Lead Privacy Program Manager
Redmond, WA - USA
Department:
Job Summary
Do you want to shape how privacy and data protection work across one of the worlds largest commercial businesses
The Trust and Integrity Protection (TrIP) organization enables Microsofts commercial business to grow with trust by translating privacy and data protection requirements into clear decisions durable controls and measurable outcomes. We are seeking a senior individual contributor to serve as the Privacy Program Owner and architect for the business spanning global sales consulting and technical support.
You will set the strategy and target state for the privacy and data protection program assess whether it is operating effectively and lead the management of systemic and emerging risk. This is a lead individual-contributor rolenot a people-manager positionwith broad influence across business legal engineering compliance and privacy teams.
This opportunity is ideal for a privacy leader who combines deep subject-matter expertise strong business judgment and an architects mindset. You will create clarity in ambiguity modernize how the program operates and help the business move faster while protecting data and earning trust.
Microsofts mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect integrity and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
Set the program strategy and architecture. Define the vision priorities operating model and multiyear roadmap for privacy and data protection across sales consulting and technical support.
Own program effectiveness. Establish governance controls accountability metrics and assurance mechanisms that demonstrate compliance with the Microsoft Privacy Standard and applicable legal regulatory contractual and industry requirements.
Lead privacy risk management. Identify aggregate assess and prioritize systemic emerging and business-specific privacy risks; recommend pragmatic treatments; and drive mitigation through accountable business and technical owners.
Translate obligations into scalable solutions. Convert complex privacy requirements into actionable business guidance technical patterns control designs and privacy-by-design practices that teams can implement consistently.
Modernize and simplify the program. Use AI automation telemetry and Microsoft technologies to reduce manual effort strengthen evidence accelerate risk reduction and improve the stakeholder experience.
Orchestrate a federated privacy model. Align distributed privacy legal engineering risk compliance and business teams around common standards priorities and outcomes without relying on direct authority.
Advise senior leaders. Provide clear decision-ready insights on risk posture control effectiveness regulatory change investment priorities and opportunities to enable responsible business growth.
Represent the program with credibility. Serve as a trusted privacy authority with customers auditors regulators legal partners and Microsoft leaders when addressing complex data protection matters.
Qualifications
Required Qualifications
- Bachelors Degree in Risk Management Engineering Government Intelligence Security or Information Technology or related field AND 6 years experience in risk management privacy security compliance government intelligence operations auditing and/or finance OR equivalent experience.
Preferred Qualifications
- Masters Degree in Risk Management Engineering Government Intelligence Security or Information Technology or related field AND 8 years experience in risk management in the context of operations engineering information technology business analyst consulting auditing privacy security compliance government intelligence and/or finance OR Bachelors Degree in Risk Management Engineering Government Intelligence Security Cybersecurity or Information Technology or related field AND 12 years experience in risk management in the context of operations engineering information technology business analyst consulting auditing privacy security compliance government intelligence and/or finance OR equivalent experience.
- Membership with a relevant risk domain area association including: International Association of Privacy Professionals (IAPP) International Information System Security Certification Consortium (ISC)2 and Information Systems Audit and Control Association (ISACA) Certified Internal Auditor (CIA) Society for Corporate Compliance and Ethics (SCCE) Disaster Recovery Institute (DRI) Certified Business Continuity Professional (CBCB) Committee of Sponsoring Organizations of the Treadway Commission (COSO) and Institute of Internal Auditors (IIA).
- Experience with AI AI-based analytical tools AI governance and AI governance frameworks.
- Experience with privacy program architecture control design testing metrics dashboards audit readiness and regulatory documentation such as DPIAs and records of processing activities particularly in relation to Data Processor activities
- Experience in dealing with complex third-party privacy sub processor scenarios
- Understanding of cloud services enterprise data ecosystems and the privacy considerations associated with AI and emerging technologies.
- Excellent judgment and communication skills with the ability to make complex privacy risks clear and actionable for technical legal and executive audiences.
- 6 years of experience in privacy data protection risk management security compliance audit operations or a related field; OR a bachelors degree and 4 years of relevant experience; OR equivalent experience.
- Demonstrated experience designing leading or materially transforming a privacy or data protection program in a large complex matrixed organization.
- Knowledge of global privacy and data protection obligations privacy-by-design principles data governance privacy risk assessment and accountability frameworks.
- Experience translating legal regulatory contractual or policy requirements into practical business processes technical requirements and scalable controls.
- Proven ability to influence senior leaders and cross-functional teams create structure in ambiguity and drive outcomes without direct authority.
Risk Management IC5 - The typical base pay range for this role across the U.S. is USD $116900 - $203600 per year. There is a different range applicable to specific work locations within the San Francisco Bay area and New York City metropolitan area and the base pay range for this role in those locations is USD $148400 - $222600 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
position will be open for a minimum of 5 days with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age ancestry citizenship color family or medical care leave gender identity or expression genetic information immigration status marital status medical condition national origin physical or mental disability political affiliation protected veteran or military status race ethnicity religion sex (including pregnancy) sexual orientation or any other characteristic protected by applicable local laws regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process read more about requesting accommodations.
Required Experience:
IC