- Workplace
- Remote
- Type
- Full-time
- Department
- IT
- Seniority
- Manager
- Experience
- 6+ years
- Closing date
- Today
- Source
- ApplyToJob
Description
Prowess Consulting is a consulting firm that specializes in helping the largest enterprises in the technology industry define, manage, benchmark, and market their solutions and services. We take great pride in investing the time and effort to gain a deep understanding of our clients’ technologies, their customers, and the stories and strategies they need to tell to be successful in the market. Our team of technology and marketing experts is immersed in the technology trends that affect our clients’ businesses, so we can add value at every stage of engagement to help them succeed.
WHO YOU ARE
Prowess Consulting is looking for a Security Compliance Project Manager to define and drive the vision, strategy, roadmap, and adoption of security and compliance capabilities across the Windows ecosystem.
This role requires a strong technical security foundation and the ability to serve as a trusted Security SME, influencing engineering decisions across Windows platforms, services, engineering systems, secure software supply chains, and emerging AI engineering environments. The ideal candidate combines deep security expertise with product leadership to translate complex security, customer, and regulatory requirements into scalable platform capabilities and strategic investments that improve Windows security posture and regulatory readiness.
IMPACT
This role shapes the future of trust, security, and compliance across Windows by defining the strategy, capabilities, and investments needed to meet evolving security and regulatory expectations. The successful candidate will be recognized as a technical security leader and trusted advisor who influences product direction across Windows platforms, services, engineering systems, and secure software supply chains.
To be considered for this role, you must reside in one of the following states: Alabama, California, Colorado, Georgia, Iowa, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Jersey, New York, North Carolina, Oregon, Pennsylvania, South Carolina, Texas, Utah, Virginia, or Washington.
This is a full-time role that can be worked remotely, however, collaboration with teammates centered in the Pacific time zone will be essential. No third-party agencies, please.
THE ROLE AND RESPONSIBILITIES
- Own the vision, strategy, roadmap, and investment priorities for Windows security compliance and assurance capabilities.
- Serve as a Security SME and trusted advisor across platform, services, application, infrastructure, and secure software supply chain security domains.
- Identify security and compliance gaps and drive product investments that improve Windows security posture and regulatory readiness.
- Drive prioritization and investment decisions across competing security, compliance, customer, and engineering needs, balancing risk, impact, and business value.
- Translate complex security, customer, and regulatory requirements into scalable platform capabilities and engineering solutions.
- Partner with engineering teams to design and deliver secure-by-design, compliance-by-design, and AI-enabled capabilities that improve security assurance, governance efficiency, and audit readiness.
- Influence architecture and engineering decisions across Windows products, services, build infrastructure, release systems, signing systems, and engineering platforms.
- Drive security assurance and compliance readiness for Cybersecurity EO, CRA, PQC/CNSA, SDL, SFI, FedRAMP, FIPS, and future regulatory requirements.
- Define success metrics and use data-driven insights to drive adoption, prioritization, investment decisions, and continuous improvement in auditability and compliance readiness.
- 6+ years of experience in Product Management, Security Engineering, Security Architecture, Technical Program Management, or related fields.
- Strong technical expertise in platform, services, application, and infrastructure security, with deep understanding of build infrastructure, CI/CD systems, secure software supply chains, release engineering, signing services, artifact management, and AI/ML development and training environments.
- Ability to serve as a trusted Security SME and influence architecture, product strategy, and engineering decisions across complex technical domains.
- Experience serving as a technical security leader or SME, influencing architecture, product strategy, and engineering decisions.
- Strong knowledge of security architecture, secure development practices, threat modeling, vulnerability management, and security assurance principles.
- Experience driving product strategy and execution for security, platform, infrastructure, or developer-focused technologies.
- Familiarity with EU CRA, Cybersecurity EO, NIST, FedRAMP, FIPS, PQC/CNSA, or similar security and regulatory frameworks.
- Excellent executive communication and cross-organizational leadership skills.
- Experience with operating systems, developer platforms, cloud services, or large-scale engineering infrastructure.
- Experience working on secure software supply chain, release engineering, code-signing, build systems, or engineering platform security initiatives.
- Familiarity with AI/ML security, model development environments, and AI governance considerations.
- Strong understanding of enterprise/on-prem Windows security fundamentals, such as Active Directory, authentication/authorization concepts, Group Policy, credential hygiene, hardening baselines, and security logging/auditing
- Experience operating vulnerability management and coordinated disclosure processes, including intake/triage, severity scoring (e.g., CVSS), remediation SLAs, exception handling, and reporting/notification obligations
- Software supply chain & secure development knowledge (aligned to NIST SSDF concepts), including build integrity, dependency management, SBOMs (SPDX/CycloneDX), code signing, and release/change control
- Ability to work with compliance tooling and evidence workflows (GRC/control libraries, automated evidence collection, audit trails) and integrate with engineering systems (ADO/Jira, CI/CD, ticketing)
- Data/analytics skills to build continuous monitoring and compliance reporting (Power BI or similar; ability to work with log/metric sources and perform basic querying to validate control health)
- The offered pay range for this position is $95,000 105,000 per year depending on experience.