Technical Solution Manager - Security Strategy

MicrosoftPublished 2 hours agoFirst seen 1 hours ago
Overview

MCAPS-Core accelerates customer outcomes and business growth. By uniting product, engineering, marketing, sales, customer success, and partners around a common customer mission, we help customers realize value faster and turn innovation into measurable business impact. Through deep technical expertise and differentiated go-to-market execution, we win competitively, capture market share, and scale repeatable growth motions. We differentiate through value creation - delivering world-class, AI-powered customer experiences that accelerate adoption, strengthen loyalty, and create sustainable competitive advantage, driving growth that outpaces the market.

MCAPS-Core’s Office of the Chief Technology Officer (OCTO) connects technical strategy to engineering execution to deliver secure, reliable customer experiences and measurable business value. By uniting technical leadership, customer insight, engineering, data, security expertise, and cross-company partnerships, OCTO scales innovation while strengthening security by design, operational resilience, and risk-informed decision-making. Through a Customer Zero mindset, OCTO turns security requirements into practical solutions that account for architecture, dependencies, workforce needs, customer impact, and the safe adoption of emerging technologies.

OCTO is seeking a Technical Solution Manager - Security Strategy to define security strategy and leads implementation of high-priority initiatives across MCAPS-Core. This individual contributor will shape mitigation strategies, influence architecture and design decisions, lead large-scale security and architectural reviews, and align cross-functional teams to identify, prioritize, and resolve systemic risks.
The ideal candidate is proficient in security and systems thinker who can assess complex designs, identify systemic risks, and balance security with operational needs. They bring expertise in security architecture, threat modeling, failure modes, attack chains, and vulnerabilities; translate critical issues into actionable guidance; and lead through influence across Security, Engineering, and business.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.


Responsibilities

•    Define the security strategy and leads implementation of high-priority initiatives across MCAPS-Core, translating company objectives into security roadmaps, measurable outcomes, investment priorities, and coordinated delivery across products, platforms, and business operations.

  • Establish security initiative governance, success measures, decision frameworks, and operating rhythms; influence schedules, investments, dependencies, and risk decisions; remove execution barriers; and represent security priorities and outcomes in leadership forums.
  • Lead large-scale security and architectural design reviews for feature areas, ensure secure design and development practices are embedded in delivery, translate findings into prioritized remediation plans, and track closure of material risks to maximize review value.
  • Provide security architecture expertise through design reviews and threat models; evaluate how proposed controls, dependencies, and attack paths affect the end-to-end feature design; and translate findings into actionable guidance for partner teams.
  • Evaluate security, customer, business, and operational tradeoffs; document risk-based recommendations; and drive timely decisions, mitigations, or escalations when requirements compete.
  • Analyze complex security issues across multiple data sources, validate their scope and impact across dependent and down-level platforms, and lead cross-functional mitigation or remediation of systemic and emerging risks.
  • Lead virtual and cross-functional security teams by establishing clear outcomes, decision rights, workstreams, owners, milestones, and dependencies; resolve ambiguity and conflict; and maintain alignment to strategic security goals.
  • Build trusted partnerships across Security, Engineering, product, operations, and business teams to align on security priorities, secure commitments, drive adoption of mitigations and secure practices, and ensure material issues are addressed.
  • Develop and scale secure practices, reference patterns, playbooks, and validation approaches for products, services, and systems; incorporate lessons from reviews, incidents, escalations, and recurring risk themes to improve security maturity for business.
  • Conduct in-depth evaluations against security baselines, identify material control gaps and systemic weaknesses, and translate findings into prioritized improvements for products, platforms, and business processes.
  • Assess the efficiency, consistency, and effectiveness of security reviews; prioritize effort based on risk and customer impact; and develop automation, analytics, and AI-assisted capabilities that improve review quality, coverage, traceability, and time to insight.
  • Scale security expertise by coaching and mentoring others, sharing reusable guidance and lessons learned, and modeling sound judgment, accountability, and ethical behavior in security practice.
Qualifications

Required/minimum qualifications

  • Master's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 6+ years experience in project management, operations, or engineering OR Bachelor's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 8+ years experience in project management, operations, or engineering OR equivalent experience.

Other Requirements

Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.

Additional or preferred qualifications

  • Master's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 12+ years experience in project management, operations, or engineering OR Bachelor's Degree in Business, Project Management, Supply Chain, Computer Science, Management Information Systems, Engineering, or related field AND 15+ years experience in project management, operations, or engineering OR equivalent experience.
  • Project Management Professional (PMP) certification or equivalent.
  • Continuous Improvement certification, Lean Six Sigma certification, or equivalent.
  • Agile Certified Practitioner (ACP) or equivalent.
  • Change Management certification (e.g., Prosci Certification).
  • Enterprise experience, in software development lifecycle, large-scale computing, threat modeling, cybersecurity, or anomaly detection.
  • Experience analyzing complex security issues and driving mitigation or remediation across multiple feature teams.
  • Expertise in security design, architecture reviews, threat modeling, security baselines, secure software development, and risk assessment.
  • Demonstrated experience defining and executing multi-team security strategies, roadmaps, governance models, and measurable outcomes in complex enterprise environments, including the ability to influence architecture, schedules, dependencies, investments, and cross-functional decisions without direct authority.
  • Proficient written, verbal, and executive communication skills, including the ability to synthesize complex security issues, articulate business and customer impact, present risk-based options, and drive timely decisions.
  • Experience leading large-scale security and architectural reviews across feature areas.
  • Experience developing mitigation strategies, security practices, baselines, and scalable guidance.
  • Experience establishing security initiative roadmaps, OKRs, governance mechanisms, stakeholder operating rhythms, and cross-functional execution plans that deliver measurable risk reduction.
  • Experience applying AI, analytics, or automation to improve security issue detection, review quality, coverage, traceability, mitigation, or analysis of review content.

Technical Solution Management IC6 - The typical base pay range for this role across the U.S. is USD $130,900 - $277,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $165,600 - $303,600 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.


Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.