GRC Technical Program Manager
Listed on 2026-10-05
-
IT/Tech
Cybersecurity
At Net App, your ideas power innovation. We lead in intelligent data infrastructure—delivering unified storage, integrated data services, and solutions that help organizations unlock the full potential of their data, from AI to multicloud. Ready to innovate and contribute to our path to $10B? Here, you'll collaborate with passionate teams, tackle real-world challenges, and see your impact in how customers transform and grow.
If you're ready to bring curiosity, creativity, and drive to every moment, Net App is where your journey begins. Join teams that innovate to elevate, drive results, and excel together across every function.
Net App’s Cloud business seeks a Governance, Risk & Compliance (GRC) Technical Program Manager to join the Security & Compliance team. This compliance and program management role requires strong cloud technical fluency to prepare products for assessments and certifications, manage risk, translate requirements into testable controls, and improve the security posture. This is not a software engineering role. The position partners with engineering and security teams to automate compliance activities, detection, remediation, evidence collection, and monitoring, including through AI tooling.
The role also aligns cross‑functional stakeholders and represents the compliance program to leaders, auditors, and hyperscaler partners.
Location:
RTP, Boston, Waltham
- Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications.
- Perform technical gap and risk assessments across infrastructure, applications, and cloud engineering processes; monitor controls and advise owners on remediation.
- Translate regulatory and compliance controls into clear, measurable engineering and security requirements.
- Identify manual compliance activities for automation and partner with engineering and security teams on automated detection, remediation, evidence collection, and continuous monitoring.
- Apply AI and related tooling to improve compliance workflows.
- Align Engineering, SRE, Product, Cloud Security, Legal, Privacy, and Corporate Security teams and drive cross‑functional initiatives to completion.
- Partner with Microsoft Azure, Google Cloud, and Amazon Web Services on shared compliance and security objectives.
- Manage auditor and assessor relationships and clearly present the organization’s technical security posture.
- Improve policies, processes, security governance, and adoption of GRC tooling.
- 6+ years building and managing security risk and compliance programs, including ownership of large cross‑functional programs through certification.
- Deep knowledge of ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP, with demonstrated ability to convert controls into engineering requirements.
- Direct experience partnering with engineering teams to deliver technical outcomes.
- Exceptional stakeholder management and ability to influence senior stakeholders and external partners without direct authority.
- Strong technical fluency in AWS and Azure, Kubernetes, containers, virtual machines, identity and access control, network security, cryptography, logging and monitoring, incident response, Dev Ops, and CI/CD.
- Familiarity with cloud security capabilities, SIEM, vulnerability scanning, cloud security posture management, and endpoint detection and response.
- Product‑oriented problem solving with the ability to investigate gaps, gather requirements, and drive solutions to completion.
- Experience with FedRAMP, GovRAMP, CMMC, CJIS, and NIST 800-53/800-171.
- Experience applying AI or large language model tooling to compliance workflows and familiarity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).