Business Program Manager
Operations
Reading, UK
GBP 70,300-133,900 / year
Responsibilities
- Define, maintain and implement information and operational security policies, standards and procedures aligned with UK Government policy, Microsoft requirements and contractual obligations.
- Act as a subject matter expert on information security governance for UK national security programmes.
- Translate government and customer security requirements into scalable, operationally workable controls.
- Provide independent advice and constructive challenge where security, contractual or compliance obligations may be at risk.
- Support audits, inspections, assurance reviews and customer accreditation activity.
- Maintain awareness of evolving UK Government security policy, regulation and the national security threat landscape.
- Provide information security leadership across the programme lifecycle, from early engagement and tenders through delivery and operation.
- Work with programme management and engineering teams to embed security in programme design and delivery.
- Review and interpret Security Aspects Letters, Security Grading Guides, contractual security schedules and security flow-down requirements.
- Support the development and maintenance of Security Management Plans, procedures and assurance documentation.
- Help establish or participate in customer and programme Security Working Groups.
- Ensure information security risks are identified, documented, reviewed and escalated through appropriate governance.
- Engage with sales, account and bid teams to identify security requirements early.
- Review relevant DEFCON, Defence Standard and customer-specific security requirements.
- Advise on security obligations within Statements of Work and related contractual documents.
- Identify delivery and compliance risks associated with proposed commitments or solutions.
- Support customer discussions where security requirements require clarification or negotiation.
- Ensure agreed security requirements transition effectively into programme delivery.
- Support security risk assessments across UK national security programmes.
- Review programme risk registers and evaluate the effectiveness of proposed mitigations.
- Ensure significant security risks are escalated to the appropriate risk owner or governance body.
- Provide information security assurance to programme leadership and senior stakeholders.
- Support remediation, assurance assessments, accreditation reviews and security testing.
- Monitor recurring issues and identify opportunities to improve controls, processes and programme security maturity.
- Promote consistent, evidence-based security risk management across programmes.
- Provide guidance on the handling, storage, sharing, transfer, retention and disposal of sensitive information.
- Advise on the suitability of Microsoft tooling and collaboration environments for sensitive programme activity.
- Support secure document management and customer-specific information handling requirements.
- Advise on restricted collaboration environments, ethical firewalls and information-separation controls.
- Help ensure sensitive information is handled in line with contractual and government requirements and need-to-know principles
- Provide information security advice and support during security incidents affecting relevant programmes.
- Ensure potential incidents are identified, recorded and escalated appropriately.
- Support proportionate, independent incident investigations where required.
- Assess security, customer and contractual implications.
- Recommend containment, remediation and risk-reduction actions.
- Produce or support incident reports and after-action reviews.
- Ensure lessons learned are reflected in programme controls, guidance and training.
- Act as an information security point of contact for UK national security programmes.
- Build trusted relationships with programme teams, Engineering, Sales, Legal and Microsoft security stakeholders.
- Engage with UK Government, defence and national security customers on security assurance and compliance matters.
- Represent Microsoft at Security Working Groups, assurance meetings and security governance forums.
- Develop security briefings for programme leadership, senior executives and customers.
- Communicate complex security risks and requirements clearly to technical and non-technical audiences.
- Promote security as a practical business enabler.
- Develop positive relationships with legal colleagues within the UK & Ireland Legal Affairs team, with UK government affairs colleagues and with colleagues in the wider EMEA region to coach and advise on compliance issues.
- Engage with legal and business colleagues to identify and share best practices.
- Support programme-specific security briefings, training and awareness material.
- Support and collaborate with NST Personnel Security Controller and Facility Manager.
- Develop positive relationships with customers, and partners to protect and advocate for Microsoft’s interests.
- Collaborate with service providers to develop strategies and innovative solutions to address business issues and achieve business objectives.
- Some knowledge of Defence exports compliance issues would be an advantage but not essential. The role includes support to project teams and liaison with Microsoft’s international trade specialists on matters involving US and other applicable export-control regimes.
- Identify gaps and inefficiencies in security processes and lead proportionate improvements
- Use AI solutions to scale work and drive continuous improvement.
- Monitor emerging risks, policy developments and operational security trends.
Qualifications
- Demonstrable experience in information security, operational security, programme security or a government security role.
- The successful candidate is a sole UK National and hold, or be able to obtain and maintain, the UK Government security clearance required for the role (DV).
- Knowledge of UK Government security policy, security controls and government information handling requirements.
- Demonstrable experience supporting large, complex programmes for UK Government, defence or national security customers.
- Experience interpreting contractual security requirements and translating them into practical operational controls.
- Experience managing information security risk, assurance or accreditation activities.
- Stakeholder-management skills, including engagement with leaders, customers and multidisciplinary delivery teams and ability to establish a “trusted advisor” relationship.
- An ability to work independently while also being a collaborator with the ability to work with colleagues based in different locations.
- A high tolerance for ambiguity and change.
- Passion for technology, the potential of digital transformation and Microsoft’s diverse range of products and services
- Desirable CISSP, CISM, CCSP.
Business Program Management IC5 - The typical base pay range for this role across United Kingdom is £ 70,300.00 - £ 133,900.00 per year. Certain roles may be eligible for benefits and other compensation.
Find additional benefits and pay information here:
https://careers.microsoft.com/v2/global/en/corporate-pay/united-kingdom-corporate-pay.html
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.