
Manager, Security, Governance, Risk and Compliance
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in California, +1 more state.
β’ Facilitate and synchronize security operations among security and IT teams that support enterprise platforms and SaaS/PaaS environments.
β’ Assist in the implementation and ongoing maintenance of SaaS security governance processes that adhere to internal policies, regulatory standards, and industry norms.
β’ Oversee security initiatives and deliver status updates, issue monitoring, and risk visibility to management.
β’ Monitor and communicate key risk indicators, metrics, and compliance status.
β’ Establish, implement, and uphold security baselines, standards, and control frameworks for SaaS and PaaS solutions.
β’ Aid in control lifecycle management, which includes defining, documenting, and validating controls.
β’ Align controls with frameworks such as NIST, ISO 27001, and OWASP.
β’ Support both internal and external audits by ensuring audit readiness and collecting necessary evidence.
β’ Organize security assessments, testing activities, and risk evaluations.
β’ Manage security exception processes, which involve risk documentation, stakeholder communication, approval tracking, and remediation follow-up.
β’ Observe exception trends concerning SaaS and PaaS workloads.
β’ Oversee security governance for platforms including Workday, Salesforce, Snowflake, ServiceNow, and Microsoft 365.
β’ Maintain approved security baselines while monitoring for configuration drift or compliance gaps.
β’ Collaborate with platform owners on configuration, change, and release management.
β’ Work with business stakeholders to enhance secure adoption and operational security maturity.
β’ Partner with IAM and data governance teams on access controls, RBAC models, and data protection strategies.
β’ Act as a liaison between security, compliance, IT, and business teams.
β’ Coordinate with stakeholders and vendors regarding SGRC Vendor Risk Management assessments.
β’ Proven experience in security program management, cloud security, SaaS governance, and SGRC functions.
β’ In-depth knowledge of security frameworks such as NIST, ISO 27001, and OWASP.
β’ Proficiency in operationalizing policies into efficient technical and procedural controls.
β’ Ability to influence cross-functional teams and communicate risk effectively to stakeholders at varying levels.
β’ Familiarity with enterprise SaaS platforms and cloud security control environments.
β’ Proven experience in supporting audits, compliance initiatives, and continuous control monitoring.
β’ Knowledge of identity and access management (IAM), data protection, and SaaS security architectures.
β’ Experience with metrics-driven security programs, including KPI/KRI development and reporting.
β’ Capability to work effectively with business partners.
β’ Strong analytical, organizational, and stakeholder management abilities.
β’ Minimum of 5 years of experience in information security, cybersecurity governance, risk management, compliance, cloud security, or related fields.
β’ Bachelor's degree required.
β’ Discretionary annual cash bonus or incentive compensation.
β’ Discretionary equity grants.
β’ Medical insurance.
β’ Dental insurance.
β’ Vision insurance.
β’ 401k retirement savings plan.
β’ Flexible paid vacation.
L3Harris Technologies
Amgen
Parexel
Lifelancer
Get handpicked remote jobs straight to your inbox weekly.