Business Program Manager

Company: Microsoft
Apply for the Business Program Manager
Location: Reading
Job Description:

Overview

In this role you will lead information security governance and assurance across UK Public Safety and National Security programmes, ensuring compliance with government policy and contractual obligations. You will act as a trusted adviser to programme teams, translating complex requirements into practical controls. You’ll work with cross-functional partners to embed security early in delivery and reduce friction while maintaining strong risk management. This is a high-impact role that supports customer confidence, programme delivery, and revenue by preventing breaches and delays.

Responsibilities

  • Define and implement information and operational security policies aligned with UK Government policy and contractual obligations
  • Provide information security governance across UK national security programmes and translate requirements into scalable controls
  • Support audits, assurance reviews, and accreditation activities
  • Lead information security governance across the programme lifecycle and embed security in design and delivery
  • Review contractual security documents and ensure security flow-down into delivery
  • Manage security risk assessments and ensure escalation to governance bodies
  • Guide handling, storage, and sharing of sensitive information and advise on Microsoft tooling for secure collaboration
  • Provide incident management support and post-incident reviews
  • Engage with stakeholders across engineering, sales, legal and leadership to communicate risks clearly

Key requirements

  • Demonstrable experience in information security, operational security, or government security roles
  • Ability to obtain and maintain UK Government DV security clearance
  • Experience supporting large, complex programmes for UK Government, defence or national security customers
  • Knowledge of UK Government security policy and information handling requirements
  • Desirable: CISSP, CISM, CCSP (not required)
  • Stakeholder-management and relationship-building
  • Independent yet collaborative work style
  • Adaptability and tolerance for ambiguity
  • Information security governance and policy
  • Security risk management and assurance
  • Contract security interpretation and control implementation

…

Posted: October 6th, 2026