Expoint - all jobs in one place

The point where experts and best companies meet

Limitless High-tech career opportunities - Expoint

Microsoft Senior Security Product Manager 
United States, Washington 
133703278

10.09.2024

inRedmond, WA.

Security is foundational to all product and service offerings from Microsoft.Microsoft’s Secure Futures Initiative is the number one priority for the company.security issues before theymillions of users. As part of the Microsoft AI Security team, you will collaborate with product engineering to innovate software design to defend against a continued and emerging security threat landscape.

and collaborates on solutions and design modifications to improve the overall security posture of Microsoft AI (Artificial Intelligence) offerings.

testers and security personnel,

the security discipline.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Required/Minimum Qualifications:

  • Bachelor’s Degree AND 5+ years experience in product/service/project/program management or software development
    • OR equivalent experience
  • 5+years experiencein security development and engineering, security consulting, or application penetration testing.
  • 5+ years of hands-on and strong experience with the Security Development Lifecycle (SDL).

Additional or Preferred Qualifications

  • Bachelor's Degree AND 7+ years experience in product/service/project/program management or software development
    • OR equivalent experience.
  • Experience with Security threat modeling for new features.
  • Experience conducting security assessments on Web Applications, Mobile Applications, Cloud Servicesrunning on variety of operating systems including containers.
  • Experience with application security standards such as OWASP(Open Web Application Security Project ASVS (Application Security Verification Standard)/Top 10, CWE (Common Weakness Enumeration) 25.
  • Experience with common security libraries, security controls, and common security flaws.
  • Outstanding collaboration and partnership skills, with proven ability to drive results across teams.
  • Coding skills in one or more general purpose scripting languages.
  • Experience managing security compliance related engineering programs.
  • Familiarity with web proxies such as Burp, OWASP ZAP (Zed Attack Proxy) or Fiddler.
  • Development or scripting experience. Java, Ruby, Ruby on Rails,GraphQL, REST.
  • Demonstrated experience in successfully designing, delivering, and iterating on complex projects with a diverse set of stakeholders

Product Management IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:Microsoft will accept applications for the role until September 8, 2024.


Responsibilities
  • Be the security contact for teams building new innovative services and technologies in the next version of Microsoft AI.
  • Specify new security controls needed to reduce risksidentifiedfrom security reviews and threat modelling exercises or from security incidents and specify these new controls as requirements to beaddedthe organization’s SDL process.
  • Proactively researchnew technologies, make technology recommendations.
  • Drive and cultivate a positive culture of security across the engineering teams. Train product engineering to recognize bad patterns and innovate ways for developers to learn toidentifysecurity badpractice.
  • identify,defineand implement security controls and automation
  • Leverage a broad and current understanding of security to envision new protectionsand baseline secure by design
  • Embody our