Certification Program Compliance and Risk Manager
Listed on 2026-08-02
-
IT/Tech
Cybersecurity
About ISACA
ISACA® ("(Use the "Apply for this Job" box below).") champions the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 195 countries and with more than 230 chapters worldwide, ISACA offers resources tailored to every stage of members’ careers—helping them to thrive in a rapidly changing digital landscape, drive trusted innovation and ensure a more secure digital world.
Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.
This position is accountable for managing ISACA’s credentialing programs policies, including certification, recertification, appeals, and exam security policies and ensuring that certification operational procedures are compliant with these policies. This position is responsible for ensuring that all certification policies and procedures are compliant with the ISO/IEC 17024:2026 standard via the ANAB accreditation.
This position is also responsible for the design, implementation and testing of controls to mitigate risk associated with exam IP and certification fraud, as well as continuous monitoring of the certification threat landscape.
This position oversees credentialing policy-driven activities, supports regulatory compliance, and collaborates with internal teams to maintain high standards of exam integrity and certification management system efficiency.
Responsibilities- Identify and document risk scenarios and work with internal and external stakeholders to develop, implement, and test controls to mitigate impact. Maintain ISACA’s Certification Impartiality Threat Analysis to address emerging threats within ISACA’s certification landscape.
- Own the governance, review, and continuous improvement of the Certification Policies and Procedures Manual, ensuring certification policies, processes, and controls remain compliant with ISO/IEC 17024:2026 requirements. Assess the impact of policy changes, identify compliance risks and gaps, and partner with Sr. Management to implement corrective actions and maintain accreditation readiness.
- Manage the completion and maintenance of ANSI accreditation process documentation required for the annual surveillance application of ISACA certification programs. Coordinate with internal stakeholders to gather, review, and validate evidence of compliance with accreditation requirements, ensuring documentation is accurate, complete, and submitted within established timelines. Assist in the evaluation of surveillance findings, contribute to root cause analyses of identified nonconformities, and manage the development, implementation, monitoring, and validation of corrective actions to address compliance risks and maintain continued accreditation status for ISACA certifications.
- Maintain and update certification-control documents (ECG, CPE Policy,) and verify ISACA external (e.g. website) information aligns to updated policy or procedures.
- Conduct compliance reviews of the certification management system to ensure continuous compliance with the ISO/IEC 17024:2026 Standard. Conduct periodic certification management system review meetings with Senior Management to identify inefficiencies and potential enhancements, document and implement resolutions.
- Oversee the conduct of investigations into suspected fraudulent cases, document findings, and report to appropriate stakeholders. Develop and analyze KRIs for each certification-related risk.
- Coordinate with legal, cybersecurity, IT and product teams to address large-scale certification fraud. Analyze data and create reports for management on potential fraud risks, trends, and the results of investigations. Prepare and present certification compliance metrics, annual assessment results, and accreditation-related reporting for governance bodies, including the Audit and Risk Committee (ARC), ensuring transparency,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).