Risk & Governance Manager

Dropbox Dropbox · Enterprise · Canada +1 · Risk and Compliance (Sub Team)

This role focuses on establishing and maturing risk and governance programs within a SaaS company, with a specific emphasis on AI governance. The manager will partner with various teams to identify, assess, and mitigate risks related to AI products and services, ensuring compliance with AI principles, legal obligations, and customer trust commitments. Responsibilities include developing policies, controls, metrics, and guidance for AI use cases, risk assessments, and regulatory adherence.

What you'd actually do

  1. Support the design, implementation, and continuous improvement of Dropbox’s Governance, Risk, and Compliance programs, including quantitative risk management (FAIR), governance, controls, compliance readiness, issue management, and risk reporting.
  2. Plan and execute risk assessments, gap analyses, certification readiness activities, compliance reviews, and audit support processes across areas such as security, privacy, AI, reliability, third-party services, and operational risk.
  3. Partner with cross-functional stakeholders to identify risks, assess impact and likelihood, define mitigation plans, assign owners, and track risk reduction efforts through completion.
  4. Help implement, maintain, and mature programs that support Dropbox’s AI governance framework, company AI Principles, legal and regulatory obligations, and customer trust commitments.
  5. Partner with Product, Engineering, Security, Privacy, Legal, Compliance, and business teams to assess AI use cases and define practical governance requirements for intake, documentation, review, approval, monitoring, and issue remediation.

Skills

Required

  • 7+ years of experience building or maintaining risk, governance, compliance, audit, business resilience, security, privacy, or related programs
  • Experience at a publicly traded, fast paced SaaS company
  • Experience managing and reducing AI, security, privacy, or reliability risks
  • Knowledge of FAIR quantitative risk methodologies
  • Familiarity with a broad range of technical concepts relevant to cloud computing and SaaS environments: logical access, agile development process, security architecture, information security, network security, and privacy
  • Strong project management and organizational skills
  • Collaborative working style and strong relationship-building skills, with the ability to work effectively with both technical and non-technical teams
  • Excellent writing, communication, organizational skills, and strong attention to detail
  • Ability to confidently convey nuanced information to senior leaders

Nice to have

  • Related professional certifications such as AIGP (AI Governance Professional) or CIPP (Certified Information Privacy Professional) preferred

What the JD emphasized

  • AI governance framework
  • company AI Principles
  • legal and regulatory obligations
  • customer trust commitments
  • assess AI use cases
  • governance requirements
  • AI risk assessments
  • emerging AI regulatory
  • ethical
  • industry expectations
  • responsible AI practices