Manager - Governance and Compliance (Contractor)
Quick Summary
8+ years of experience in senior IT, cybersecurity, security, risk, or compliance roles, including at least 2 years leading technical teams. Strong understanding of cloud technologies,
This is a full-time remote leadership role focused on strengthening security, risk, compliance, and AI governance across a globally distributed organization.
You will help shape long-term governance strategies while remaining closely involved in day-to-day execution and operational improvements.
The role combines cybersecurity, regulatory compliance, privacy, AI safety, and technology risk management in a fast-moving environment.
You will establish policies, controls, and security guardrails that protect sensitive information, systems, intellectual property, and client data.
Working across regions and time zones, you will partner with technical and business stakeholders as well as clients, auditors, and external specialists.
The position offers significant influence over security maturity, audit readiness, responsible AI adoption, and operational resilience.
A hands-on, proactive mindset is essential, with the opportunity to drive meaningful improvements across both internal operations and client-facing engagements.
- Develop, maintain, and enforce security, compliance, risk, privacy, AI governance, and operational policies, standards, processes, and supporting tools in line with business objectives.
- Establish governance frameworks and security guardrails for Generative AI and Machine Learning tools, addressing risks such as IP leakage, shadow AI, unauthorized data ingestion, and unsafe usage.
- Define AI governance and security architecture standards for client-facing projects, ensuring data confidentiality, algorithmic transparency, regulatory alignment, and adherence to client security requirements.
- Conduct AI risk assessments and audits covering prompt injection, training data provenance, bias mitigation, third-party AI capabilities, and emerging AI security risks.
- Serve as a subject matter expert on applicable regulations and provide compliance guidance to clients and internal stakeholders, embedding effective compliance processes into assessments and delivery activities.
- Oversee compliance with global and regional privacy requirements, including India's DPDP Act, GDPR, CCPA, and PDPA, with particular attention to cross-border data transfers.
- Oversee IT infrastructure security, monitoring, maintenance, and adherence to established security best practices.
- Mature the security program through penetration testing, disaster recovery exercises, cloud security posture management, and other proactive security initiatives.
- Integrate DevSecOps and Secure SDLC practices into internal and client development pipelines, including software supply chain security, dependency scanning, and SBOM management.
- Champion Zero Trust security principles, least-privilege access, RBAC, and robust identity and access management practices.
- Lead security and compliance incident response, including severity assessment, resource allocation, containment, and remediation.
- Manage and optimize security technologies such as SIEM, DLP, EDR, vulnerability scanning, endpoint management, Microsoft Sentinel, Microsoft Defender, and development secret-scanning solutions.
- Drive organization-wide security awareness initiatives, including phishing simulations, employee training, AI risk education, and social engineering awareness.
- Lead compliance programs and audits while acting as the primary liaison with external auditors, vCISO providers, and other assurance partners.
- Evaluate emerging technologies and lead strategic initiatives that improve operational efficiency, security maturity, and business agility.
- Manage vendor and technology partner relationships, including contract negotiations, third-party risk assessments, AI vendor evaluations, and service-level oversight.
- Take on additional responsibilities of a similar level as required to support evolving security, compliance, and business priorities.
Requirements
~2 min read- 8+ years of experience in senior IT, cybersecurity, security, risk, or compliance roles, including at least 2 years leading technical teams.
- Strong understanding of cloud technologies, with broad familiarity across GCP, AWS, and Azure environments.
- Demonstrated success leading and completing audits against major compliance frameworks such as SOC 2, ISO 27001, and ISO 42001.
- Strong practical knowledge of AI governance, AI safety, privacy within AI pipelines, and LLM threat modeling, including OWASP Top 10 for LLMs.
- Solid knowledge of established security and risk frameworks and methodologies, including MITRE ATT&CK, CIS, NIST, and ISO standards.
- Strong understanding of global and regional data protection requirements, including India's DPDP Act, GDPR, CCPA, PDPA, and cross-border data transfer governance.
- Knowledge of networking, identity and access management, cloud security architecture, and modern security best practices.
- Hands-on familiarity with SIEM, DLP, EDR, vulnerability management, endpoint management, and security monitoring technologies.
- Experience managing departmental budgets, negotiating vendor agreements, conducting third-party assessments, and overseeing external technology partners.
- Excellent written and verbal communication skills, with the ability to translate complex technical and compliance topics for customers, executives, and non-technical stakeholders.
- Strong analytical, problem-solving, prioritization, and time-management abilities, particularly when managing complex cross-functional initiatives simultaneously.
- Proactive and adaptable approach, with the ability to respond effectively to evolving business requirements, unexpected security challenges, and high-priority incidents.
- Collaborative team-player mindset and ability to work effectively with functions including sales, marketing, customer support, product development, and technical teams.
- Willingness to work flexibly across global time zones and contribute with an all-hands-on-deck mentality when required.
- Industry certification in information security or risk management, such as CCSP, CISSP, CISM, or CRISC.
- Bachelor's degree in Computer Science, Information Technology, Information Systems, IT Management, or a related discipline.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 6, 2026
- First seen
- October 6, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 6, 2026
Signal breakdown
Similar Compliance jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.