About this role
<b>Overview</b><br><div><p>Do you want to shape how privacy and data protection work across one of the world’s largest commercial businesses? </p><p> </p></div><div><p>The Trust and Integrity Protection (TrIP) organization enables Microsoft’s commercial business to grow with trust by translating privacy and data protection requirements into clear decisions, durable controls, and measurable outcomes. We are seeking a senior individual contributor to serve as the Privacy Program Owner and architect for the business spanning global sales, consulting, and technical support. </p><p> </p></div><div><p>You will set the strategy and target state for the privacy and data protection program, assess whether it is operating effectively, and lead the management of systemic and emerging risk. This is a lead individual-contributor role—not a people-manager position—with broad influence across business, legal, engineering, compliance, and privacy teams. </p><p> </p></div><div><p>This opportunity is ideal for a privacy leader who combines deep subject-matter expertise, strong business judgment, and an architect’s mindset. You will create clarity in ambiguity, modernize how the program operates, and help the business move faster while protecting data and earning trust.</p><p> </p><p>Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.</p></div><br><br><b>Responsibilities</b><br><div><p> </p><ul style="list-style-type: disc;"><li><p>Set the program strategy and architecture. Define the vision, priorities, operating model, and multiyear roadmap for privacy and data protection across sales, consulting, and technical support. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Own program effectiveness. Establish governance, controls, accountability, metrics, and assurance mechanisms that demonstrate compliance with the Microsoft Privacy Standard and applicable legal, regulatory, contractual, and industry requirements. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Lead privacy risk management. Identify, aggregate, assess, and prioritize systemic, emerging, and business-specific privacy risks; recommend pragmatic treatments; and drive mitigation through accountable business and technical owners. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Translate obligations into scalable solutions. Convert complex privacy requirements into actionable business guidance, technical patterns, control designs, and privacy-by-design practices that teams can implement consistently. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Modernize and simplify the program. Use AI, automation, telemetry, and Microsoft technologies to reduce manual effort, strengthen evidence, accelerate risk reduction, and improve the stakeholder experience. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Orchestrate a federated privacy model. Align distributed privacy, legal, engineering, risk, compliance, and business teams around common standards, priorities, and outcomes without relying on direct authority. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Advise senior leaders. Provide clear, decision-ready insights on risk posture, control effectiveness, regulatory change, investment priorities, and opportunities to enable responsible business growth. </p></li></ul><p> </p></div><div><ul style="list-style-type: disc;"><li><p>Represent the program with credibility. Serve as a trusted privacy authority with customers, auditors, regulators, legal partners, and Microsoft leaders when addressing complex data protection matters. </p></li></ul><p> </p></div><br><br><b>Qualifications</b><br><div><p>Required Qualifications </p><ul><li>Bachelor's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, or related field AND 6+ years experience in risk management, privacy, security, compliance, government intelligence, operations, auditing, and/or finance OR equivalent experience.</li></ul><p> </p></div><div><p>Preferred Qualifications </p><ul><li>Master's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, or related field AND 8+ years experience in risk management in the context of operations, engineering, information technology, business analyst, consulting, auditing, privacy, security, compliance, government intelligence, and/or finance OR Bachelor's Degree in Risk Management, Engineering, Government Intelligence, Security, Cybersecurity, or Information Technology, or related field AND 12+ years experience in risk management in the context of operations, engineering, information technology, business analyst, consulting, auditing, privacy, security, compliance, government intelligence, and/or finance OR equivalent experience.</li><li>Membership with a relevant risk domain area association including: International Association of Privacy Professionals (IAPP), International Information System Security Certification Consortium (ISC)2, and Information Systems Audit and Control Association (ISACA), Certified Internal Auditor (CIA), Society for Corporate Compliance and Ethics (SCCE), Disaster Recovery Institute (DRI), Certified Business Continuity Professional (CBCB), Committee of Sponsoring Organizations of the Treadway Commission (COSO), and Institute of Internal Auditors (IIA).</li><li>Experience with AI, AI-based analytical tools, AI governance, and AI governance frameworks.</li><li>Experience with privacy program architecture, control design, testing, metrics, dashboards, audit readiness, and regulatory documentation such as DPIAs and records of processing activities, particularly in relation to Data Processor activities</li><li>Experience in dealing with complex third-party privacy sub processor scenarios</li><li>Understanding of cloud services, enterprise data ecosystems, and the privacy considerations associated with AI and emerging technologies.</li><li>Excellent judgment and communication skills, with the ability to make complex privacy risks clear and actionable for technical, legal, and executive audiences.</li><li>6+ years of experience in privacy, data protection, risk management, security, compliance, audit, operations, or a related field; OR a bachelor’s degree and 4+ years of relevant experience; OR equivalent experience.</li><li>Demonstrated experience designing, leading, or materially transforming a privacy or data protection program in a large, complex, matrixed organization.</li><li>Knowledge of global privacy and data protection obligations, privacy-by-design principles, data governance, privacy risk assessment, and accountability frameworks.</li><li>Experience translating legal, regulatory, contractual, or policy requirements into practical business processes, technical requirements, and scalable controls.</li><li>Proven ability to influence senior leaders and cross-functional teams, create structure in ambiguity, and drive outcomes without direct authority. </li></ul></div> <br><br><p>Risk Management IC5 - The typical base pay range for this role across the U.S. is USD $116,900 - $203,600 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $148,400 - $222,600 per year. </p><p></p> <p>Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:<br><a href="https://careers.microsoft.com/us/en/us-corporate-pay">https://careers.microsoft.com/us/en/us-corporate-pay</a></p><br><p>This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.</p><br><hr><br><p>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about <a href="https://careers.microsoft.com/v2/global/en/accessibility.html"><b><u>requesting accommodations.</u></b></a></p>