Senior Risk Manager - Supplier Digital Security
MicrosoftAbout the role
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.
Our Enterprise Supplier Security Governance Team is looking for a Senior Risk Manager - Supplier Digital Security.
A successful candidate has existing cyber security expertise with working knowledge of supply chain and supplier digital security, a track record of developing relationships, collaborating across teams, coordinating multiple timelines, digging into data for insights and anomalies, and managing complex, cross discipline projects.
If you have a passion for supply chain risk management and cybersecurity, enjoy working across a complex organization while influencing different teams, and solving complex problems, this role is for you!
This role involves working with various teams across the company to identify top security and resilience risks and gaps specific to our suppliers and our eco-system of coverage, to agree on supplier priorities to address the risks, facilitate and drive the reduction of supplier risks, run the supplier resilience program, and determine the best way to consistently measure and improve our capabilities in this space.
We have exciting opportunities for you to innovate, influence, transform, inspire, and grow within our organization and we encourage you to apply to learn more!
Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
• Understand the current supply chain security & resilience programs at Microsoft, identify and analyze gaps in the eco-system and top gaps and risks in their programs, report on and influence changes, and draft executive and board of director communications on said topic.
• Facilitate and drive the reduction of supplier risks including driving supplier security & resilience initiatives across various teams while engaging with customers and stakeholders to gather and integrate feedback into program(s).
• Own supplier incident management governance and remediation which includes working with incident management teams to identify the full set of remediation activities needed to reduce likelihood of occurrence for supplier incidents, and drive with partner teams remediation activities to closure.
• Run the supplier resilience program including, but not limited to, the revamp and day-to-day operations of the supplier assessments, meetings, communications / evangelism, and disciplinary enforcement.
• Identify and report on metrics to measure the impact and risk reduction of the relevant program(s).
• Prepare and deliver updates to team leadership on program status and the supplier risk.
• Stay current with the industry trends and advancements in Third Pary Risk Management (TPRM) and apply this knowledge to enhance the programs capabilities.
• Develop and maintain program documentation including standard operating procedures, customer guidance, and strategy roadmaps.
Other
Qualifications
Required/Minimum Qualifications
- 6+ years experience in Risk Management, Privacy, Security, Compliance, Government Intelligence, Operations, Auditing, and/or Finance
o OR Bachelor's Degree AND 4+ years experience in Risk Management, Privacy, Security, Comp
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s