We are looking for an experienced Program Manager to drive Governance, Risk & Compliance (GRC) initiatives across our Infrastructure landscape. This role is central to orchestrating cross-functional programs that span Cybersecurity, Application Security, Cloud Infrastructure (AWS/GCP), Identity & Access Management (IAM), and Modern Workplace (M365) teams. A key focus of this role is driving the adoption and rollout of AI-powered capabilities — moving beyond traditional rule-based automation — to strengthen risk management, compliance monitoring, and security operations at scale.
Key Responsibilities
Cross-Functional Program Coordination
- Serve as the primary program-level point of coordination across multiple stakeholder groups, including Cybersecurity, Application Security, AWS Infrastructure, GCP Infrastructure, IAM, and M365 teams, to drive alignment on GRC initiatives.
- Build and maintain strong working relationships with engineering, security, and platform leads to ensure program objectives are understood, prioritized, and executed consistently across teams.
- Facilitate cross-team working sessions, steering committees, and governance forums to resolve dependencies, blockers, and conflicting priorities.
AI-Driven Initiative Rollout
- Lead the planning, rollout, and adoption of AI-based capabilities (e.g., ML-driven risk scoring, intelligent anomaly detection, AI-assisted compliance monitoring, LLM-based policy/control analysis) across infrastructure and security domains — distinct from traditional rule-based or scripted automation.
- Partner with data science, security engineering, and platform teams to translate AI/ML capabilities into practical GRC use cases such as automated risk detection, predictive compliance analytics, and intelligent control testing.
- Track emerging AI capabilities relevant to GRC and infrastructure risk management, and evaluate their applicability for the organization's control environment.
- Own the end-to-end rollout lifecycle for AI initiatives: use-case definition, pilot design, stakeholder buy-in, phased deployment, and post-rollout measurement of risk/compliance impact.
Governance, Risk & Compliance Ownership
- Maintain and evolve the GRC roadmap for infrastructure, ensuring initiatives map to applicable regulatory, audit, and internal control requirements.
- Track risk posture, control gaps, and remediation plans across cloud (AWS/GCP), identity (IAM), endpoint/collaboration (M365), and application security domains.
- Support internal and external audit engagements by coordinating evidence collection, control walkthroughs, and remediation tracking across stakeholder teams.
Program & Delivery Management
- Define program charters, milestones, RAID logs, and success metrics for each initiative; report progress to senior leadership and steering committees.
- Manage program budgets, resource allocation, and timelines across multiple concurrent work streams.
- Proactively identify risks and dependencies across teams and drive mitigation plans to avoid delivery slippage.
Reporting & Stakeholder Communication
- Develop executive-level dashboards, status reports, and risk heat-maps summarizing program health and AI-initiative rollout progress.
- Communicate technical AI/automation concepts in business-friendly terms to non-technical stakeholders and leadership.
Required Skills & Qualifications
- Bachelor's or Master's degree in Computer Science, Information Security, Risk Management, or related field.
- Proven experience in Program/Project Management within GRC, Cybersecurity, or Infrastructure domains.
- Demonstrated experience coordinating initiatives across multiple technical groups such as Cybersecurity, AppSec, Cloud Infra (AWS/GCP), IAM, and M365/Modern Workplace.
- Working knowledge of AI/ML concepts and their application to security and compliance use cases (e.g., anomaly detection, predictive risk analytics, generative AI for policy/control analysis) — distinguishing these from traditional scripted or rule-based automation.
- Familiarity with common GRC frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 2, PCI-DSS, CIS Benchmarks).
- Strong understanding of cloud infrastructure security (AWS, GCP), identity/access management principles, and enterprise collaboration platforms (M365).
- Excellent stakeholder management, executive communication, and presentation skills.
- Proven ability to manage multiple concurrent, cross-functional programs in a fast-paced, matrixed environment.
- PMP, PgMP, CISM, CISA, or CRISC certification is a plus.
Preferred / Nice-to-Have
- Prior experience piloting or scaling AI-based security/compliance tools (e.g., AI-driven SIEM/SOAR enhancements, AI copilots for GRC platforms, LLM-based control testing).
- Experience with GRC tooling (e.g., ServiceNow GRC, Archer, MetricStream) and cloud-native security posture management (CSPM) tools.
- Exposure to Agile/Scrum delivery methodologies for running technical rollout programs.
What Success Looks Like
- Seamless coordination across Cybersecurity, AppSec, AWS/GCP Infra, IAM, and M365 teams with minimal escalations.
- Successful, measurable rollout of AI-based GRC capabilities that demonstrably improve risk detection and compliance efficiency over legacy automation approaches.
- A mature, well-governed program cadence with clear visibility for leadership on risk, compliance, and initiative progress.