Datacenter Security Operations Manager
Microsoft
Microsoft
Join Microsoft's Cloud Operations + Innovation (CO+I) team, the powerhouse behind our vast cloud infrastructure. Our Datacenter Physical Security division is dedicated to safeguarding our people, facilities, assets, and critical infrastructure.
As a Datacenter Security Operations Manager (DSOM), you will be at the forefront of leading daily physical security operations across Microsoft's datacenters, campuses, and metro areas. This pivotal role offers operational leadership, deep security subject-matter expertise, and oversight of contracted security services. Your focus will be on ensuring physical security measures are consistently effective, resilient, and aligned with Microsoft's stringent policies, standards, and operational demands. The ideal candidate will foster strong collaborations with Datacenter Operations, Engineering, EHS, Compliance, Investigations, Security Design and Delivery, lease providers, construction partners, and contracted security service providers to achieve these objectives.
Drive comprehensive physical security operations across designated datacenters, campuses, and metro locations. Ensure the consistent implementation of security programs, procedures, post orders, and site-specific instructions. Evaluate the efficacy of access control, video surveillance, intrusion detection, alarms, physical barriers, and screening checkpoints. Conduct regular site visits and security reviews to verify compliance with established security baselines. Monitor operational performance, identify deficiencies, and implement corrective and preventive actions. Maintain meticulous security documentation, operational records, and provide detailed leadership reports.
Lead on-site responses to security incidents and significant operational events, coordinating with Datacenter Operations, security service providers, lease providers, internal security teams, and local authorities. Support security investigations, evidence preservation, root-cause analysis, and post-incident reviews, ensuring accurate record-keeping and timely action closure. Apply lessons learned to enhance operational controls.
Conduct physical security risk assessments and develop practical mitigation plans, ensuring all assigned locations are audit-ready. Coordinate audit evidence and support internal, external, customer, and regulatory audits. Track audit observations and remediation commitments to closure. Monitor the evolving local threat landscape and recommend adjustments to security posture.
Provide operational oversight of contracted security service providers, ensuring service delivery meets contractual and program expectations. Establish structured governance with vendor security management, including operational reviews and performance discussions. Hold service providers accountable for timely remediation of operational gaps while fostering professional working relationships. Support security staffing readiness for new sites and operational changes.
Support physical security readiness for new datacenters, expansions, and checkpoint deployments. Participate in security integration and transition discussions, reviewing readiness requirements and implementation plans. Coordinate with Security Design and Delivery and project teams to transition new facilities into steady-state operations. Engage in security-related projects and technology deployments.
Cultivate effective relationships with Datacenter Operations, Engineering, EHS, Compliance, Security Design and Delivery, Investigations, and lease providers. Offer expert physical security advice and risk-based guidance to business partners. Clearly communicate security risks and mitigations to management. Influence cross-functional teams to achieve security outcomes.
Actively participate in the local crisis management structure and support emergency preparedness and business-continuity activities. Provide on-site security leadership during significant incidents or periods of elevated risk, ensuring contracted teams execute emergency plans. Identify resilience gaps and support contingency measures.
Promote security awareness and responsible reporting across the datacenter community. Support initiatives addressing insider risk and physical security risks. Analyze incidents and operational feedback to identify improvement opportunities and contribute to regional security programs.
A minimum of 14 years of professional experience in physical security, security operations, critical infrastructure protection, military service, law enforcement, investigations, intelligence, or risk management. This includes at least 3 years of corporate security experience within a private-sector organization, demonstrating established security governance, compliance, reporting, and stakeholder management processes. Experience managing physical security operations in complex, high-availability, or critical infrastructure environments is essential.
Proven experience overseeing contracted security services, guarding operations, or third-party service providers. Expertise in managing security incidents, investigations, operational risks, and corrective actions. A strong working knowledge of physical security systems, including access control, video surveillance, intrusion detection, alarms, and screening technologies. Experience supporting security audits, compliance reviews, risk assessments, and remediation programs is required.
Exceptional stakeholder management skills are vital, enabling effective collaboration across operations, engineering, compliance, facilities, project, and vendor teams. Strong written and verbal communication skills, including proficiency in preparing incident reports, risk summaries, and leadership updates. The ability to make sound, risk-based decisions in time-sensitive and operationally demanding situations is crucial.
Candidates should also be able to travel between supported datacenter locations as needed and provide on-site support during significant incidents or critical operational activities. While a Bachelor's degree in a related field is preferred, equivalent practical experience will also be considered. Experience supporting datacenters, cloud infrastructure, or other critical infrastructure sectors is advantageous. Professional certifications like CPP, PSP, PCI, or PMP are a plus. Familiarity with relevant Indian regulatory requirements is beneficial.
Microsoft welcomes all qualified applicants, encouraging those to apply even if they don't meet every listed qualification. We value passion for protecting critical infrastructure and experience closely aligned with this role.
Microsoft Corporation
Information Technology & Services