Microsoft's Global Security vision is focused on how business partnership leads to outcomes and how we drive impact.
We do this through our core values - People, Prioritization, Partnership and Protect.
Responsibilities
Security Risk Management
- Anticipates and addresses security threats by gathering, analyzing, and evaluating information about existing or potential threats to determine the likelihood of Microsoft infrastructure, business, people, and assets being targeted.
- Monitors and manages the development of current, emerging, and evolving threats with the likelihood to impact Microsoft infrastructure, business, people, and assets.
- Anticipates and addresses assets or operations where security is not adequate and can be exploited by a threat.
- Evaluates geopolitical activities and events, and synthesizes key intelligence to inform internal and external stakeholder constituents or employees of potential threats.
- Informs, escalates and manages the risks to appropriate teams.
- Identifies and interprets security risks to Microsoft infrastructure, business, people, and assets.
- Selects, implements, and manages measures to modify identified risks.
- Develops mitigation strategies and methods to measure the effectiveness of the actions taken for the risks.
- Designs, implements, and monitors controls to treat risks to infrastructure, business, people, and assets.
- Monitors and manages the effectiveness of measures taken to modify risks.
- Monitors and manages the security aspects of assets/projects throughout the asset or project lifecycle.
- Participates in discussions to develop plans of action and milestones to track and mitigate risks.
Security Services
- Develops and executes procedures and processes to provide protection across all security disciplines (e.g., personnel and company property, day‑to‑day damage, vandalism, loss prevention, security‑related risk programs, personnel privacy) by meeting required codes and regulations.
- Maintains records, manuals, and documentation related to security.
- Administers organizational security plans and operations.
- Coordinates with government bodies to administer security clearance, policies, and procedures in accordance with appropriate agencies.
- Internally, provides training on security protocols, operating standards, and response requirements.
- Develops and executes troubleshooting guides and standard monitoring procedures to oversee daily activities across networks and systems.
- Performs analysis to detect advanced security threats, alerts, or risks and escalates to critical incident response team and/or external authorities, if necessary.
- Implements and assists in developing security protocols to support the physical protection of company personnel and assets.
- Delivers and maintains security programs in areas of responsibility.
- Measures impact of security programs in areas of responsibility.
- Manages delivery of day‑to‑day today security activities in the areas of responsibilities (e.g., event security risk management, travel security support, visitor management, security patrols).
- Delivers specialized physical security services for larger regions.
- Prepares for and responds to security and life‑safety threats, incidents, alerts, and risks.
Leadership
- Develop public, private, and supplier partnerships.
- Engages with the stakeholders (e.g., Global Workplace Services (GWS), Human Resources (HR), Procurement, suppliers, maintenance) and communicates risk assessment findings.
- Coordinates activities with HR, legal, and authorities having jurisdiction as appropriate.
- Consults stakeholders to provide security capabilities.
- Collaborates with teams to implement risk management frameworks for identifying and controlling security risks across the Microsoft portfolio.
- Anticipates and addresses global insecurity and security disruption (e.g., life safety, business operations, reputation) to drive decision‑makers in mitigating risks and responding to residual risks.
- Summarizes and reports risk analysis findings to internal and external stakeholders and leaders.
- Advises on strategy to mitigate and respond to residual risks based on its team's anticipation of global insecurity and physical disruption (e.g., life safety, business operations, reputation) within Microsoft.
Other – Embody our culture and values
Qualifications
Required / Minimum Qualifications
- 5+ years experience in Security Program or Program Management or related field.
- Fluency in Spanish and English
Additional or Preferred Qualifications
- Bachelor's Degree in Business Risks, or related field AND 12+ years experience in Security Program or Program Management
- OR equivalent experience
- Certified Protection Professional (CPP) or equivalent Protection certification
- OR Physical Security Professional (PSP)
- OR equivalent Physical Security Certification
- Knowledge of physical security standards and best practices.
- Ability to manage incidents, situations, and personnel at multiple locations