Enterprise SaaS

10 Microsoft security leaders

These ten current and former Microsoft security leaders include a former Microsoft CISO, division CISOs, deputy CISOs and executive and corporate vice presidents in Microsoft Security. Readers can learn how Microsoft organizes security across its own corporate environment, its security products and its work with customers.

10 professionals1 companiesData retrieved September 29, 2026

Professionals to explore

01—10
  1. Bret Arsenault

    LinkedIn

    Experience: Corporate Vice President and Chief Information Security Officer · Microsoft

    Former Corporate Vice President and Chief Information Security Officer at Microsoft (2015–2024), and Corporate Vice President and Chief Cybersecurity Advisor at Microsoft since 2024; his profile headline calls him CVP, CISO Emeritus and Global Chief Security Advisor. The profile also lists Vice President and Chief Information Security Officer at Microsoft (2009–2024) and Chief Technology Officer, Identity Security Division (2009).

  2. Chang Kawaguchi

    LinkedIn

    Experience: VP, CISO Microsoft 365 · Microsoft

    Former VP, CISO Microsoft 365 at Microsoft (2021–2022) and Director, CISO, Office 365 at Microsoft (2017–2021); he has been an AI Security Architect at Microsoft since 2022. His other Microsoft roles include Group Engineering Manager (2014–2017) and Director of Service Engineering (2003–2014).

  3. Craig Nelson

    LinkedIn

    Experience: Vice President - Office of the CISO · Microsoft

    Vice President - Office of the CISO at Microsoft since 2024; his profile says he is responsible for establishing and operating the Microsoft Red Team spanning all Microsoft Clouds and infrastructure, designed to challenge groupthink and shape technical direction. His profile headline reads CVP | Microsoft Security.

  4. Hayete Gallot

    LinkedIn

    Experience: Executive Vice President, Microsoft Security · Microsoft

    Executive Vice President, Microsoft Security since 2026; her profile says she leads the engineering teams dedicated to making the digital world safer, driving innovation across Identity, Threat Protection, Compliance, Data Protection and Management. She was President, Customer Experience Google Cloud at Google (2024–2026), and her other Microsoft roles include Corporate Vice President, Commercial Solution Areas (2021–2024) and Corporate Vice President, Modern Work and Security (2020–2021).

  5. John Lambert

    LinkedIn

    Experience: CTO of the CISO organization, Security Fellow, Corporate Vice President · Microsoft

    CTO of the CISO organization, Security Fellow, Corporate Vice President at Microsoft since 2025. His other Microsoft roles include Corporate Vice President, Security Fellow (2023–2025), Distinguished Engineer (2018–2023) and General Manager, Microsoft Threat Intelligence Center (2014–2022), and his profile describes his work as CVP of Microsoft Security Research leading the consolidated research and intelligence teams for Microsoft Security.

  6. Michal Braverman-Blumenstyk

    LinkedIn

    Experience: CVP at Microsoft, Managing Director of Microsoft Israel R&D Center and CTO of Microsoft Security · Microsoft

    CVP at Microsoft, Managing Director of Microsoft Israel R&D Center and CTO of Microsoft Security since 2022. Her other Microsoft roles include Corporate Vice President, Managing Director of Israel R&D Center and CTO, Cloud & AI Security (2020–2022), CTO, Cloud and AI Security Division (2017–2020) and General Manager, Azure Cybersecurity (2013–2017).

  7. Terrell Cox

    LinkedIn

    Experience: CVP, Deputy CISO of Customer Security · Microsoft

    CVP, Deputy CISO of Customer Security within Microsoft's CISO organization since 2026, after serving as Deputy CISO for Privacy and Compliance at Microsoft (2025–2026). Other Microsoft roles on the profile include Vice President, Microsoft Security & Privacy (2023–2025) and Vice President, Microsoft Defender for Cloud (2022–2023), and the profile says Cox has led security, privacy, compliance and product engineering organizations serving enterprise customers, small and medium businesses and education.

  8. Timothy Langan

    LinkedIn

    Experience: Corporate Vice President, Deputy CISO · Microsoft

    Corporate Vice President, Deputy CISO at Microsoft since 2024, listed at Executive level. His profile also lists Executive Assistant Director (2022–2024), Assistant Director -Counterterrorism Division (2021–2022) and Special Agent in Charge - Kansas City Division (2019–2021) at the Federal Bureau of Investigation (FBI).

  9. Umar Waheed CISSP CISM

    LinkedIn

    Experience: Chief Information Security Officer (CISO) Nuance, a Microsoft Company · Microsoft

    Chief Information Security Officer (CISO) Nuance, a Microsoft Company, at Microsoft since 2023, listed at Executive level; his profile headline also describes him as Partner/GM - Regulated Industries. The profile also lists Senior Director & Deputy CISO - Security Intelligence & Operations at Nuance Communications (2021–2023) and Head of Security Operations at the Financial Conduct Authority (2019–2021).

  10. Vasu Jakkal

    LinkedIn

    Experience: Corporate Vice President, Security, Compliance, Identity, and Management · Microsoft

    Corporate Vice President, Security, Compliance, Identity, and Management at Microsoft since 2020; her profile headline reads CVP Microsoft Security and also notes a seat on the Aptiv board of directors. The profile also lists a Corporate Vice-President role at Microsoft since 2020 and Member Board Of Directors at Element since 2021.

Choose the right perspective

Match the leader's remit, such as the CISO organization, product security engineering or customer security, to your question. Check whether each Microsoft role is current or ended, especially for CISO roles, before asking about recent practices.

Questions to take into the conversation

  1. 01How should a CISO organization divide responsibility among deputy CISOs for areas such as identity, customers and compliance?
  2. 02What does an effective internal red team program look like at a large cloud provider?
  3. 03How do you turn lessons from securing your own company into security products and guidance for customers?

About this directory

This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.

Request a correction or removal

Other perspectives in Enterprise SaaS