Remote Senior Manager, Policy and Controls Governance

Posted today

mongodbIrving (TX)
Compliance ManagersComputer Systems Design Services

SENIORITY

Manager

Apply

About the role

The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives.The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness. This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives.This role will be based remotely in the United StatesResponsibilities:Scope of OwnershipPolicy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governanceControls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversightGovernance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibilityIssue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findingsExecutive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectivenessProgram LeadershipOwn and evolve the governance model for policies, standards, procedures and controls, ensuring clear accountability, consistent execution and audit-ready outputsLead the end-to-end policy lifecycle, including creation, review, approval, publication, maintenance, retirement and exception governanceLead the controls governance program, including common controls framework ownership, framework revision management, control harmonization and periodic cross-functional control reviewsOwn the governance model for ARC issues and remediation tracking, including workflows for intake, tracking, monitoring, closure validation and ongoing reportingEnsure policies and controls remain aligned with compliance requirements, and translate framework changes into actionable program updatesPeople ManagementManage and develop team members responsible for policy governance, controls governance, and related operational processes by setting priorities, driving workload clarity, and coaching for strong executionEstablish a high bar for quality, accountability, and follow-through while supporting team growth through regular feedback and developmentCross-functional PartnershipPartner within ARC and across Security, Engineering, Product, and Legal teams to align requirements, resolve blockers, and drive timely decisionsCoordinate with policy owners, subject matter experts and operational stakeholders to drive timely reviews, required updates, and exception handlingServe as a key point of contact for compliance audit support related to policy governance and controls governance processes and program documentationOperational excellence and metricsDefine, maintain and evolve KPIs, KRIs, dashboards and reporting that measure policy lifecycle health, control maturity, audit readiness, exception trends and program performanceOversee the systems that support the program, including Jira workflows, GRC platform, and related automation or enhancement opportunitiesDrive continuous improvement across governance workflows to reduce manual effort, strengthen stakeholder experience and improve scalability across ARC programsRequirements:10+ years of program management, governance, compliance or related experience within Information Security, GRC, or a high-growth technology environmentExperience leading policy and procedure programs, governance frameworks or controls governance programs at scaleStrong understanding of security and compliance frameworks such as SOC2, ISO 27001, PCI DSS, HIPAA, NIST CSF, with the ability to translate framework requirements into operational policy and control structuresExperience managing full-lifecycle cross-functional programs, including planning, risk mitigation, dependency management, change control, and executive reportingAdvanced experience with Jira, and GRC or policy management platformsStrong people leadership capability, including managing team priorities, coaching team members, and driving accountability through ambiguity and complexityExcellent communication and stakeholder management skills, with the ability to influence cross-functional partners and hold teams accountable to deadlines and governance expectationsExceptional attention to detail, strong judgement and a proactive approach to building structure, clarity and sustainable governance mechanismsScope and Complexity:This role manages complex governance programs that require coordination across business and technical teams, balancing policy lifecycle needs, framework evolution, audit readiness, tooling maturity and operational scalability Leadership in this role is demonstrated through ownership, structure-building, sound judgement, and the ability to align different stakeholders around clear governance expectations and outcomesThis leader will enhance the maturity of the policy and controls governance programs by creating repeatable mechanisms. You are expected to own the strategy and success of the  programs, not just track tasks within themYou will work closely with technical and operational subject matter experts, but you are accountable for governance design, execution rigor, reporting clarity, and resolution of bottlenecks that could impact program maturity or audit readiness Success in this role is measured by the strength, consistency, and scalability of the policy and controls governance model, and teams ability to maintain current, auditable, and business-aligned processesAbout MongoDBMongoDB is built for change, empowering our customers and our people to innovate at the speed of the market. We have redefined the data platform for the AI era, enabling builders to create, transform, and disrupt industries with software. MongoDB’s unified data platform, the most widely available, globally distributed data platform on the market, helps organizations modernize legacy workloads, embrace innovation, and unleash AI. Our cloud-native platform, MongoDB Atlas, is the only globally distributed, multi-cloud data platform and is available across AWS, Google Cloud, and Microsoft Azure.With offices worldwide and over 67,000 customers, including 75% of the Fortune 100 and AI-native startups, relying on MongoDB for their most important applications, we’re powering the next era of software.Our compass at MongoDB is our Leadership Commitment, guiding how and why we make decisions, show up for each other, and win. It’s what makes us MongoDB. To drive the personal growth and business impact of our employees, we’re committed to developing a supportive and enriching culture for everyone. From employee affinity groups, to fertility assistance and a generous parental leave policy, we value our employees’ wellbeing and want to support them along every step of their professional and personal journeys. Learn more about what it’s like to work at MongoDB, and help us make an impact on the world!MongoDB is committed to providing any necessary accommodations for individuals with disabilities within our application and interview process. To request an accommodation due to a disability, please inform your recruiter.MongoDB, Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type and makes all hiring decisions without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.Req ID: 2273504894

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this

Remote Senior Manager, Policy and Controls Governance Jobs at...