Senior Technical Program Manager, Security Compliance
IT, Operations, Compliance / Regulatory
United States
Do you thrive in environments where clarity, rigor, and evidence drive impact? Are you energized by strengthening enterprise controls, improving assurance processes, and making control health visible across complex organizations? This role is for you.
CISO Governance Risk and Compliance (GRC), part of Microsoft Cloud + AI and the Office of the CISO, protects Microsoft by strengthening cybersecurity governance, ensuring regulatory compliance, and managing risk with clarity and accountability. We are evolving our Controls Assurance Platform (CAP) to meet increasing regulatory expectations, audit scrutiny, and enterprise scale.
We are hiring a Senior Technical Program Manager, Security Compliance to serve as a Controls Assurance Owner, responsible for maturing CAP’s governance, cadence, and evidence lifecycle. In this role, you will anchor the assurance layer for cybersecurity, driving execution consistency, improving evidence quality, and ensuring readiness for internal and external audits. You will partner closely with engineering, security, privacy, and legal stakeholders to strengthen control health and build sustainable compliance processes that scale.
You will thrive here if you operate with outward confidence, think in evidence, and bring structure to ambiguity. You will help shape the future of CAP and ensure Microsoft is prepared for regulatory change, audit cycles, and enterprise growth.
Responsibilities
- Own CAP assurance — Mature the Controls Assurance Platform (CAP) by strengthening governance, cadence, and evidence lifecycle for Security’s enterprise control environment.
- Drive audit readiness — Ensure CAP controls, evidence, and processes meet internal, external, and regulatory audit expectations with precision and urgency.
- Verify control alignment — Validate that controls and evidence meet compliance, regulatory, and policy requirements in partnership with control owners.
- Strengthen control health — Improve control design, execution consistency, and evidence quality across engineering, security, privacy, legal, and CISO stakeholders.
- Coordinate stakeholders — Partner across CISO, security, privacy, legal, and engineering teams to ensure alignment and unblock dependencies.
- Lead CAP audit support — Serve as the primary TPM interface for CAP‑related audit activities, ensuring timely, structured, and transparent evidence delivery.
- Communicate clearly — Deliver clear, confident, executive‑calibrated communications on control health, audit status, risks, and remediation progress.
Qualifications
Required Qualifications:
- Bachelor's Degree AND 4+ years experience in engineering, product/technical program management, data analysis, or product development
- OR equivalent experience.
- 2+ years of experience managing cross-functional and/or cross-team projects.
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- Bachelor's Degree AND 8+ years in technical program management, security compliance, risk management, or regulated program delivery
- OR equivalent experience.
- 6+ years managing cross‑functional programs across engineering, security, privacy, or compliance teams.
- 3+ years providing executive‑level communications and program updates.
- Experience driving programs in regulated or high‑risk domains (security, privacy, compliance, AI governance).
- Proven ability to collaborate across diverse business stakeholders to achieve results and impact.
- Experience coordinating across engineering, privacy, and legal stakeholders to deliver program outcomes.
- Ability to bring clarity to ambiguous regulatory or compliance requirements and drive actionable program plans.
- Demonstrated success building structure in undefined or rapidly evolving problem spaces.
#CISOGRC
Technical Program Management IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.