Security Governance Lead

Cohesity

Ireland

On-site

EUR 90,000 - 130,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cohesity is seeking a Security Governance Lead who owns policy and proof for Cohesity's security controls. You will lead the Common Controls Framework, draft and maintain information security policies, and partner with Security and Engineering to codify live challenges into policy.

You will leverage tooling, including AI-assisted approaches, to drive real-time control metrics and audit readiness. You will work with Security, IT, Legal, and Engineering to improve control effectiveness, and help

Qualifications

  • 8+ years in cybersecurity governance, IT security, GRC, or related roles.
  • Foundational knowledge of security frameworks (NIST CSF, ISO 27001, CIS).
  • Experience with control evidence data and analytics for metrics.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and ITSM tools.
  • Experience implementing and customizing GRC platforms beyond basic setups.

Responsibilities

  • Own the Cohesity Common Controls Framework end to end, including mapping and alignment to ISO 27001, SOC 2, SOX, GDPR.
  • Define and manage information security policies and standards from drafting to publication.
  • Collaborate with Security and Engineering leadership to codify emerging challenges into policy and controls.
  • Turn control data into real time or recurring metrics using tooling and AI-assisted approaches.
  • Support audits by partnering with the cyber-Compliance team and maintain KPI dashboards.

Skills

Cybersecurity governance
GRC awareness
Risk management
Policy development

Education

Bachelor's degree in Cybersecurity or related field

Tools

GRC platforms
Security tooling data analysis
Cloud security controls

Job description

Cohesity is the leader in AI-powered data security. Over 13,600 enterprise customers, including over 85 of the Fortune 100 and nearly 70% of the Global 500, rely on Cohesity to strengthen their resilience while providing Gen AI insights into their vast amounts of data. Formed from the combination of Cohesity with Veritas' enterprise data protection business, the company's solutions secure and protect data on-premises, in the cloud, and at the edge. Backed by NVIDIA, IBM, HPE, Cisco, AWS, Google Cloud, and others, Cohesity is headquartered in Santa Clara, CA, with offices around the globe. We've been named a Leader by multiple analyst firms and have been globally recognized for Innovation, Product Strength, and Simplicity in Design, and our culture.

We are looking for a Security Governance Lead who owns both the policy and the proof: deciding what belongs in Cohesity's security policies and Common Controls Framework, and staying just as comfortable in the technical data and systems that show whether those controls are actually working. This role suits someone with a strong foundation in cybersecurity governance, risk, and compliance who also wants to get hands-on with the tooling and data behind a modern security program.

How you'll spend your time here
  • Own the Cohesity Common Controls Framework end to end, including control definitions, control mapping, and alignment to regulatory and industry frameworks (e.g., ISO 27001, SOC 2, SOX, GDPR).
  • Determine what belongs in Cohesity's information security policies and standards, own their lifecycle from drafting through publication and communication, and partner with control owners to pressure-test enforceability and feasibility before requirements are codified (e.g., aligned to NIST, ISO 27001).
  • Work directly with Security and Engineering leadership to frame emerging security challenges and shape solutions that get codified into policy and the controls framework.
  • Understand the data behind Cohesity's technical controls, and use available tooling, including AI-assisted approaches, to turn that data into meaningful, real time or recurring control effectiveness metrics, driving the technology innovation that lets the program scale with the growing company.
  • Support internal and external audits by partnering with the cyber-Compliance team.
  • Partner with stakeholders to maintain documentation and dashboards that give visibility into control effectiveness and program KPIs, supporting continuous improvement.
  • Implement, configure, and customize GRC platform tooling, including connecting it to the underlying security and IT systems that feed it, to support control mapping, evidence collection, and posture reporting.
  • Collaborate day to day with Security, IT, Legal, and Engineering teams to solve control and compliance problems as they surface.
We’d love to talk to you if you have many of the following
  • 8+ years of experience in cybersecurity, IT governance, GRC, or related roles.
  • Foundational knowledge of security frameworks (e.g., NIST CSF, ISO 27001, CIS Controls).
  • Comfortable working with the data behind technical controls: knowing where it comes from, and able to use available tooling, including AI-assisted approaches, to turn it into a clear, meaningful control metric or status.
  • Familiarity with the kinds of technical systems that generate control evidence in a modern security program, such as cloud platforms (e.g., AWS, Azure, GCP), identity providers, or IT service and ticketing tools (e.g., ServiceNow, Jira).
  • Experience implementing and customizing GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust, or similar), not just operating a pre-built instance.
  • Strong organizational and communication skills, with the ability to engage cross-functional stakeholders.
  • Understanding of risk and compliance principles as they relate to enterprise cybersecurity programs.
  • Bachelor's degree or equivalent experience in Cybersecurity, Information Security, Risk Management, audit or a related field.
  • Experience writing, maintaining, and implementing security policies, standards, and procedures, including working with control owners on what's actually enforceable in practice.
  • Familiarity with audit processes and compliance requirements (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
  • Exposure to risk or control assessments and control testing.
  • Background in GRC engineering or security data engineering, building recurring control effectiveness monitoring or posture dashboards from technical source systems.
  • Basic scripting or query skills (e.g., Python, SQL, or similar) to help shape, validate, or automate control data.
  • Industry certifications such as Security+, ISO 27001 Lead Implementer, or similar are desirable.
  • Knowledge of security governance in cloud-first, SaaS, or DevOps environments.

This is a great opportunity for a rising security professional to take ownership of cyber security governance at a fast-growing, security-conscious tech company. You'll shape what actually goes into policy, work directly with Security and Engineering leadership on live security challenges, and use modern tooling, including AI-assisted approaches, to turn control data into meaningful metrics, all while working alongside a skilled and collaborative cybersecurity team. This work will directly impact the continued success of Cohesity.

Data Privacy Notice for Job Candidates: For information on personal data processing, please see our Privacy Policy.

Equal Employment Opportunity Employer (EEOE) Cohesity is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at 1-855-9COHESITY or recruiting@cohesity.com for assistance.

Cohesity employees who are within a reasonable commute (e.g. within a forty-five (45) minute average travel time) work out of our core offices 2-3 days a week of their choosing.

We strongly prefer candidates who are currently located in or near the designated job location. Candidates outside the area should apply only if they are committed to relocating prior to their start date and have the legal right to work in the job location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance Lead
Security Governance Lead

Cohesity • Dublin

Hybrid
EUR 110,000 - 150,000
Physical Security Application Engineer
Physical Security Application Engineer

Madrona Venture Labs • Cork

Hybrid
EUR 65,000 - 90,000
Physical Security Application Engineer
Physical Security Application Engineer

Cohesity • Dublin

Hybrid
EUR 60,000 - 90,000
Hybrid work schedule
Physical Security Application Engineer
Physical Security Application Engineer

Cohesity • Cork

Hybrid
EUR 70,000 - 90,000
Security Governance Lead: Policy & Controls Architect
Security Governance Lead: Policy & Controls Architect

Cohesity • Dublin

Hybrid
EUR 110,000 - 150,000
Security Governance & Controls Lead
Security Governance & Controls Lead

Cohesity • Ireland

On-site
EUR 90,000 - 130,000
Procurement - Purchasing Analyst
Procurement - Purchasing Analyst

Cohesity • Ireland

On-site
EUR 45,000 - 70,000
Procurement - Purchasing Analyst
Procurement - Purchasing Analyst

Cohesity • Cork

On-site
EUR 42,000 - 70,000
Tax Director - EMEA
Tax Director - EMEA

Cohesity • Dublin

Hybrid
EUR 180,000 - 240,000
Tax Director - EMEA | Dublin - Ireland (Office)
Tax Director - EMEA | Dublin - Ireland (Office)

Cohesity Inc. • Dublin

On-site
EUR 180,000 - 260,000
Healthcare coverage for you and family
Paid parental leave
Flexible paid time off
+1