Senior Compliance Program Manager, Audit Response

Roblox Roblox · Consumer · San Mateo, CA · Project Management (Non-Tech)

Roblox is seeking a Senior Program Manager to lead their compliance audit response efforts. This role involves coordinating between internal teams (Engineering, Product, Safety), external auditors, and Legal to manage the end-to-end audit lifecycle, ensure evidence quality, and track remediation. The ideal candidate will have experience in program management, compliance, risk management, or external audit, with a strong understanding of regulatory frameworks and legal acumen.

What you'd actually do

  1. Lead Compliance Audit Execution: Orchestrate the end-to-end lifecycle of internal and external audit requirements, ensuring strict adherence to timelines and scope.
  2. Act as the Primary Coordinator: Serve as the central coordinating function for audit activities. You will translate auditor requests into actionable tasks for Engineering, Product, and Safety teams, and conversely, translate internal information into audit evidence.
  3. Manage Legal Sign-Off Workflows: Design and enforce a rigorous chain-of-custody process for all audit evidence. You will ensure that no document, data point, or response is submitted to external auditors without explicit review and approval from designated Legal SMEs.
  4. Drive Readiness & Mock Audits: Help Roblox improve its audit readiness through "mock audit" exercises to identify risks and ensure internal teams are prepared for rigorous audit requirements.
  5. Coordinate Evidence Gathering: Manage the collection, organization, and repository of thousands of evidence artifacts. You will challenge the quality of evidence provided by SMEs to ensure it fully answers the audit test steps before it reaches Legal review.

Skills

Required

  • 7+ years of experience in Program Management, Compliance, Risk Management, or External Audit
  • Demonstrated capability to become fluent in relevant regulatory frameworks, especially those focused on online safety.
  • Proven ability to manage complex third-party audits (e.g., SOC2, ISO, Regulatory Audits) from scoping to final report.
  • Experience working closely with Legal Counsel.
  • The ability to influence stakeholders without direct authority.
  • Exceptional project management skills with the ability to track hundreds of moving parts simultaneously using tools like Jira, Asana, Airtable or GRC platforms.
  • Excellent writer and verbal communicator who can synthesize complex technical and legal concepts for diverse audiences.

What the JD emphasized

  • rigorous internal and external regulatory compliance audit requirements
  • rigorous chain-of-custody process
  • rigorous audit requirements
  • rigorous audit requirements