Risk Management Manager
We tailor your resume to this role and apply for you in seconds.
Apply to Risk Management Manager at MicrosoftJob details
- Location
- Redmond, Washington
- Work type
- Hybrid
- Compensation
- $116,900 - $203,600/yr
- Posted
- today
- Apply on
- microsoft.eightfold.ai
About this role
The Trust and Integrity Protection (TrIP) organization enables Microsoft’s commercial business to grow with trust by turning privacy/data protection, security, Responsible AI, business resilience, and anti-corruption risk into clear business decisions, durable controls, and measurable outcomes.
We are looking for a strategic, high-impact leader to evolve the privacy, data protection, and business resilience program for one of Microsoft’s largest global businesses spanning sales, consulting, and technical support. This leader will move the program beyond compliance execution to deliver proactive risk reduction, AI-enabled scale, audit-ready evidence, and confidence with customers, regulators, and executives.
Reduce privacy, data protection, and resilience risk across Microsoft’s commercial operating model while enabling speed, customer trust, and responsible growth.
Modernize the program through AI, automation, telemetry, and scalable controls that improve quality, reduce friction, and strengthen audit readiness.
Create a federated operating model that connects divisional privacy teams into one coordinated, executive-ready view of risk, priorities, and progress.
Establish risk aggregation, KPIs, KRIs, and metrics that turn fragmented signals into actionable decisions for senior leaders.
Translate complex regulatory, customer, and audit expectations into crisp business guidance that teams can execute with confidence.
Represent Microsoft’s commercial data protection posture with credibility to customers, regulators, auditors, legal partners, and executives.
The ideal candidate is a builder, operator, and thought leader: someone who combines privacy depth, business judgment, executive presence, and transformation muscle to create a program that is resilient, measurable, and built to last.
This leader will create clarity in ambiguity, develop strong talent, and build trusted partnerships that help the business move faster with greater confidence.
Responsibilities
Build a high-performing team
Build and lead a team known for business judgment, risk discipline, customer empathy, and measurable impact.
Create clarity on priorities, ownership, and outcomes so the team can make smart tradeoffs and execute with pace.
Develop talent and an inclusive culture that raises the bar for accountability, collaboration, and continuous improvement.
Reduce risk while enabling the business
Deliver a risk-based privacy, data protection, and resilience program that protects customer, partner, employee, and Microsoft data at commercial scale.
Turn assessments, incidents, audit issues, and control signals into prioritized risk themes, mitigation plans, and leadership decisions.
Strengthen accountability through high-quality DPIAs, ROPAs, evidence, risk acceptances, and mitigation tracking that can withstand internal and external scrutiny.
Connect privacy, resilience, continuity, incident response, and operational risk so teams manage obligations as one coherent business system.
Equip sales, consulting, support, and leadership teams with practical guidance that accelerates good decisions and reduces rework.
Modernize the program through AI and automation
Build an AI-enabled transformation roadmap that reduces manual effort, improves evidence quality, and increases risk visibility.
Use Microsoft technologies such as Purview, Priva, agentic solutions, and automation to scale controls and accelerate mitigation.
Convert regulatory change, customer expectations, audit findings, and lessons learned into stronger controls, simpler workflows, and better business outcomes.
Create one coordinated view of privacy risk
Connect divisional, corporate, legal, engineering, and business privacy teams into a federated model with clear ownership and coordinated execution.
Establish governance that surfaces the right risks, dependencies, decisions, and tradeoffs to the right leaders at the right time.
Build KPIs, KRIs, dashboards, and executive reporting that show risk posture, program health, mitigation progress, and emerging themes.
Advise senior leaders with crisp business implications and recommendations, not compliance jargon.
Represent the program externally and internally with a clear, credible narrative for how Microsoft protects data across global sales, consulting, and support.
Qualifications
Required Qualifications
- Required 10+ years of experience in risk management, privacy, data protection, security, compliance, audit, operations, finance, government intelligence, or related fields.
- OR bachelor’s degree and 6+ years of experience in risk management, privacy, data protection, security, compliance, audit, operations, finance, government intelligence, or related fields.
- OR equivalent experience.
Preferred Qualifications
Proven ability to lead privacy, data protection, business resilience, or risk programs in a large, matrixed, global technology or services business.
Track record modernizing risk or compliance programs through AI, automation, telemetry, simplification, and scalable controls.
- CIPP, CIPM, CIPT, or equivalent privacy, security, audit, risk, or resilience certification, or membership with a relevant risk domain association such as IAPP, (ISC)², ISACA, CIA, SCCE, DRI, CBCP, COSO, or IIA.
Strong command of global privacy and data protection obligations, accountability frameworks, privacy by design, and data governance, with experience building risk aggregation mechanisms, metrics, dashboards, and executive reporting that drive leadership action
Experience creating risk aggregation mechanisms, metrics, dashboards, and executive reporting that drive leadership action.
Ability to align distributed teams in a federated model and drive consistent outcomes without relying on direct authority.
Credibility with customers, regulators, auditors, legal teams, engineering teams, and senior business stakeholders.
Excellent judgment, executive presence, communication skills, and ability to create structure and momentum in ambiguity.
Risk Management M5 - The typical base pay range for this role across the U.S. is USD $116,900 - $203,600 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $148,400 - $222,600 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.