Senior Technical Program Manager, Security Compliance
Microsoft (Eightfold Apply)
- Location
- United States, Multiple Locations, Multiple Locations
- Work model
- On-Site
- Level
- Senior
- Posted
- 3h ago
Skills
About this role
Overview
Do you thrive in environments where clarity, rigor, and evidence drive impact? Are you energized by strengthening enterprise controls, improving assurance processes, and making control health visible across complex organizations? This role is for you. CISO Governance Risk and Compliance (GRC), part of Microsoft Cloud + AI and the Office of the CISO, protects Microsoft by strengthening cybersecurity governance, ensuring regulatory compliance, and managing risk with clarity and accountability. We are evolving our Controls Assurance Platform (CAP) to meet increasing regulatory expectations, audit scrutiny, and enterprise scale. We are hiring a Senior Technical Program Manager, Security Compliance to serve as a Controls Assurance Owner, responsible for maturing CAP’s governance, cadence, and evidence lifecycle. In this role, you will anchor the assurance layer for cybersecurity, driving execution consistency, improving evidence quality, and ensuring readiness for internal and external audits. You will partner closely with engineering, security, privacy, and legal stakeholders to strengthen control health and build sustainable compliance processes that scale. You will thrive here if you operate with outward confidence, think in evidence, and bring structure to ambiguity. You will help shape the future of CAP and ensure Microsoft is prepared for regulatory change, audit cycles, and enterprise growth. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
Own CAP assurance — Mature the Controls Assurance Platform (CAP) by strengthening governance, cadence, and evidence lifecycle for Security’s enterprise control environment. Drive audit readiness — Ensure CAP controls, evidence, and processes meet internal, external, and regulatory audit expectations with precision and urgency. Verify control alignment — Validate that controls and evidence meet compliance, regulatory, and policy requirements in partnership with control owners. Strengthen control health — Improve control design, execution consistency, and evidence quality across engineering, security, privacy, legal, and CISO stakeholders. Coordinate stakeholders — Partner across CISO, security, privacy, legal, and engineering teams to ensure alignment and unblock dependencies. Lead CAP audit support — Serve as the primary TPM interface for CAP‑related audit activities, ensuring timely, structured, and transparent evidence delivery. Communicate clearly — Deliver clear, confident, executive‑calibrated communications on control health, audit status, risks, and remediation progress.
Qualifications
Required Qualifications: Bachelor's Degree AND 4+ years experience in engineering, product/technical program management, data analysis, or product development OR equivalent experience. 2+ years of experience managing cross-functional and/or cross-team projects. Other Requirements: Candidates must be able to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications
Bachelor's Degree AND 8+ years in technical program management, security compliance, risk management, or regulated program delivery OR equivalent