Sr. Program Manager - Cybersecurity Incident Communications

Microsoft
Redmond, WA, United States
2 days ago
Apply on www.businessworkforce.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$119,800.0 - $234,700.0
Working hours
Regular working hours

Tech stack

Microsoft Online Services Cyber Security Digital Content Microsoft Security Essentials Cyber Threat Analysis

Job description

  • This role does require you to be available/online outside of typical business hours/weekdays, given the crisis management aspect of our team’s support for cybersecurity incidents at least one per month.
  • Collaborate with cross-functional teams, including incident coordinators, security operations, threat intelligence, product engineering, legal, marketing, issues management/PR, etc. to coordinate and align messaging and respond to customers with timely, actionable information about security incidents or security-adjacent events at Microsoft.
  • Serve as a primary point of contact to other incident response workstream leaders and stakeholders concerning customer communications during cybersecurity incidents, providing clear and concise written and verbal daily updates on the progress of communications content.
  • Support Microsoft security-aligned executives by preparing executive talk tracks, FAQs and other information about security incidents in preparation for customer engagement and to respond to customer inquiries and escalations.
  • Track, manage, monitor, oversee, and orchestrate the development and finalization of external-facing communications collateral (e.g., customer notifications, Talking Points, responses to customer escalations and inquiries, blogs, etc.).
  • Draft, edit, and approve security incident communication contents and help drive consensus with other communications stakeholders.
  • Learn about and document the end-to-end process of supporting and communicating with customers about security incidents so that you can help identify solutions to improve and better instrument/automate these processes.
  • Meticulously review content to avoid errors, ambiguities, and miscommunication; ensure accuracy and consistency in all communications; and assess content from the customers’ perspective.
  • Ability to be available outside of typical business hours/weekdays, given the crisis management aspect of our team’s support for cybersecurity incidents.

Requirements

The Customer Security Management Office, which is part of the Office of the Chief Information Security Officer (OCISO), is seeking a skilled and experienced Sr. Program Manager - Cybersecurity Incident Communications to join our team.

This role is pivotal in managing and supporting customer-facing and other external communications related to cybersecurity incidents. During a security incident, customers need accurate information to understand the scope and impact of the issue. This role will help ensure that Microsoft can offer our customers and partners critical details about what happened, what data or services are affected, and what steps are being taken to mitigate and remediate the issue. How we communicate this guidance enables our customers and partners to make informed decisions and take necessary actions to protect their own systems and data. This role will need a background in communications, a understanding of cybersecurity, and the ability to navigate complex, high-stakes situations with confidence and clarity.

This Sr. Program Manager - Cybersecurity Incident Communications will also be able to prioritize competing, time-sensitive demands and help manage a diverse set of organizational stakeholders and ensure key stakeholders are informed and aligned, while navigating and balancing the needs and expectations of different teams. Organizational skills, project management, and critical thinking skills are keys to success in this role.

If you enjoy a dynamic work environment, where you will support a global team and are focused on your role as a communications professional - we’d like to learn more about you!, * 5+ years experience in program management, digital content publishing/management, or experience in a writing or editing role

  • OR equivalent experience.

Other Requirements:

Candidates must be able to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:

  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
  • Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. 1324b(a)(3)) for assessment of eligibility to access the export controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.
  • Citizenship & Citizenship Verification: This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport, * 5+ years experience in program management or communications
  • OR equivalent experience.
  • 2+ years experience in cybersecurity, engineering, operations, product management, or technical program management.
  • Experience in cross functional project management or crisis management.?
  • Experience leading or managing communications strategy, developing communications content, or supporting communications program execution in the technology, cybersecurity, or related sectors.
  • Effective written and verbal communication skills, with the ability to convey complex and technical information clearly and effectively.
  • Experience managing communications for cybersecurity incidents or other high-stakes situations.
  • Experience writing copy/content or producing collateral for external or customer-facing distribution in crisis scenarios.
  • Experience managing diverse stakeholders with competing interests.
  • Ability to assess the urgency and importance of various requests and prioritize tasks accordingly.
  • Efficiently manage time to meet tight deadlines without compromising quality.

Content Program Management IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.

About the company

Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. The Microsoft Office of the CISO aspires to make the world a safer place for all. We want to reshape security ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.businessworkforce.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

3:20 min

Capturing momentum with internationalization in growing markets

Mike Giannakopoulos · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:06 min

Implementing runtime threat event frameworks for attack telemetry

Tom Tovar · World Congress 2023

1:44 min

Verifying digital content authenticity through open validation standards

Stephanie Cohen Stephanie Cohen +1 · World Congress 2025

Videos

See all

Related articles

See all