Compliance Product Owner

Adobe Adobe · Enterprise · Noida, India

Product Owner for Security Compliance Program in APAC region, focusing on driving technology compliance, supporting sales, building monitoring programs, and liaising with auditors and customers. Requires experience with security frameworks, cloud infrastructure, and AI security/governance.

What you'd actually do

  1. Perform information security assessments covering domains such as user access management, network security, OS & application security, encryption, backup management, disaster recovery, physical security, and training & awareness.
  2. Drive technology compliance activities across Adobe under the supervision and guidance of the Tech GRC manager.
  3. Answer customer questions around information security as they pertain to Adobe's individual applications & solutions and overall security posture.
  4. Provide support to sales organizations by speaking expertly and knowledgably about Adobe's information security control framework.
  5. Answer information gathering security questionnaires to support the sales process and represent Adobe's information security team on sales calls with customers.

Skills

Required

  • Bachelor’s degree or equivalent experience in Information Security/Cyber Security or related field.
  • Minimum 3-6 years of related security compliance assessments, IT/Cloud auditing, and control testing experience.
  • Proven knowledge of Security Compliance frameworks such as IRAP, Cyber Essential Eight, ISMAP, ISO 270xx, SOC 2, etc.
  • Strong auditing background, technical expertise, and deep knowledge of information security controls including but not limited to SDLC, Cryptography, Access management and Backup will be useful
  • Knowledge of cloud infrastructure like AWS, Azure, GCP, along with hands on experience
  • Knowledge of AI security and governance, with the ability to assess and implement controls for emerging technologies.
  • Good interpersonal, verbal and written communication skills.
  • Ability to anticipate questions, independently assess risk, and think critically and creatively.
  • Ability to work closely with others in a fast-paced environment.

Nice to have

  • Relevant security related certifications (e.g., CISA, CISM) are a plus.

What the JD emphasized

  • Security Compliance Program for APAC region
  • Security Compliance frameworks such as IRAP, Cyber Essential Eight, ISMAP, ISO 270xx, SOC 2, etc.
  • AI security and governance