Senior Manager, Enterprise Governance & Assurance

Netflix Netflix · Big Tech · United States · Remote · Engineering

Senior Manager to lead and grow a team of GRC, business continuity, and software engineering professionals, maturing Netflix's Enterprise Governance and Assurance capabilities. The role involves setting strategic vision, ensuring compliance with regulatory requirements (SOX, PCI-DSS, GDPR, ISO-27001), and driving a risk-driven, scalable GRC program with an emphasis on modern, engineering-first approaches. Experience building or leading GRC engineering functions that automate compliance workflows is desired.

What you'd actually do

  1. lead and grow a team of high-performing GRC, business continuity and software engineering professionals
  2. mature Netflix's Enterprise Governance and Assurance capabilities
  3. setting the strategic vision and execution across multiple functions
  4. partner broadly across the enterprise to meet continually evolving regulatory requirements in a fast moving and complex environment
  5. driving a pragmatic, risk-driven, and scalable GRC program with a strong emphasis on modern, engineering first approaches

Skills

Required

  • 10+ years in a combination of GRC, technology risk, compliance, audit/assurance, security governance, and/or operational resilience
  • at least 4 in a leadership role
  • building and growing high-performing teams
  • building controls and assurance programs that stand up to external scrutiny
  • deep expertise in regulatory and compliance frameworks and regimes including but not limited to: SOX, PCI-DSS, GDPR, and ISO-27001
  • risk-driven, scalable approaches over checkbox compliance
  • experience building or leading GRC engineering functions that automate compliance workflows, generate metrics, and reduce manual burden
  • operating in a cloud-native, engineering-driven environment
  • translate compliance requirements into technical solutions
  • meticulous and responsive cross-team communicator
  • work effectively with legal, finance, engineering, and executive stakeholders
  • empathetic leader who cultivates a culture of psychological safety and inclusion
  • coach, mentor, develop, and inspire a talented and diverse team across seniority levels
  • operate effectively in highly ambiguous and rapidly changing environments with minimal process and a heavy emphasis on individual responsibility

What the JD emphasized

  • regulatory obligations
  • regulatory requirements
  • SOX
  • PCI-DSS
  • GDPR
  • ISO-27001
  • GRC engineering functions