
Staff Security Program Manager (GRC) EDB. **Candidates note: This is 100% remote position for candidates based in the US (EST/CST time zones preferred).. As a . Staff Security Program Manager. on the Information Security team, you will play a pivotal role in leading the transformation of our security program to drive business growth and mitigate information risks. You will collaborate with multiple teams, acting as a key driver for our security and compliance initiatives, both internally for software development and delivery, and externally as we pursue industry-standard compliance accreditations. This role is responsible for understanding and translating security frameworks, partnering with stakeholders on control design, supporting implementation, and establishing automated auditing. You will be a vital participant in customer diligence activities, reinforcing EDB’s security and compliance posture.. EDB is undergoing a significant security program transformation, and you will be a leading voice of change. This role requires a blend of strategic planning, project management, and security expertise. You will be responsible for developing and maintaining controls, policies, and procedures, while also driving the execution of projects to enhance our security posture. We are looking for individuals who thrive in a global, distributed environment with flexible work schedules.. What your impact will be: . Lead the transformation of EDBs common controls framework and associated policies and procedures to support business growth and reduce information risks.. Contribute to the annual planning process for Information Security initiatives, ensuring alignment with business objectives.. Oversee and drive security and compliance initiatives, including maintaining industry-standard accreditations.. Lead, coordinate, and manage audits, working with internal teams and third-party auditors.. Educate and consult with control owners on effective control environments and audit evidence.. Manage the Plan of Action and Milestones (POAM) related to security exceptions, ensuring timely completion.. Forge essential working relationships with engineering leadership, product management, and executive management.. Participate in customer security diligence efforts, managing questionnaires and requests while continuously improving the efficiency and effectiveness of the response process.. Identify, develop, and implement metrics that effectively measure the performance and effectiveness of our information security initiatives.. What you will bring:. Proven experience in information security and compliance, including project management.. Strong understanding of cybersecurity principles, frameworks, and best practices.. Experience working with external auditors and a strong understanding of audit methodology.. Technical aptitude to navigate compliance controls and cloud security best practices.. Strong experience with auditing security objectives of SOC2, PCI, HIPAA, FedRAMP (800-53), ISO 27001.. Proven project management skills, with the ability to manage multiple projects simultaneously.. Excellent organizational and time management skills, with the ability to prioritize and multitask. . Excellent communication skills to keep internal and external stakeholders aligned.. Drive, a proactive attitude, and thorough attention to detail.. What will give you an edge:. Certified Information Security Auditor (CISA) or Certified Information Systems Security Professional (CISSP) certifications. Experience with Hyperproof GRC Platform and Jira. Project Management certification. Compensation Range (DOE/Location)= $170-$190k base salary + annual variable bonus