cross-team projects.
- Ability to meet Microsoft, customer, and/or government security screening requirements.
- Pass the Microsoft Cloud Background Check upon hire or transfer and every two years thereafter.
- Provide citizenship, permanent residency, or other protected-status documentation for export-control eligibility assessment.
- Verify citizenship when required for government customer-related legal restrictions.
- Experience implementing security governance or risk and compliance programs.
- Deep technical fluency in cybersecurity or adjacent technical domains.
- Experience coordinating significant security incident or operational crisis workstreams.
- Experience independently leading complex, high-impact, cross-functional programs through ambiguity.
- Strong leadership, influence, stakeholder alignment, and accountability-driving skills.
- Strong executive communication skills, including presenting options, tradeoffs, and recommendations.
- Ability to diagnose unfamiliar program problems and apply structured thinking under uncertainty.
- Strong analytical and systems-thinking skills involving dependencies, risks, and evidence-based recommendations.
- Ability to lead multiple concurrent initiatives while managing priorities, dependencies, and resource constraints.
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.







