Sr. Manager Risk & Governance

Adobe Adobe · Enterprise · San Jose, CA +3

This role leads Adobe's Security Risk and Governance program, focusing on advancing security risk strategy through qualitative and quantitative analysis. It involves improving decision-making using security insights, data analytics, and modeling, managing the Security Management framework, integrating risk measurement models, and driving the Security Policy & Procedures framework. The role requires expertise in security risk management models, regulatory frameworks, threat modeling, data analytics, and AI/ML for risk analysis, along with experience managing teams and optimizing GRC platforms.

What you'd actually do

  1. Transform the security risk program with qualitative and quantitative insights, using AI, data analytics, and financial analysis.
  2. Maintain and enhance Adobe’s security risk framework, ensuring accurate risk capture, prioritization, and compliance with regulatory changes.
  3. Lead the Security Governance and Policy program, aligning policies and standards with input from Security Architecture, Adobe CCF, Cyber Operations, and Product Security.
  4. Apply industry risk frameworks (e.g., FAIR, OCTAVE, NIST RMF, ISO 27005) to governance processes and quantify risks in financial terms to support executive decision-making.
  5. Develop dashboards and BI tools to visualize risk metrics for technical and non-technical partners.

Skills

Required

  • Security Risk Management
  • Team Management
  • Risk Management Models (FAIR, OCTAVE, NIST RMF, ISO 27005)
  • Regulatory Frameworks
  • Threat Modeling
  • Data Analytics
  • AI/ML for risk analysis
  • Automation Tools
  • Security Concepts
  • Security Tools
  • Industry Trends
  • Vulnerabilities
  • Security Policies and Standards
  • Cloud Architecture
  • Vulnerability Management
  • Policy Governance
  • Compliance with Audit Frameworks (SOC2, ISO 27001, NIST 800-53)
  • CISSP
  • CISM
  • CISA
  • CRISC

What the JD emphasized

  • 10+ years of experience in Security Risk Management
  • 3-5 years of experience managing high-performing teams.
  • Expertise in security risk management models (e.g., FAIR, OCTAVE, NIST RMF, ISO 27005) and regulatory frameworks.
  • Proficiency in threat modeling, data analytics, AI/ML, and automation tools for risk analysis.
  • Led Compliance with Audit Frameworks (e.g. SOC2, ISO 27001, NIST 800-53 etc.)