Risk Management Manager
Microsoft · Redmond, WA · 2 days ago
Hybrid$117k–$204k/yrFull-time
Responsibilities
- Build a high-performing team
- Create clarity on priorities, ownership, and outcomes so the team can make smart tradeoffs and execute with pace
- Develop talent and an inclusive culture that raises the bar for accountability, collaboration, and continuous improvement
- Reduce risk while enabling the business
- Turn assessments, incidents, audit issues, and control signals into prioritized risk themes, mitigation plans, and leadership decisions
- Strengthen accountability through high-quality DPIAs, ROPAs, evidence, risk acceptances, and mitigation tracking that can withstand internal and external scrutiny
- Connect privacy, resilience, continuity, incident response, and operational risk so teams manage obligations as one coherent business system
- Equip sales, consulting, support, and leadership teams with practical guidance that accelerates good decisions and reduces rework
- Modernize the program through AI and automation
- Create one coordinated view of privacy risk
- Advise senior leaders with crisp business implications and recommendations, not compliance jargon
Qualifications
- Required Qualifications
- 10+ years of experience in risk management, privacy, data protection, security, compliance, audit, operations, finance, government intelligence, or related fields.
- OR bachelor’s degree and 6+ years of experience in risk management, privacy, data protection, security, compliance, audit, operations, finance, government intelligence, or related fields.
- OR equivalent experience.
- Preferred Qualifications
- Proven ability to lead privacy, data protection, business resilience, or risk programs in a large, matrixed, global technology or services business.
- Track record modernizing risk or compliance programs through AI, automation, telemetry, simplification, and scalable controls.
- CIPP, CIPM, CIPT, or equivalent privacy, security, audit, risk, or resilience certification, or membership with a relevant risk domain association such as IAPP, (ISC)², ISACA, CIA, SCCE, DRI, CBCP, COSO, or IIA.
- Strong command of global privacy and data protection obligations, accountability frameworks, privacy by design, and data governance, with experience building risk aggregation mechanisms, metrics, dashboards, and executive reporting that drive leadership action.
- Ability to align distributed teams in a federated model and drive consistent outcomes without relying on direct authority.
- Credibility with customers, regulators, auditors, legal teams, engineering teams, and senior business stakeholders.
- Excellent judgment, executive presence, communication skills, and ability to create structure and momentum in ambiguity.