Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Governance Engineer, Policies & Sta
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Governance Engineer, Policies & Standards based in United States. This role offers the opportunity to shape how security policies and standards are created, maintained, communicated, and measured across a global technology environment. You will translate evolving regulations and security frameworks, including emerging AI requirements, into practical guidance that engineering, product, legal, and security teams can apply. As a senior individual contributor, you will own policy governance while helping make security and compliance processes more automated, measurable, and continuous. You will work closely with Security Compliance, Security Risk, GRC Engineering, Product, Legal, and Engineering teams. The position combines governance expertise with technical understanding of cloud, SaaS, DevSecOps, and automation. Working remotely and asynchronously, you will have broad scope and visible impact while helping establish the future direction of security governance.
Own the complete lifecycle of security policies, standards, procedures, and guidelines, including drafting, stakeholder review, approval, publication, periodic review, and retirement. Define and operate a risk-based exception management process covering approvals, expiration tracking, adherence trends, and recommendations for policy improvements. Manage policy attestation activities, investigate non-adherence, and develop measurable indicators of policy effectiveness and adoption. Monitor emerging regulations and security standards, including AI-focused requirements, and collaborate with Legal to assess their impact and update policies ahead of compliance deadlines. Maintain mappings between internal policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF to enable requirements to be reused effectively. Conduct targeted internal assessments, coordinate remediation efforts, and support audits through evidence collection, testing, and remediation management. Support customer security questionnaires and meetings while identifying recurring customer needs that can be addressed through stronger policies and self-service resources. Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment activities in partnership with GRC Engineering. Provide technical and program leadership across Security, Product, Legal, and Engineering, influencing stakeholders without direct authority while mentoring colleagues and helping shape the Security Governance roadmap. Requirements 10+ years of experience in security governance, GRC, IT risk, or a related field, with hands-on ownership of policy and standards lifecycles and a track record of measurable outcomes. Strong working knowledge of security and compliance frameworks including SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF, with the ability to apply them in practical operational environments. Understanding of cloud, SaaS, and DevSecOps practices, with the ability to create security policies that are clear, practical, and actionable for engineering teams. Strong risk-based approach, balancing regulatory and compliance requirements with real-world security risks and operational needs. Demonstrated experience using automation or AI to reduce manual governance, risk, and compliance activities. Excellent written and verbal communication skills, with the ability to translate technical and regulatory concepts for engineers, executives, auditors, customers, and other stakeholders. Proven ability to collaborate effectively across Security, Product, Legal, and Engineering teams and influence decisions without direct authority. Experience leading complex or ambiguous technical programs and mentoring other professionals through design, review, and implementation. Certifications such as CISSP, CISM, CISA, or similar credentials are highly desirable. Benefits Base salary range of USD $168,000–$238,000 per year for eligible U.S.-based positions. Equity compensation and Employee Stock Purchase Plan. Benefits supporting health, finances, and overall well-being. Flexible Paid Time Off. Parental Leave. Growth and Development Fund to support ongoing learning and professional development. Team Member Resource Groups and an inclusive workplace culture. Fully remote work environment with an asynchronous, documentation-driven way of working. Opportunity to work on high-impact security governance initiatives spanning Security, Product, Legal, and Engineering.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from jobgether (lever) →