Principal Privacy Product Manager, Health AI
About the role
Microsoft AI is building the next generation of AI products for health, where privacy decisions carry profound implications for trust, safety, and product quality. Operating at the intersection of healthcare innovation and privacy means handling sensitive health and personal data at scale while navigating a complex, multi-jurisdictional legal and policy landscape. As a Principle Privacy Product Manager for our Health vertical within Microsoft AI, you will be the privacy architect for our health AI products like Copilot Health and frontier AI model development.
Responsibilities
- Be the privacy partner to health engineering, product, and clinical stakeholders, guiding privacy decisions across the end-to-end product experience, including feature design, user flows, defaults, and sensitive data use.
- Set and prioritize privacy controls for health AI scenarios, translate them into clear engineering requirements, and drive implementation and adoption across the lifecycle.
- Lead privacy design reviews for health AI features, including data handling, model behavior, and user-facing transparency and choice experiences.
- Own data governance expectations across the health product lifecycle, including collection, use, sharing, retention, and deletion.
- Monitor emerging health and data policy developments, assess product impact, and drive prioritized control or experience changes with product and engineering partners.
- Drive privacy program improvements through repeatable patterns, tooling recommendations, governance and effectiveness metrics, and engineering enablement.
Qualifications
Required qualifications include a Bachelor's Degree and 8+ years of experience in product/service/program management or software development, or equivalent experience. Additionally, 6+ years of experience disrupting a market for a product, feature, or experience, and 4+ years of practical experience creating and maintaining compliance programs and conducting privacy reviews are required.
- Preferred qualifications include a Bachelor's degree in Computer Science or a closely related discipline.
- Experience translating policy and privacy requirements into shipped product controls in partnership with engineering.
- Experience leading privacy/compliance engineering programs for AI/ML products or other data-intensive platforms at scale.
- Hands-on familiarity with regulations related to health verticals, such as HIPAA, GDPR, and similar.
- Practical experience in health privacy, health policy, and/or health data governance.
- Working knowledge of health regulations and industry frameworks, including data sensitivity, governance expectations, and common privacy risk patterns.
- Hands-on experience with privacy engineering practices such as data flow mapping, data classification, consent infrastructure, threat modeling, DSR tooling, retention enforcement, and telemetry governance.
- Proven ability to lead ambiguous cross-functional work and influence senior leaders without authority, while communicating clearly to engineering and executive audiences.
- IAPP Certified Information Privacy Professional (CIPP) or Certified Information Privacy Manager (CIPM).
- Demonstrated team and project management excellence on medium-to-large scale projects, including managing scope, schedule, and budget.
Pay
The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.