Principal Security Product Manager

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Product Management

Product Manager for Windows Security, focusing on driving security innovations and strategy. The role involves leading OS-level security features, influencing architecture, and managing cross-functional programs. While the role encourages using AI tools for product management and embedding AI in workflows, its core function is not building AI models but rather applying AI to enhance security product development and strategy within the Windows OS.

What you'd actually do

  1. Lead development of OS-level security features, ensuring they evolve to meet emerging threats and hardware capabilities.
  2. Influence Windows security architecture and strategy, driving defense-in-depth and secure-by-default principles.
  3. Collaborate across engineering, security response, and partner teams to accelerate vulnerability resolution and deliver proactive security investments.
  4. Manage complex, cross-functional programs with clear milestones, data-driven prioritization, and strong execution.
  5. Communicate program vision and status to technical and executive audiences, fostering alignment and trust.

Skills

Required

  • Bachelor's Degree AND 8+ years experience in product/service/program management or software development
  • Ability to meet Microsoft, customer and/or government security screening requirements

Nice to have

  • 10+ years product management or equivalent experience shipping enterprise platform/infra products.
  • CS/EE or related technical degree.
  • Deep expertise in OS-level security (firmware/boot process, TPM, identity, cryptography).
  • Track record of calmly managing critical security incidents or rapid response situations.
  • Demonstrated ability to use generative AI in all phases of product management from research to prototyping.
  • Strategic thinker with experience defining product roadmaps or multi-year technical strategy.
  • Strong analytical problem-solving skills; attention to detail in risk assessment and mitigation planning.
  • Knowledge of Windows internals and key security technologies (kernel, authentication, update mechanisms).
  • Proven ability to lead large, ambiguous projects and deliver results across multiple orgs/stakeholders.
  • Experience driving cybersecurity initiatives and defense-in-depth improvements in software programs.
  • Excellent communication and executive presentation skills for technical and non-technical audiences.

What the JD emphasized

  • deeply technical PM
  • operating system security
  • cross functional, cross-organization programs
  • security-minded team
  • strategic collaboration
  • OS-level security features
  • Windows security architecture and strategy
  • vulnerability resolution
  • cross-functional programs
  • security screening requirements
  • Deep expertise in OS-level security
  • managing critical security incidents
  • generative AI in all phases of product management
  • cybersecurity initiatives