About this role
About the Role Director - Cloud Supply Chain Risk & Compliance leads the Cloud Supply Chain (CSCP) risk and compliance program for Microsoft’s cloud hardware infrastructure. You will partner with cross-functional teams to design, implement, and operate controls that protect customers and the business as the CSCP expands with AI. What You'll Do
- Develop and execute the cloud supply chain risk and compliance strategy, including policy, standards, and controls.
- Lead risk assessments, third-party/vendor risk management, and internal audits.
- Collaborate with security, privacy, legal, procurement, and engineering teams to ensure compliance with applicable laws and standards (e.g., ISO 27001, SOC 2, NIST).
- Establish governance framework, metrics, and reporting for CSCP risk posture.
- Build, mentor, and lead a high-performing team and influence senior leadership across the organization. What We're Looking For
- Experience leading risk and compliance programs for cloud or hardware supply chains.
- Strong knowledge of regulatory requirements and industry standards (ISO, SOC 2, NIST) and experience applying them to cloud/hardware programs.
- Strategic thinker with the ability to translate risk into business decisions and actionable plans.
- Excellent cross-functional collaboration and communication skills; ability to influence at executive levels.
- Bachelor’s degree; advanced degree preferred; 10+ years in governance, risk, and compliance; cloud or CSCP-related experience a plus. Nice to Have
- Experience with AI-related cloud infrastructure; supplier risk management; security certifications (CISA, CISM, CISSP) are a plus.
- Familiarity with Microsoft procurement or CSCP programs is beneficial. Compensation & Benefits
- Details not provided in the posting.