Security Governance Lead

Cohesity

Dublin

Hybrid

EUR 110,000 - 150,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cohesity is seeking a Security Governance Lead to own policy and the proof for Cohesity's security controls and Common Controls Framework. You will work with Security and Engineering leadership to codify live security challenges into policy, using tooling and AI to derive meaningful, measurable control metrics.

Ideal candidates bring deep governance, risk, and compliance experience, familiarity with cloud-native security, and hands-on experience implementing GRC platforms such as ServiceNow GRC,

Qualifications

  • 8+ years of experience in cybersecurity, IT governance, GRC, or related roles.
  • Foundational knowledge of security frameworks (e.g., NIST CSF, ISO 27001, CIS Controls).
  • Comfortable with data behind technical controls and turning it into clear control metrics with tooling (AI-assisted where applicable).
  • Familiarity with security systems and cloud platforms (AWS/Azure/GCP), identity providers, or IT service tools like Jira/ServiceNow.
  • Experience implementing and customizing GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust).
  • Strong written and verbal communication; ability to engage cross-functional stakeholders.
  • Experience with audits and compliance (SOC 2, ISO 27001, GDPR, HIPAA).
  • Background in GRC engineering or security data engineering; dashboards, posture monitoring.

Responsibilities

  • Own the Cohesity Common Controls Framework end to end, including mapping to regulatory frameworks.
  • Define and publish Cohesity information security policies and standards; lifecycle management.
  • Collaborate with Security and Engineering leadership to codify emerging challenges into policy and controls.
  • Turn control data into real-time or recurring metrics using tooling and AI-assisted approaches.
  • Support internal and external audits with the cyber-Compliance team.
  • Maintain dashboards and documentation showing control effectiveness and KPIs.
  • Configure and customize GRC tooling to support evidence collection and posture reporting.
  • Collaborate with Security, IT, Legal and Engineering to solve control and compliance problems.

Skills

Security governance
Risk management
Policy development
Stakeholder engagement
Communication skills
GRC analytics
Audits
Cloud platforms
Python/SQL basics

Education

Bachelor's degree in Cybersecurity
ISO 27001 Lead Implementer (certification)

Tools

ServiceNow GRC
Archer
OneTrust
GRC tooling
Cloud & IT service tools (Jira)

Job description

Cohesity is the leader in AI-powered data security. Over 13,600 enterprise customers, including over 85 of the Fortune 100 and nearly 70% of the Global 500, rely on Cohesity to strengthen their resilience while providing Gen AI insights into their vast amounts of data. Formed from the combination of Cohesity with Veritas' enterprise data protection business, the company's solutions secure and protect data on-premises, in the cloud, and at the edge. Backed by NVIDIA, IBM, HPE, Cisco, AWS, Google Cloud, and others, Cohesity is headquartered in Santa Clara, CA, with offices around the globe. We've been named a Leader by multiple analyst firms and have been globally recognized for Innovation, Product Strength, and Simplicity in Design, and our culture.

We are looking for a Security Governance Lead who owns both the policy and the proof: deciding what belongs in Cohesity's security policies and Common Controls Framework, and staying just as comfortable in the technical data and systems that show whether those controls are actually working. This role suits someone with a strong foundation in cybersecurity governance, risk, and compliance who also wants to get hands-on with the tooling and data behind a modern security program.

How you'll spend your time here
  • Own the Cohesity Common Controls Framework end to end, including control definitions, control mapping, and alignment to regulatory and industry frameworks (e.g., ISO 27001, SOC 2, SOX, GDPR).
  • Determine what belongs in Cohesity's information security policies and standards, own their lifecycle from drafting through publication and communication, and partner with control owners to pressure-test enforceability and feasibility before requirements are codified (e.g., aligned to NIST, ISO 27001).
  • Work directly with Security and Engineering leadership to frame emerging security challenges and shape solutions that get codified into policy and the controls framework.
  • Understand the data behind Cohesity's technical controls, and use available tooling, including AI-assisted approaches, to turn that data into meaningful, real time or recurring control effectiveness metrics, driving the technology innovation that lets the program scale with the growing company.
  • Support internal and external audits by partnering with the cyber-Compliance team.
  • Partner with stakeholders to maintain documentation and dashboards that give visibility into control effectiveness and program KPIs, supporting continuous improvement.
  • Implement, configure, and customize GRC platform tooling, including connecting it to the underlying security and IT systems that feed it, to support control mapping, evidence collection, and posture reporting.
  • Collaborate day to day with Security, IT, Legal, and Engineering teams to solve control and compliance problems as they surface.
We’d love to talk to you if you have many of the following
  • 8+ years of experience in cybersecurity, IT governance, GRC, or related roles.
  • Foundational knowledge of security frameworks (e.g., NIST CSF, ISO 27001, CIS Controls).
  • Comfortable working with the data behind technical controls: knowing where it comes from, and able to use available tooling, including AI-assisted approaches, to turn it into a clear, meaningful control metric or status.
  • Familiarity with the kinds of technical systems that generate control evidence in a modern security program, such as cloud platforms (e.g., AWS, Azure, GCP), identity providers, or IT service and ticketing tools (e.g., ServiceNow, Jira).
  • Experience implementing and customizing GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust, or similar), not just operating a pre-built instance.
  • Strong organizational and communication skills, with the ability to engage cross-functional stakeholders.
  • Understanding of risk and compliance principles as they relate to enterprise cybersecurity programs.
  • Bachelor's degree or equivalent experience in Cybersecurity, Information Security, Risk Management, audit or a related field.
  • Experience writing, maintaining, and implementing security policies, standards, and procedures, including working with control owners on what's actually enforceable in practice.
  • Familiarity with audit processes and compliance requirements (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
  • Exposure to risk or control assessments and control testing.
  • Background in GRC engineering or security data engineering, building recurring control effectiveness monitoring or posture dashboards from technical source systems.
  • Basic scripting or query skills (e.g., Python, SQL, or similar) to help shape, validate, or automate control data.
  • Industry certifications such as Security+, ISO 27001 Lead Implementer, or similar are desirable.
  • Knowledge of security governance in cloud-first, SaaS, or DevOps environments.

This is a great opportunity for a rising security professional to take ownership of cyber security governance at a fast-growing, security-conscious tech company. You'll shape what actually goes into policy, work directly with Security and Engineering leadership on live security challenges, and use modern tooling, including AI-assisted approaches, to turn control data into meaningful metrics, all while working alongside a skilled and collaborative cybersecurity team. This work will directly impact the continued success of Cohesity.

Data Privacy Notice for Job Candidates: For information on personal data processing, please see our Privacy Policy.

Equal Employment Opportunity Employer (EEOE) Cohesity is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at 1-855-9COHESITY or recruiting@cohesity.com for assistance.

Cohesity employees who are within a reasonable commute (e.g. within a forty-five (45) minute average travel time) work out of our core offices 2-3 days a week of their choosing.

We strongly prefer candidates who are currently located in or near the designated job location. Candidates outside the area should apply only if they are committed to relocating prior to their start date and have the legal right to work in the job location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance Lead
Security Governance Lead

Cohesity • Ireland

On-site
EUR 90,000 - 130,000
Physical Security Application Engineer
Physical Security Application Engineer

Madrona Venture Labs • Cork

Hybrid
EUR 65,000 - 90,000
Physical Security Application Engineer
Physical Security Application Engineer

Cohesity • Cork

Hybrid
EUR 70,000 - 90,000
Security Governance Lead: Policy & Controls Architect
Security Governance Lead: Policy & Controls Architect

Cohesity • Dublin

Hybrid
EUR 110,000 - 150,000
Security Governance & Controls Lead
Security Governance & Controls Lead

Cohesity • Ireland

On-site
EUR 90,000 - 130,000
Procurement - Purchasing Analyst
Procurement - Purchasing Analyst

Cohesity • Ireland

On-site
EUR 45,000 - 70,000
Procurement - Purchasing Analyst
Procurement - Purchasing Analyst

Cohesity • Cork

On-site
EUR 42,000 - 70,000
Tax Director - EMEA
Tax Director - EMEA

Cohesity • Dublin

Hybrid
EUR 180,000 - 240,000
Tax Director - EMEA | Dublin - Ireland (Office)
Tax Director - EMEA | Dublin - Ireland (Office)

Cohesity Inc. • Dublin

On-site
EUR 180,000 - 260,000
Healthcare coverage for you and family
Paid parental leave
Flexible paid time off
+1
Tax Director – EMEA
Tax Director – EMEA

Madrona Venture Labs • Dublin

On-site
EUR 180,000 - 240,000