The opportunity
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control…
What you'll do
Policy governance program ownership, including policy lifecycle management,: documentation standards, review and approval cadences, change tracking, and exception governance
Controls governance ownership, including common controls framework lifecycle: management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight
Governance over supporting systems and workflows, including Jira, GRC: tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility
Issue management and remediation governance, including intake, triage,: tracking, and reporting for timely closure of findings
Executive-ready reporting and metrics for policy health, controls maturity,: policy exceptions and broader program effectiveness
Own and evolve the governance model for policies, standards, procedures and: controls, ensuring clear accountability, consistent execution and audit-ready outputs
What they're looking for
- Lead the end-to-end policy lifecycle, including creation, review, approval,: publication, maintenance, retirement and exception governance
- Lead the controls governance program, including common controls framework: ownership, framework revision management, control harmonization and periodic cross-functional control reviews
- Own the governance model for ARC issues and remediation tracking, including: workflows for intake, tracking, monitoring, closure validation and ongoing reporting
- Ensure policies and controls remain aligned with compliance requirements, and: translate framework changes into actionable program updates