About this role
<b>Overview</b><br><p>The Windows Trust Experiences & Compliance (TEC) team is seeking a <strong>Senior Product Manager </strong>- Security & Compliance<strong> </strong>to define and drive the vision, strategy, roadmap, and adoption of security and compliance capabilities across the Windows ecosystem.</p><p>This role requires a solid technical security foundation and the ability to serve as a trusted Security SME, influencing product direction and engineering decisions across Windows platforms, services, engineering systems, secure software supply chains, and emerging AI engineering environments. The ideal candidate combines deep security expertise with product leadership to translate complex security, customer, and regulatory requirements into scalable platform capabilities, strategic investments, and measurable business outcomes that strengthen Windows security posture and regulatory readiness.</p><p>Impact</p><p>This role shapes the future of trust, security, and compliance across Windows by defining product strategy, roadmap priorities, and platform capabilities needed to meet evolving security threats, customer expectations, and regulatory requirements.</p><p>The successful candidate will be recognized as a technical security leader and trusted advisor who influences product direction across Windows platforms, services, engineering systems, and secure software supply chains while driving adoption and business impact through scalable security and compliance solutions.</p><p>Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.</p><br><br><b>Responsibilities</b><br><ul><li>Own the vision, strategy, roadmap, and investment priorities for Windows security compliance and assurance capabilities.</li><li>Serve as a Security SME and trusted advisor across platform, services, application, infrastructure, and secure software supply chain security domains.</li><li>Identify security and compliance gaps and define product investments that improve Windows security posture and regulatory readiness.</li><li>Drive prioritization and investment decisions across competing security, compliance, customer, and engineering needs, balancing risk, impact, customer value, and business outcomes.</li><li>Translate complex security, customer, and regulatory requirements into scalable platform capabilities, product requirements, and engineering investments.</li><li>Partner with engineering teams to design and deliver secure-by-design, compliance-by-design, and AI-enabled capabilities that improve security assurance, governance efficiency, and audit readiness.</li><li>Influence architecture and engineering decisions across Windows products, services, build infrastructure, release systems, signing systems, and engineering platforms.</li><li>Drive security assurance and compliance readiness for Cybersecurity EO, CRA, PQC/CNSA, SDL, SFI, FedRAMP, FIPS, and future regulatory requirements.</li><li>Define success metrics and use data-driven insights to drive adoption, prioritization, investment decisions, and continuous improvement in trust, auditability, and compliance readiness.</li></ul><br><br><b>Qualifications</b><br><p><strong>Required Qualifications: </strong></p><ul><li>Bachelor's Degree AND 5+ years experience in product/service/program management or software development.<ul style="list-style-type: circle;"><li>OR equivalent experience.</li></ul></li></ul><p><strong>Preferred Qualifications:</strong></p><ul><li>6+ years of experience in Product Management, Security Engineering, Security Architecture, Technical Program Management, or related fields.</li><li>Solid technical expertise in platform, services, application, and infrastructure security, including build infrastructure, CI/CD systems, secure software supply chains, release engineering, signing services, artifact management, and AI/ML development environments.</li><li>Experience driving product strategy, roadmap development, and execution for security, platform, infrastructure, or developer-focused capabilities.</li><li>Ability to serve as a trusted Security SME and influence architecture, product strategy, investment decisions, and engineering priorities across complex technical domains.</li><li>Experience leading cross-functional initiatives involving engineering, security, compliance, and executive stakeholders.</li><li>Solid knowledge of security architecture, secure development practices, threat modeling, vulnerability management, and security assurance principles.</li><li>Familiarity with EU CRA, Cybersecurity EO, NIST, FedRAMP, FIPS, PQC/CNSA, or similar security and regulatory frameworks.</li><li>Excellent executive communication, stakeholder management, and cross-organizational leadership skills.</li><li>Experience with operating systems, developer platforms, cloud services, or large-scale engineering infrastructure.</li><li>Experience working on secure software supply chain, release engineering, code-signing, build systems, or engineering platform security initiatives.</li><li>Familiarity with AI/ML security, model development environments, and AI governance considerations.</li></ul><p> </p><p> </p><p> </p><p>#W+DJOBS</p> <br><br><p>Product Management IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year. </p><p></p> <p>Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:<br><a href="https://careers.microsoft.com/us/en/us-corporate-pay">https://careers.microsoft.com/us/en/us-corporate-pay</a></p><br><p>This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.</p><br><hr><br><p>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about <a href="https://careers.microsoft.com/v2/global/en/accessibility.html"><b><u>requesting accommodations.</u></b></a></p>