Microsoft
Business Program Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview
Microsoft is on a mission to empower every person and every organization on the planet to achieve more. Our culture is centred on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. You can help us achieve our mission.
Do you want to work in a company that is transforming the world? How about working on cutting-edge issues, with world-class clients and the support of a global community of professionals? If you are ready to work directly with business leaders and their teams to solve problems and drive change, then a career with the Microsoft National Security Team is for you.
The UK National Security Team (NST) is a small, high-impact group of security experts working at the intersection of compliance, technology, policy, and business strategy. NST partners closely with sales, engineering, legal, and business leaders to enable Microsoft’s most strategic customer opportunities while managing regulatory and reputational risk.
We have an immediate opening for a highly motivated and experienced Information Security Manager to join the NST, which sits within the UK & Ireland Legal Affairs team and National Security Team, and supports compliance with government personnel, project, information, and facility-security requirements. The position is based at our offices in Reading and will report to a Principal Corporate Counsel in Legal Affairs.
Role Purpose
The Information Security Manager is responsible for information security governance, assurance, and operational security support across Microsoft UK Public Safety and National Security activities. The role helps ensure compliance with UK Government security policy, contractual obligations, and customer security requirements.
The post holder acts as a trusted information security adviser to programme teams, engineering, sales, legal, security stakeholders, and leadership. They translate complex regulatory and contractual security requirements into practical controls that enable secure, compliant delivery throughout the programme lifecycle.
A key priority is identifying security requirements early and reducing avoidable delivery friction without weakening compliance. This work supports customer confidence, programme delivery, and revenue realisation by reducing the risk of contractual breaches, accreditation delays, security incidents, and unplanned remediation.
Responsibilities
Information Security Governance & Policy
- Define, maintain, and implement information and operational security policies, standards, and procedures aligned with UK Government policy, Microsoft requirements, and contractual obligations.
- Act as a subject matter expert on information security governance for UK national security programmes.
- Translate government and customer security requirements into scalable, operationally workable controls.
- Provide independent advice and constructive challenge where security, contractual, or compliance obligations may be at risk.
- Support audits, inspections, assurance reviews, and customer accreditation activity.
- Maintain awareness of evolving UK Government security policy, regulation, and the national security threat landscape.
Programme Security Governance & Assurance
- Provide information security leadership across the programme lifecycle, from early engagement and tenders through delivery and operation.
- Work with programme management and engineering teams to embed security in programme design and delivery.
- Review and interpret Security Aspects Letters, Security Grading Guides, contractual security schedules, and security flow-down requirements.
- Support the development and maintenance of Security Management Plans, procedures, and assurance documentation.
- Help establish or participate in customer and programme Security Working Groups.
- Ensure information security risks are identified, documented, reviewed, and escalated through appropriate governance.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Contract Security
- Engage with sales, account, and bid teams to identify security requirements early.
- Review relevant DEFCON, Defence Standard, and customer-specific security requirements.
- Advise on security obligations within Statements of Work and related contractual documents.
- Identify delivery and compliance risks associated with proposed commitments or solutions.
- Support customer discussions where security requirements require clarification or negotiation.
- Ensure agreed security requirements transition effectively into programme delivery.
Information Security Risk Management
- Support security risk assessments across UK national security programmes.
- Review programme risk registers and evaluate the effectiveness of proposed mitigations.
- Ensure significant security risks are escalated to the appropriate risk owner or governance body.
- Provide information security assurance to programme leadership and senior stakeholders.
- Support remediation, assurance assessments, accreditation reviews, and security testing.
- Monitor recurring issues and identify opportunities to improve controls, processes, and programme security maturity.
- Promote consistent, evidence-based security risk management across programmes.
Information Protection & Secure Collaboration
- Provide guidance on the handling, storage, sharing, transfer, retention, and disposal of sensitive information.
- Advise on the suitability of Microsoft tooling and collaboration environments for sensitive programme activity.
- Support secure document management and customer-specific information handling requirements.
- Advise on restricted collaboration environments, ethical firewalls, and information-separation controls.
- Help ensure sensitive information is handled in line with contractual and government requirements and need-to-know principles.
Security Incident Management
- Provide information security advice and support during security incidents affecting relevant programmes.
- Ensure potential incidents are identified, recorded, and escalated appropriately.
- Support proportionate, independent incident investigations where required.
- Assess security, customer, and contractual implications.
- Recommend containment, remediation, and risk-reduction actions.
- Produce or support incident reports and after-action reviews.
- Ensure lessons learned are reflected in programme controls, guidance, and training.
Customer & Stakeholder Engagement
- Act as an information security point of contact for UK national security programmes.
- Build trusted relationships with programme teams, Engineering, Sales, Legal, and Microsoft security stakeholders.
- Engage with UK Government, defence, and national security customers on security assurance and compliance matters.
- Represent Microsoft at Security Working Groups, assurance meetings, and security governance forums.
- Develop security briefings for programme leadership, senior executives, and customers.
- Communicate complex security risks and requirements clearly to technical and non-technical audiences.
- Promote security as a practical business enabler.
Other Areas
- Develop positive relationships with legal colleagues within the UK & Ireland Legal Affairs team, with UK government affairs colleagues, and with colleagues in the wider EMEA region to coach and advise on compliance issues.
- Engage with legal and business colleagues to identify and share best practices.
- Support programme-specific security briefings, training, and awareness material.
- Support and collaborate with NST Personnel Security Controller and Facility Manager.
- Develop positive relationships with customers, and partners to protect and advocate for Microsoft’s interests.
- Collaborate with service providers to develop strategies and innovative solutions to address business issues and achieve business objectives.
- Some knowledge of Defence exports compliance issues would be an advantage but not essential. The role includes support to project teams and liaison with Microsoft’s international trade specialists on matters involving US and other applicable export-control regimes.
- Identify gaps and inefficiencies in security processes and lead proportionate improvements.
- Use AI solutions to scale work and drive continuous improvement.
- Monitor emerging risks, policy developments, and operational security trends.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Qualifications
Required qualifications:
- Demonstrable experience in information security, operational security, programme security, or a government security role.
- The successful candidate is a sole UK National and hold, or be able to obtain and maintain, the UK Government security clearance required for the role (DV).
- Knowledge of UK Government security policy, security controls, and government information handling requirements.
- Demonstrable experience supporting large, complex programmes for UK Government, defence, or national security customers.
Preferred Qualifications
- Experience interpreting contractual security requirements and translating them into practical operational controls.
- Experience managing information security risk, assurance, or accreditation activities.
- Stakeholder-management skills, including engagement with leaders, customers, and multidisciplinary delivery teams and the ability to establish a “trusted advisor” relationship.
- An ability to work independently while also being a collaborator with the ability to work with colleagues based in different locations.
- A high tolerance for ambiguity and change.
- Passion for technology, the potential of digital transformation, and Microsoft’s diverse range of products and services.
- Desirable CISSP, CISM, CCSP.
Pay
Business Program Management IC5 - The typical base pay range for this role across the United Kingdom is £70,300.00 - £133,900.00 per year. Certain roles may be eligible for benefits and other compensation.
Find Additional Benefits And Pay Information Here
https://careers.microsoft.com/v2/global/en/corporate-pay/united-kingdom-corporate-pay.html
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Equal Opportunity
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations, and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
https://careers.microsoft.com/global/en/working-at-microsoft/inclusion-and-diversity
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location