← Back to all jobs

Product Manager II

Microsoft · WA · Posted 2026-09-03

Apply on the company site →

Job description

Overview The Trust Experiences and Compliance (TEC) team’s mission is to make Windows the most trusted platform for business and life. We are redefining how compliance is designed, implemented, and sustained across Windows. Our vision is simple: make compliance happen seamlessly. We are building innovative, AI-powered and agentic solutions that integrate directly into engineering workflows, reduce compliance toil, strengthen control effectiveness, and enable teams to build trusted products by default. The Compliance arm under TEC enables Windows + Devices teams to ship innovative experiences responsibly by translating evolving internal policies, regulatory obligations, and customer expectations across Responsible AI, Privacy, and Data domains into clear product requirements, scalable review processes, durable controls, verifiable evidence, and timely release decisions. We are seeking a Product Manager II to drive complex compliance programs across Windows + Devices. This role sits at the intersection of product development, engineering, privacy, data governance, responsible AI, trust, legal, safety, security, regulatory and audit readiness. The successful candidate will help teams move from evolving requirements to concrete design decisions, privacy and data assessments, responsible AI reviews, risks and mitigations, approvals, and continuous compliance — without losing sight of product velocity, customer control, or trust. You will own cross-functional programs spanning privacy reviews, Responsible AI system and model reviews, data governance, consent and data-use controls, diagnostic and required service data, access governance, data portability, transparency documentation, release readiness, regulatory implementation, and audit evidence. You will create durable operating models that make obligations clear, ownership explicit, decisions traceable, and compliance increasingly automated and built into the engineering lifecycle. The regulatory portfolio includes obligations under GDPR, Digital Markets Act, EU Data Act, Executive Order 14117, EU AI Act, California AI Transparency Act, South Korea AI Act, Colorado AI Act, and other applicable global requirements. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. Responsibilities - Drive end-to-end compliance reviews for Windows applications, platform services, AI systems and models, data-processing scenarios, telemetry pipelines, connected experiences, and agentic solutions—from early scoping through approval, launch, and sustained operation. - Guide product teams through privacy assessments, system registration, impact and release assessments, data classification, purpose and legal-basis analysis, risk evaluation, testing plans, evidence collection, mitigation closure, and documented out-of-scope decisions. - Partner with CELA, Privacy, the Office of Responsible AI, central regulatory programs, data platform teams, and engineering organizations to interpret new policies and laws and translate them into actionable Windows requirements, surface gaps early and establish clear owners, dates, decisions, and escalation paths. - Drive creation, review, publication, and lifecycle maintenance of privacy disclosures, data documentation, application cards, platform cards, model cards, compliance reports, and other customer- or regulator-facing artifacts. Qualifications Required Qualifications: - Bachelor's Degree AND 2+ years experience in product/service/program management or software development.- OR equivalent experience. Preferred Qualifications: - Bachelor’s degree and significant experience in product or program management, software engineering, privacy, data governance, compliance, risk, policy, or a related discipline—or equivalent experience. - Demonstrated ability to drive complex, ambiguous programs across engineering, legal, policy, privacy, security, data platform, responsible AI, and business stakeholders. - Experience translating technical, policy, privacy, data-governance, AI, or regulatory requirements into executable product plans, controls, milestones, operating processes, and evidence. - Solid understanding of modern product and data lifecycles, including telemetry collection, cloud services, storage, data access, analytics, AI models, platform services, applications, agents, evaluation, monitoring, and release management. - Excellent written and verbal communication skills, including the ability to create executive-ready narratives, present trade-offs, document decisions, and drive timely alignment. - Demonstrated ability to challenge the status quo and streamline or transform processes to improve efficiency, scale, control effectiveness, and business impact. - Working knowledge of privacy, data governance, Responsible AI, and regulatory compliance programs, including assessments, reviews, controls, audit readiness, and supporting evidence. - Familiarity with regulations and frameworks such as GDPR, U.S. state privacy laws, the Digital Markets Act, the EU Data Act, Executive Order 14117, the EU AI Act, global AI transparency laws, ISO/IEC 42001, and the NIST AI Risk Management Framework. - Familiarity with AI models and systems, including capabilities, limitations, evaluation approaches, deployment patterns, provenance, watermarking, human oversight, and associated safety, privacy, and compliance considerations. - Ability to engage deeply with engineers, data scientists, researchers, and architects while communicating clearly with legal partners, executives, auditors, regulators, and customers. #W+DJOBS Product Management IC3 - The typical base pay range for this role across the U.S. is USD $102,100 - $202