Principal Security Program Manager - Windows Security

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Security Assurance

This role is for a Principal Security Program Manager at Microsoft Windows Security, focusing on end-to-end security assurance, including compliance, risk assessment, vulnerability research, and security tooling. It involves platform security architecture, threat intelligence, and vulnerability discovery, with broad influence across Windows engineering and security partners. The role requires shaping how Windows identifies, prioritizes, and mitigates security risks at scale.

What you'd actually do

  1. Own the Windows EnS security risk assessment framework, driving systematic identification, prioritization, and tracking of security risks across OS, firmware, silicon, drivers, and ecosystem dependencies.
  2. Partner with engineering, architecture, and threat intelligence teams to translate emerging threats, vulnerability trends, and attacker techniques into actionable platform investments.
  3. Develop and drive the security assurance process for Windows teams utilizing a shared responsibility approach that supports the scale of the Windows org while ensuring broad compliance and a risk based approach towards scaling security review and depth engagement.
  4. Act as virtual lead for a small security PM team by managing PM coverage across the team’s charter, leading planning and engagement with EnS security engineering, and owning key cross team partnerships.

Skills

Required

  • Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • equivalent experience
  • Ability to meet Microsoft, customer and/or government security screening requirements

Nice to have

  • Ability to create clarity, energy, and cohesion across the team.
  • Ability to influence and drive security initiatives across groups.
  • 10+ years of experience in a software engineering or security-related engineering.
  • Demonstrated experience in security research, especially around vulnerability discovery.
  • Experience exploiting bugs and bypassing security mitigations in operating systems.
  • Familiarity with Microsoft Windows architecture.

What the JD emphasized

  • security compliance
  • risk assessment
  • vulnerability research
  • security tooling
  • end-to-end security assurance