Senior Manager, Policy and Controls Governance
MongoDB
- Location
- United States
- Work model
- Remote
- Level
- Senior
- Salary
- $114k/yr
- H-1B history
- 30 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives.
The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness.
This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives.
This role will be based remotely in the United States
Responsibilities
Scope of Ownership
• Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance
• Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight
• Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility
• Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings
• Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness
Program Leadership
• Own and evolve the governance model for policies, standards, procedures and controls, ensuring clear accountability, consistent execution and audit-ready outputs
• Lead the end-to-end policy lifecycle, including creation, review, approval, publication, maintenance, retirement and exception governance
• Lead the controls governance program, including common controls framework ownership, framework revision management, control harmonization and periodic cross-functional control reviews
• Own the governance model for ARC issues and remediation tracking, including workflows for intake, tracking, monitoring, closure validation and ongoing reporting
• Ensure policies and controls remain aligned with compliance requirements, and translate framework changes into actionable program updates
People Management
• Manage and develop team members responsible for policy governance, controls governance, and related operational processes by setting priorities, driving workload clarity, and coaching for strong execution
• Establish a high bar for quality, accountability, and follow-through while supporting team growth through regular feedback and development
Cross-functional Partnership
• Partner within ARC and across Security, Engineering, Product, and Legal teams to align requirements, resolve blockers, and drive timely decisions
• Coordinate with policy owners, subject matter experts and operational stakeholders to drive timely reviews, required updates, and exception handling
• Serve as a key point of contact for compliance audit support related to policy governance and controls governance processes and program documentation
Operational excellence and metrics
• Define, maintain and evolve KPIs, KRIs, dashboards and reporting that measure policy