Director, Privacy & Business Resilience

Microsoft
Microsoft

Redmond, WA, USA

Posted on Aug 7, 2026
Overview

The Trust and Integrity Protection (TrIP) organization enables Microsoft’s Commercial Business to grow with trust by turning privacy/data protection, security, responsible AI, business resilience, and anti-corruption risk into clear business decisions, durable controls, and measurable outcomes.

We are looking for a strategic, high-impact leader to evolve the privacy, data protection, and business resilience program for one of Microsoft’s largest global businesses spanning sales, consulting, and technical support. This leader will move the program beyond compliance execution to deliver proactive risk reduction, AI-enabled scale, audit-ready evidence, and confidence with customers, regulators, and executives.

  • Reduce privacy, data protection, and resilience risk across Microsoft’s commercial operating model while enabling speed, customer trust, and responsible growth.
  • Modernize the program through AI, automation, telemetry, and scalable controls that improve quality, reduce friction, and strengthen audit readiness.
  • Create a federated operating model that connects divisional privacy teams into one coordinated, executive-ready view of risk, priorities, and progress.
  • Establish risk aggregation, KPIs, KRIs, and metrics that turn fragmented signals into actionable decisions for senior leaders.
  • Translate complex regulatory, customer, and audit expectations into crisp business guidance that teams can execute with confidence.
  • Represent Microsoft’s commercial data protection posture with credibility to customers, regulators, auditors, legal partners, and executives.

The ideal candidate is a builder, operator, and thought leader: someone who combines privacy depth, business judgment, executive presence, and transformation to create a program that is resilient, measurable, and built to last.

This leader will create clarity in ambiguity, develop talent, and build trusted partnerships that help the business move faster with greater confidence.



Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.



Responsibilities

Build a high-impact team

  • Build and lead a high-performing team known for sound judgment, customer empathy, risk discipline, and measurable impact.
  • Set clear priorities and accountability, develop exceptional talent, and empower the team to make smart tradeoffs and execute with speed.

Enable the business while reducing risk

  • Lead an integrated, risk-based privacy, data protection, and resilience program that protects data, earns trust, and enables the business to operate at global commercial scale.
  • Turn risk signals into clear priorities, pragmatic mitigation, and timely leadership decisions—strengthening accountability while reducing friction for sales, consulting, and support.

Modernize and scale the program

  • Set and deliver an AI-enabled transformation roadmap that simplifies work, improves evidence and risk visibility, and accelerates mitigation.
  • Use Microsoft technologies, automation, and lessons from regulatory change, customer expectations, and audits to build scalable controls and better business outcomes.

Create one enterprise view of risk

  • Lead a federated operating model with clear ownership, coordinated execution, and an enterprise view of risk posture, priorities, and progress.
  • Advise senior leaders with actionable business recommendations and represent a credible narrative for how Microsoft protects data while enabling global sales, consulting, and support.



Qualifications

Required Qualifications

  • Master's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, AND 6+ years experience in risk management, privacy, security, compliance, intelligence, operations, auditing, and/or finance OR Bachelor's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, or related field AND 8+ years experience in risk management, privacy, security, compliance, government intelligence, operations, auditing, and/or finance OR equivalent experience.

Preferred Qualifications

  • Master's Degree in Risk Management, Engineering, Government Intelligence, Security, or Information Technology, or related field AND 12+ years experience in Risk Management in the context of Operations, Engineering, Information Technology, Business Analyst, Consulting, Auditing, Privacy, Security, Compliance, Government Intelligence, and/or Finance OR Bachelor's Degree in Risk Management, Engineering, Government Intelligence, Security, Cybersecurity, or Information Technology, or related field AND 15+ years experience in risk management in the context of operations, engineering, information technology, business analyst, consulting, auditing, privacy, security, compliance, government intelligence, and/or finance OR equivalent experience.
  • 5+ years people management experience.
  • Membership with a relevant risk domain area association including: International Association of Privacy Professionals (IAPP), International Information System Security Certification Consortium (ISC)2, and Information Systems Audit and Control Association (ISACA), Certified Internal Auditor (CIA), Society for Corporate Compliance and Ethics (SCCE), Disaster Recovery Institute (DRI), Certified Business Continuity Professional (CBCB), Committee of Sponsoring Organizations of the Treadway Commission (COSO), and Institute of Internal Auditors (IIA).
  • Experience with AI, AI-based analytical tools, AI governance, and AI governance frameworks.
  • Proven ability to lead privacy, data protection, business resilience, or risk programs in a large, matrixed, global technology or services business.
  • Track record modernizing risk or compliance programs through AI, automation, telemetry, simplification, and scalable controls.
  • Deep knowledge of global privacy and data protection obligations, accountability frameworks, privacy by design, data governance, and evidence expectations.
  • Experience creating risk aggregation mechanisms, metrics, dashboards, and executive reporting that drive leadership action.
  • Ability to align distributed teams in a federated model and drive consistent outcomes without relying on direct authority.


Risk Management M6 - The typical base pay range for this role across the U.S. is USD $130,900 - $277,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $165,600 - $303,600 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.




Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.