Senior Technical Program Manager, Security Compliance
Microsoft
Do you thrive in environments where clarity, rigor, and evidence drive impact? Are you energized by strengthening enterprise controls, improving assurance processes, and making control health visible across complex organizations? This role is for you.
CISO Governance Risk and Compliance (GRC), part of Microsoft Cloud + AI and the Office of the CISO, protects Microsoft by strengthening cybersecurity governance, ensuring regulatory compliance, and managing risk with clarity and accountability. We are evolving our Controls Assurance Platform (CAP) to meet increasing regulatory expectations, audit scrutiny, and enterprise scale.
We are hiring a Senior Technical Program Manager, Security Compliance to serve as a Controls Assurance Owner, responsible for maturing CAP’s governance, cadence, and evidence lifecycle. In this role, you will anchor the assurance layer for cybersecurity, driving execution consistency, improving evidence quality, and ensuring readiness for internal and external audits. You will partner closely with engineering, security, privacy, and legal stakeholders to strengthen control health and build sustainable compliance processes that scale.
You will thrive here if you operate with outward confidence, think in evidence, and bring structure to ambiguity. You will help shape the future of CAP and ensure Microsoft is prepared for regulatory change, audit cycles, and enterprise growth.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
- Own CAP assurance — Mature the Controls Assurance Platform (CAP) by strengthening governance, cadence, and evidence lifecycle for Security’s enterprise control environment.
- Drive audit readiness — Ensure CAP controls, evidence, and processes meet internal, external, and regulatory audit expectations with precision and urgency.
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.

