Skip to content

Jobgether

Staff Security Governance Engineer, Policies & Standards

Compensation
$168K–$238K / yr
From job posting
Location
US
Arrangement
Remote
Employment type
Full-time
Level
Staff
Posted
1 October 2026 (today)

Checked todayApplications go to the employer, never to RoleSprint

About this role

Accountabilities: • Own the complete lifecycle of security policies, standards, procedures, and guidelines, including drafting, stakeholder review, approval, publication, periodic review, and retirement.

• Define and operate a risk-based exception management process covering approvals, expiration tracking, adherence trends, and recommendations for policy improvements.

• Manage policy attestation activities, investigate non-adherence, and develop measurable indicators of policy effectiveness and adoption.

• Monitor emerging regulations and security standards, including AI-focused requirements, and collaborate with Legal to assess their impact and update policies ahead of compliance deadlines.

• Maintain mappings between internal policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF to enable requirements to be reused effectively.

• Conduct targeted internal assessments, coordinate remediation efforts, and support audits through evidence collection, testing, and remediation management.

• Support customer security questionnaires and meetings while identifying recurring customer needs that can be addressed through stronger policies and self-service resources.

• Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment activities in partnership with GRC Engineering.

• Provide technical and program leadership across Security, Product, Legal, and Engineering, influencing stakeholders without direct authority while mentoring colleagues and helping shape the Security Governance roadmap.

Requirements

• 10+ years of experience in security governance, GRC, IT risk, or a related field, with hands-on ownership of policy and standards lifecycles and a track record of measurable outcomes.

• Strong working knowledge of security and compliance frameworks including SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF, with the ability to apply them in practical operational environments.

• Understanding of cloud, SaaS, and DevSecOps practices, with the ability to create security policies that are clear, practical, and actionable for engineering teams.

• Strong risk-based approach, balancing regulatory and compliance requirements with real-world security risks and operational needs.

• Demonstrated experience using automation or AI to reduce manual governance, risk, and compliance activities.

• Excellent written and verbal communication skills, with the ability to translate technical and regulatory concepts for engineers, executives, auditors, customers, and other stakeholders.

• Proven ability to collaborate effectively across Security, Product, Legal, and Engineering teams and influence decisions without direct authority.

• Experience leading complex or ambiguous technical programs and mentoring other professionals through design, review, and implementation.

• Certifications such as CISSP, CISM, CISA, or similar credentials are highly desirable.

Benefits

• Base salary range of USD $168,000–$238,000 per year for eligible U.S.-based positions.

• Equity compensation and Employee Stock Purchase Plan.

• Benefits supporting health, finances, and overall well-being.

• Flexible Paid Time Off.

• Parental Leave.

• Growth and Development Fund to support ongoing learning and professional development.

• Team Member Resource Groups and an inclusive workplace culture.

• Fully remote work environment with an asynchronous, documentation-driven way of working.

• Opportunity to work on high-impact security governance initiatives spanning Security, Product, Legal, and Engineering.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Work location

  • US

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 1 October 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free