OverviewThe Windows Trust Experiences & Compliance (TEC) team is seeking a
Senior Product Manager to define and drive the vision, strategy, roadmap, and adoption of security and compliance capabilities across the Windows ecosystem.
This role requires a solid technical security foundation and the ability to serve as a trusted Security SME, influencing engineering decisions across Windows platforms, services, engineering systems, secure software supply chains, and emerging AI engineering environments. The ideal candidate combines deep security expertise with product leadership to translate complex security, customer, and regulatory requirements into scalable platform capabilities and strategic investments that improve Windows security posture and regulatory readiness.
ImpactThis role shapes the future of trust, security, and compliance across Windows by defining the strategy, capabilities, and investments needed to meet evolving security and regulatory expectations. The successful candidate will be recognized as a technical security leader and trusted advisor who influences product direction across Windows platforms, services, engineering systems, and secure software supply chains.
Responsibilities- Own the vision, strategy, roadmap, and investment priorities for Windows security compliance and assurance capabilities.
- Serve as a Security SME and trusted advisor across platform, services, application, infrastructure, and secure software supply chain security domains.
- Identify security and compliance gaps and drive product investments that improve Windows security posture and regulatory readiness.
- Drive prioritization and investment decisions across competing security, compliance, customer, and engineering needs, balancing risk, impact, and business value.
- Translate complex security, customer, and regulatory requirements into scalable platform capabilities and engineering solutions.
- Partner with engineering teams to design and deliver secure-by-design, compliance-by-design, and AI-enabled capabilities that improve security assurance, governance efficiency, and audit readiness.
- Influence architecture and engineering decisions across Windows products, services, build infrastructure, release systems, signing systems, and engineering platforms.
- Drive security assurance and compliance readiness for Cybersecurity EO, CRA, PQC/CNSA, SDL, SFI, FedRAMP, FIPS, and future regulatory requirements.
- Define success metrics and use data-driven insights to drive adoption, prioritization, investment decisions, and continuous improvement in auditability and compliance readiness.
QualificationsRequired Qualifications: - Bachelor's Degree AND 5+ years experience in product/service/program management or software development.
- OR equivalent experience.
Preferred Qualifications:- 6+ years of experience in Product Management, Security Engineering, Security Architecture, Technical Program Management, or related fields.
- Solid technical expertise in platform, services, application, and infrastructure security, with deep understanding of build infrastructure, CI/CD systems, secure software supply chains, release engineering, signing services, artifact management, and AI/ML development and training environments.
- Ability to serve as a trusted Security SME and influence architecture, product strategy, and engineering decisions across complex technical domains.
- Experience serving as a technical security leader or SME, influencing architecture, product strategy, and engineering decisions.
- Solid knowledge of security architecture, secure development practices, threat modeling, vulnerability management, and security assurance principles.
- Experience driving product strategy and execution for security, platform, infrastructure, or developer-focused technologies.
- Familiarity with EU CRA, Cybersecurity EO, NIST, FedRAMP, FIPS, PQC/CNSA, or similar security and regulatory frameworks.
- Excellent executive communication and cross-organizational leadership skills.
- Experience with operating systems, developer platforms, cloud services, or large-scale engineering infrastructure.
- Experience working on secure software supply chain, release engineering, code-signing, build systems, or engineering platform security initiatives.
- Familiarity with AI/ML security, model development environments, and AI governance considerations.
#W+DJOBS
Product Management IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.