Enterprise Security Trust Program Manager, Customer Trust

Snowflake Snowflake · Data AI · Germany, DE · Remote · Security

This role is for an Enterprise Security Trust Program Manager within Snowflake's Global Security Compliance & Risk team, focusing on customer trust across Europe, the Middle East, and Africa. The individual will manage the lifecycle of projects related to regulated industry compliance, including developing programs, managing compliance posture, responding to customer/regulatory inquiries, and participating in audits and sales calls. The role requires deep understanding of regulations like DORA, EU AI Act, and NIS2, along with technical audit experience and cloud provider knowledge. While the company is building an 'AI Data Cloud' and mentions AI as a collaborator, this specific role focuses on security, compliance, and program management within that context, rather than direct AI/ML model development or deployment.

What you'd actually do

  1. Develop understanding of regulated industry compliance requirements as they apply to Snowflake.
  2. Establish programs to manage Snowflake’s compliance posture with those regulations, including ensuring readiness, how we communicate that posture externally, and leading customer or regulator audits of the same.
  3. Become an expert on Snowflake’s control environment, security features and best practices for customer deployment.
  4. Respond to customer inquiries about Snowflake’s security and compliance obligations and lean into how we can enable customers and field personnel to increasingly self-serve.
  5. Become a trusted advisor, facilitator and respond to customer and regulatory inquiries about Snowflake’s security and compliance obligations and documentation.

Skills

Required

  • Deep understanding of regulations (DORA, EU AI Act, NIS2, FCA Guidance)
  • Technical audit experience (C5, Cyber Essentials Plus, PCI-DSS, SOC2, ISO, ISAE 3402)
  • Evaluating design and effectiveness of IT controls
  • Evidence collection for assessments
  • Working with auditors/regulators
  • Experience with AWS, Azure, GCP
  • Excellent interpersonal, verbal, and written communication skills
  • Ability to collaborate cross-functionally and across different time zones
  • Experience building certification roadmaps
  • Ensuring scheduled assessments are delivered on schedule

Nice to have

  • CISSP, CISM, CISA certifications
  • Experience with NIST 800-53 or HIPAA
  • Experience with SaaS/Cloud solutions
  • Database experience
  • AI Security and compliance

What the JD emphasized

  • Deep understanding of regulations, such as; EU Digital Operational Resilience Act (DORA), EU AI Act, NIS2, FCA Guidance: Operational resilience: Critical third parties to the UK financial sector and other applicable standards and requirements.
  • 10+ years of technical audit experience in programs such as C5, Cyber Essentials Plus, PCI-DSS, SOC2, ISO certifications or IT audits based on ISAE 3402
  • Experience building certification roadmaps based on regulatory requirements, compliance documentation, and ensuring that scheduled assessments are delivered on schedule.