Sr Director, Security Strategy & Risk

Redmond, Washington, United States

Microsoft

Entdecken Sie Microsoft-Produkte und -Dienste für Ihr Zuhause oder Ihr Unternehmen. Microsoft 365, Copilot, Teams, Xbox, Windows, Azure, Surface und mehr kaufen

View all jobs at Microsoft

Apply now Apply later

Do you enjoy working on unique security solutions for a variety of areas related to Gaming? If so, the Gaming Security team would like to talk to you. 

We are the Gaming Security team. Our team supports the services, platform, and studios that make up the Gaming business.  In addition, we work with other Security teams within the company to ensure that we have the right tools and services to protect these key businesses.  We are looking for a Senior Director to help with leading strategic security initiatives and risk management by partnering and engaging with leaders and engineering teams across the organization. 

The successful candidate will have passion for security, risk management, collaboration skills, technical depth, coupled with the ability to bring others together in building cross-organization solutions.  Effective communication skills and the ability to thrive in an ambiguous and dynamic environment are necessary. Candidates should represent the growth mindset and display Microsoft cultural values in day-to-day activities. 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Drive continuous innovation in strategic security offerings including design, deployment, and management of AI security solutions. 
  • Lead functions related to cybersecurity risk management and compliance, shaping strategic vision for Microsoft Gaming risk program and continually improving the program in response to changing threats and industry trends. 
  • Operationalize GRC capability areas including policy and exception management, maturity assessment, external audits and enterprise security risk management 
  • Develop and oversee the governance structure for integrating cyber risk into the enterprise risk management framework. Ensure cyber risks are aligned with overall business risks and priorities and that appropriate risk mitigation strategies are in place with a governance framework that supports risk-based decision-making and prioritization. 
  • Establish key metrics and reporting mechanisms to regularly update leadership on the organization’s cyber risk posture and mitigation effectiveness. Provide clear, actionable reporting that connects cyber risks to business outcomes and organizational objectives. 
  • Develop and deliver the GRC strategic roadmap and investment plan addressing People, Process, and Technology 
  • Build partnerships with Senior IT Management, Internal Audit, Ethics and Compliance, Enterprise Risk, relevant business units, and third-party vendors to ensure compliance awareness and responsibilities. 
  • Lead the creation of Information Security Policies, technical standards and procedures for secure technology configuration and implementation. 
  • Lead and grow a global team of cybersecurity professionals, managing risk, compliance, assessments, reporting, metrics, and policies 
  • Oversee validation of risk assessments, control designs, gap identification, test scripts, evidence, and compensating controls. 
  • Lead the execution of the information security strategy, ensuring alignment with overall business objectives, and will define and communicate security policies, procedures, and standards across the organization 

 

Qualifications

Minimum Qualifications 

 

  • 6+ years of experience managing cross-functional and/or cross-team projects.
  • Bachelor's Degree AND 8+ years experience in engineering, product/technical program management, data analysis, or product development OR equivalent experience.
  • 5+ years people management experience.
  • 5+ years experience with cybersecurity risk frameworks and industry standards and regulations (NIST, PCI, ISO and GDPR), including the ability to lead the execution and implementation of frameworks and articulate their value and purpose. 

 

Preferred Qualifications 

  • Bachelor's Degree AND 12+ years experience in engineering, product/technical program management, data analysis, or product development 
    • OR equivalent experience. 
  • 6+ years people management experience. 
  • Proven leadership in enterprise-level information with 15 years of experience in Cybersecurity and GRC  
  • 10+ years experience managing cross-functional and/or cross-team projects. 
  • 1+ year(s) experience reading and/or writing code (e.g., sample documentation, product demos). 
  • Demonstrated experience and success in senior leadership roles such as CISO or risk management leader at global organizations/consulting companies 
  • Proven track record of promoting and collaborating on risk and compliance policies and practices across IT and organizational business units. 
  • Demonstrative organizational, project management, communication, and stakeholder management skills, particularly at the executive leadership level. 
  • Understanding of cybersecurity risk management and control principles, with a proven ability to anticipate and identify risks and effective mitigating actions.
  • Ability to determine and set the strategic direction of the Cybersecurity functions, including managing expectations and delivering results 
  • Ability to translate complex technical information into strategic insights for technical leaders and simplify it for senior business leaders  
  • Experience developing, tracking, and reporting key KRIs and KPIs.
  • Proficient in written and verbal communication and ability to partner for success across all levels of organization and technical depths. 
  • Customer-first, business-savvy, and holds a growth mindset to uphold our culture and values. 

Technical Program Management M6 - The typical base pay range for this role across the U.S. is USD $161,600 - $286,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $209,600 - $314,400 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

Microsoft will accept applications for the role until March 10, 2025. 

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.  We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.

 

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.

Apply now Apply later
Job stats:  0  0  0

Tags: Audits CISO Compliance GDPR Governance KPIs NIST Risk assessment Risk management RMF Security strategy Strategy

Perks/benefits: Career development Medical leave Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.