Remote, United States
Remote
Senior
Full Time
💰$168,000 - $238,000
remotesecuritygovernancepolicyAIautomation
Requirements
- •10+ years in security governance, GRC, or IT risk with hands-on ownership of policy and standards lifecycle
- •Working knowledge of SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF including practical application
- •Understanding of cloud, SaaS, and DevSecOps practices
- •Ability to write policy that engineers will follow
- •Risk-based mindset balancing compliance with real security risk
- •Demonstrated use of automation or AI to reduce manual GRC work
- •Strong written and verbal communication skills
- •Experience collaborating with Security, Product, Legal, and Engineering
What You'll Do
- •Own the end-to-end lifecycle of security policies, standards, procedures, and guidelines including drafting, review, approval, publication, annual review, and retirement
- •Define and run the exception management process including risk-based approvals, expiry tracking, and trend reporting
- •Run policy attestation and investigate non-adherence
- •Keep policies clear, practical, and aligned with DevSecOps engineering practices
- •Monitor emerging regulations and standards and partner with Legal to assess impact and update policy
- •Maintain mappings between policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF
- •Define KPIs for policy adherence and report trends to Security leadership
- •Run targeted internal assessments of adherence and drive remediation to closure
- •Support audit activities by coordinating evidence, testing, and remediation management
- •Support customer questionnaires and meetings, and help turn recurring customer requests into better policies and self-service content
- •Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment work
- •Act as a technical and program leader across Security, Product, Legal, and Engineering
- •Mentor other team members and help set the direction of the Security Governance roadmap
Nice to Have
- •Certifications such as CISSP, CISM, CISA, or similar
Benefits
- •Benefits to support health, finances, and well-being
- •Flexible Paid Time Off
- •Team Member Resource Groups
- •Equity Compensation & Employee Stock Purchase Plan
- •Growth and Development Fund
- •Parental Leave
