Program Manager, Commercial Compliance

MongoDB MongoDB · Enterprise · NJ · Remote · Govt Risk Compliance (GRC)

This role manages the strategy, execution, and maintenance of global security certifications and regulatory requirements for MongoDB's cloud database products, ensuring they meet rigorous security standards for customers in highly regulated industries. It acts as the primary interface between external auditors and internal teams, translating complex regulatory requirements into scalable operational processes.

What you'd actually do

  1. Lead the end-to-end execution of specialized external audits (e.g., ENS High, IRAP, ISO 22301) and coordinate all phases from initial scoping to final certification
  2. Serve as the lead point of contact for Financial Services customer audits, facilitating meetings, responding to security questionnaires, and defending our control environment to external stakeholders
  3. Lead internal audit cadences and drive the POA&M tracking process, ensuring technical teams remediate findings within required SLAs
  4. Map new regulatory requirements to our central control framework, performing gap analyses to identify where existing controls can be leveraged for new certifications
  5. Conduct NIST CSF or similar maturity assessments to monitor the effectiveness of the Compliance Program and report findings to team leads

Skills

Required

  • 7+ years in GRC, Information Security, or IT Audit, specifically within a high-growth SaaS/Cloud environment
  • Deep understanding of cloud security principles (AWS/GCP/Azure) and a proven track record leading technical audits for ISO 27001, SOC 2, or ENS High
  • Solid grasp of audit processes, terminology, and risk assessment standards
  • Exceptional ability to lead meetings with external customers and auditors, translating technical complexities into business risk and compliance assurance
  • Advanced proficiency in Jira for tracking control performance data and managing high-volume remediation workflows
  • Practical experience performing gap analyses and maturity assessments at an enterprise level

Nice to have

  • CISA
  • CRISC
  • CISSP
  • ISO Lead Implementer

What the JD emphasized

  • lead high-stakes audits
  • specialized compliance workstreams
  • full ownership of complex international frameworks
  • manages the relationship with our Financial Services customers during audit deep-dives
  • lead internal audit cadences
  • perform gap analyses
  • operate with minimal supervision
  • own the success of the program
  • navigate complex audit negotiations
  • drive internal technical teams toward compliance milestones