Senior Manager, Policy and Controls Governance
MongoDB · United States · 2026-08-03
About this role
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives.
The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness.
This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives.
This role will be based remotely in the United States
Responsibilities:
Scope of Ownership
• Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance
• Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight
• Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility
• Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings
• Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness
Program Leadership
• Own and evolve the governance model for policies, standards, procedures and controls, ensuring clear accountability, consistent execution and audit-ready outputs
• Lead the end-to-end policy lifecycle, including creation, review, approval, publication, maintenance, retirement and exception governance
• Lead the controls governance program, including common controls framework ownership, framework revision management, control harmonization and periodic cross-functional control reviews
• Own the governance model for ARC issues and remediation tracking, including workflows for intake, tracking, monitoring, closure validation and ongoing reporting
• Ensure policies and controls remain aligned with compliance requirements, and translate framework changes into actionable program updates
People Management
• Manage and develop team members responsible for policy governance, controls governance, and related operational processes by setting priorities, driving workload clarity, and coaching for strong execution
• Establish a high bar for quality, accountability, and follow-through while supporting team growth through regular feedback and development
Cross-functional Partnership
• Partner within ARC and across Security, Engineering, Product, and Legal teams to align requirements, resolve blockers, and drive timely decisions
• Coordinate with policy owners, subject matter experts and operational stakeholders to drive timely reviews, required updates, and exception handling
• Serve as a key point of contact for compliance audit support related to policy governance and controls governance processes and program documentation
Operational excellence and metrics
• Define, maintain and evolve KPIs, KRIs, dashboards and reporting that measure policy lifecycle health, control maturity, audit readiness, exception trends and program performance
• Oversee the systems that support the program, including Jira workflows, GRC platform, and related automation or enhancement opportunities
• Drive continuous improvement across governance workflows to reduce manual effort, strengthen stakeholder experience and improve scalability across ARC programs
Requirements:
• 10+ years of program management, governance, compliance or related experience within Information Security, GRC, or a high-growth technology environment
• Experience leading policy and procedure programs, governance frameworks or controls governance programs at scale
• Strong understanding of security and compliance frameworks such as SOC2, ISO 27001, PCI DSS, HIPAA, NIST CSF, with the ability to translate framework requirements into operational policy and control structures
• Experience managing full-lifecycle cross-functional programs, including planning, risk mitigation, dependency management, change control, and executive reporting
• Advanced experience with Jira, and GRC or policy management platforms
• Strong people leadership capability, including managing team priorities, coaching team members, and driving accountability through ambiguity and complexity
• Excellent communication and stakeholder management skills, with the ability to influence cross-functional partners and hold teams…
Skills asked for
- mongodb
- jira
- aws
- google cloud
- azure
Similar jobs
- Senior Accounting ManagerTractable · United States
- Senior Manager, Data ScienceTrm Labs · United States
- Senior Product Manager, Financial InstitutionsTrm Labs · United States
- Senior Product Manager, Threat IntelligenceTrm Labs · United States
- Senior Manager - Sports CRM AnalyticsHard Rock Digital · United States
- Senior Manager - Payments AnalyticsHard Rock Digital · United States
- Senior Program ManagerTempo Io · United States
- Senior Manager, Partner MarketingTempo Io · United States
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.