Jobs in United States

Information Security Governance in United States

2,329 active opportunities · Updated October 2026

Explore current information security governance jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.

P
📍 New York, New York, United States· Full-time
✓ Quality checkedCompany trend -70%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program — ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust. About the Role You will own Plaid’s Security Contracts workstream end-to-end—the DRI for how security contract reviews get done, how fast they move, and how the program improves over time. You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they n

AWSAIGoRust
P
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -70%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with

PythonSQLAWSCI/CD
P
📍 New York, New York, United States· Full-time
✓ Quality checkedCompany trend -70%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role: You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You

AWSAIGoRust
C
📍 Hartford, United States
✓ High-confidence listingCompany trend +340.2%
Quick readStrong listing-quality and freshness signals

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary The Executive Director - Business Information Security Officer (BISO) will serve as a senior leader and trusted security advisor supporting all CVS Health lines of business, with accountability for leading the BISO team and driving mission, vision, and governance model. This individual will provide senior‑level leadership, strategic and tactical guidance for a world‑class enterprise cybersecurity program. As a business enabler, the BISO is an effective communicator with the technical aptitude to embed security strategy and risk‑based decision‑making into all aspects of the business. The BISO understands security risks, threats, vulnerabilities, control frameworks, and security technologies and translates their impact in business terms. The BISO must be capable of working closely with senior IT business leaders, executive leadership, and business subject matter experts (SMEs). This role requires demonstrated leadership, exceptional organizational skills, strong business and financial acumen, and the ability to influence and drive change at scale across the organization. <

Project Management
PG
📍 Aliso Viejo, United States· Remote
✓ High-confidence listing
Quick readStrong listing-quality and freshness signals

Why Sony Interactive Entertainment? Sony Interactive Entertainment isn’t just the Best Place to Play — it’s also the Best Place to Work. Sony Interactive Entertainment (SIE) is the company behind the PlayStation brand. As a subsidiary of Sony Group Corporation, we’re part of a proud legacy of innovation and excellence. SIE is a dynamic technology company, delivering cutting-edge hardware and network services to more than 100 million people and an entertainment leader, home to some of the most beloved and recognizable intellectual properties (IP) in the world. Our role at SIE is to create and nurture the experiences under the PlayStation brand, a name synonymous with entertainment excellence and creativity. Are you a curiosity driven technologist who can quickly understand how an AI system works, identify where it could be misused or fail, and help a team find a practical path forward? Sony Interactive Entertainment is seeking a Senior AI Security Risk Analyst to provide hands-on security support for AI systems, agents, workflows, tools, and integrations across SIE. Role Summary: In this role, you will operate at the intersection of modern AI technology, security risk, architecture, and enablement. You will conduct AI security reviews using SIE’s established security risk assessment methodology, policies, standards, and control expectations, adapting their application to AI-enabled and agentic systems and identifying where AI-specific guidance or controls are needed. You will coordinate risk-focused design and architecture input and translate AI-specific weaknesses into decision-ready recommendations and engineering actions. You will serve as an approachable security partner, working cross-functionally with teams across SIE’s business units and functions to support a diverse range of AI use cases, systems, and technologies. You will work especially closely with Responsible AI & Governance and coordinate expertise across Information Security teams and IT &amp

R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $209.3K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr

AWSGitAIGo
R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $233.6K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior Manager of Infrastructure Security. You will help shape the future of Platform Security at Roblox. We work closely with Production IAM, Network Security, and Cloud Security at Roblox. You Will: Identify security gaps and threats in our cloud and on premise infrastructure, partnering with Governance Risk and Compliance teams to create standards and policies along the way. This will help Roblox meet regulatory and compliance requirements. Harden our infrastructure by introducing secure by default configurations, designs and guardrails for all developers at Roblox. Own and drive solutions that enable Roblox engineers to design, build, and use infrastructure securely at scale. Work closely with other InfoSec teams (AppSec, D&R, GRC, CorpSec, CloudSec, NetSec) and partner with engineering teams across Roblox, specifically the Infrastructure organization, to ensure the secure outcomes of security and product driven initiatives. You Have: 5+ years of experience writing code and/or relevant technical experience. Experience with

AWSKubernetesGitLinux
R
📍 San Mateo, CA, United States· Full-time
✓ High-confidence listingCompany trend -100%

From $243.3K/yr

Quick readStrong listing-quality and freshness signals

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Enterprise Security Engineer, you will play a critical role in executing Roblox’s Enterprise Security Strategy. You will design, deploy, and manage security solutions to protect Roblox’s corporate infrastructure and ensure secure, compliant operations across the organization. Working closely with Corporate Engineering and Trust & Safety teams, you will translate business requirements into robust security implementations that enable secure productivity while mitigating risk. You will be reporting directly to the Senior Manager of Enterprise Security Engineering. You'll partner with security professionals across the Information Security organization, and work cross-functionally with teams throughout Roblox to drive security initiatives that scale with our business. You will: Evaluate and implement security technologies and vendor solutions to ensure alignment with enterprise security requirements, compliance standards, and overall risk management strategy Lead and drive initiatives across core security domains, including Endpoint Security, SaaS Security, Identity & Access Management (IAM), Agentic AI Governance, and Supply Chain Security. Collaborate closely with IT, engin

AWSGitAIGo
O
📍 United States· Full-time
✓ Quality checkedCompany trend -79.2%

About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure, protecting sensitive data, and meeting global compliance standards are essential to our success and societal impact. Security at OpenAI is a cross-cutting function that spans infrastructure, applied engineering, legal, policy, and product. Technical Program Managers (TPMs) play a critical leadership role in aligning teams and delivering execution at scale and this role will be foundational in shaping how we secure OpenAI’s systems, users, and commitments. About the Role We’re seeking a Senior Technical Program Manager to drive cross-functional security, privacy, IT and compliance initiatives at the intersection of infrastructure, product, and policy. You will execute complex programs that reduce internal data access, prevent misuse, and ship security capabilities. You will focus your efforts on the most critical initiatives within Security, crossing the spectrum of insider threat, information security, physical security, and information technology challenges. This role is deeply technical and execution-focused. It requires a structured operator who thrives in ambiguity, partners effectively across boundaries, and applies principled judgment to scale trust, governance, and security across OpenAI’s systems and products. In this role, you will: Drive execution of critical security and compliance programs such as vulnerability management, merger and acquisition security and integration, infrastructure hardening, and datacenter security management. You will need to deeply collaborate on technical architecture and resolve technical problems in partnership with engineering. Partner with IT, Infrastructure, Application, Legal, Privacy, and Security teams to build scalable programs, and deliver critical security outcomes across multiple disciplines, including insider threat, information

AWSRestAIGo
P
📍 San Francisco, California, United States· Full-time
✓ High-confidence listingCompany trend -100%
Quick readStrong listing-quality and freshness signals

Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat

AWSKubernetesCI/CDGraphql
H
📍 United States· Remote
✓ High-confidence listingCompany trend +310%
Quick readStrong listing-quality and freshness signals

Become a part of our caring community The Associate Vice President, Model & AI Governance, is the enterprise leader responsible for establishing and overseeing the organization’s framework for model governance, artificial intelligence (AI) risk management, responsible AI and AI governance. Reporting to the Chief Audit & Risk Officer, this executive provides independent second-line oversight and challenge of the organization’s use of models, advanced analytics, machine learning, generative AI, and emerging AI technologies. The role establishes the governance, risk-management, control, monitoring and escalation framework necessary to ensure AI models are deployed in a manner that is safe, ethical, transparent, explainable, compliant, secure and aligned with the organization’s mission and risk appetite. The Associate Vice President, Model & AI Governance, partners closely with executive leadership, technology, data and analytics, clinical/business leaders, compliance, legal, privacy, cybersecurity, information security, internal audit, enterprise risk management and other control functions to ensure AI-related risks are identified, assessed, governed, monitored, and appropriately reported. This leader will serve as an advisor to executive management on emerging model and AI risks, while maintaining appropriate independence from the teams developing and deploying models and AI solutions. Key Responsibilities Own and continuously enhance the enterprise model governance framework, including model identification, inventory, classification, risk tiering, development, validation, approval, implementation, monitoring, change management, retirement and documentation. Define model risk appetite, risk taxonomy, minimum control standards, governance requirements and escalation thresholds. Provide effective challenge over model

Machine LearningArtificial IntelligenceAIRecruitment
D
📍 United States· Full-time
✓ High-confidence listingCompany trend -91.5%

From $210K/yr

Quick readStrong listing-quality and freshness signals

Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: As Drata scales, we want our security and GRC leadership to be able to meet our customers’ needs in more places at once—in strategic customer conversations, on stage at industry events, and in the broader conversations happening across our security and GRC communities. We’re looking for a Field Chief Information Security Officer to join Drata’s Security & GRC organization, repo

RestAIGoRust
MT
📍 Austin, TX, United States
✓ High-confidence listingCompany trend +1266.7%
Quick readStrong listing-quality and freshness signals

Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. Join Micron as a Senior Manager, Logistics Security Program, where you will have the outstanding opportunity to lead a world-class global security initiative! This role is critical in ensuring the flawless implementation of our logistics security strategy, encouraging collaboration with key partners, and advancing our program to new heights. Responsibilities: Direct Micron’s worldwide logistics security initiative for valuable shipments, establishing strategy, governance, standards, controls, and performance expectations throughout the transportation network. Lead and expand a distributed team of logistics security experts while promoting uniform performance across Asia Pacific, the Americas, Europe, and other priority regions. Maintain a risk-based shipment security framework that assesses lane, geography, modality, theft history, business impact, recovery capability, and other key risk factors. Establish and enforce logistics provider security requirements, including cargo tracking, route compliance, geofencing, chain of custody, tamper detection, monitoring, blocking issue, and recovery protocols. Partner multi-functionally with Procurement, Logistics, Global Security, Legal, Risk, Finance, and business collaborators to integrate security requirements into contracts, procedures, governance, and scorecards. Coordinate logistics security vendors and providers, including selection, performance management, service levels, monitoring operations, recovery capabilities, and corrective ac

AIFinanceSupply ChainLogistics
O
📍 San Francisco, California, United States· Full-time· Remote
✓ High-confidence listingCompany trend -79.2%
Quick readStrong listing-quality and freshness signals

About the Team OpenAI’s Governance team helps shape how the company responsibly develops and deploys increasingly capable AI. We bring together technical evidence, policy, and operational perspectives to help the company address emerging risks, resolve difficult questions, and make well-supported decisions. Our work includes shaping and improving governance practices, supporting effective oversight, developing clear assessments and recommendations, and ensuring that decisions lead to action. We work closely with research, safety, security, legal, and product teams to identify gaps, reconcile different views, and improve our approach as capabilities and circumstances change. About the Role We are looking for a curious, high-agency Research Program Manager who can reason from first principles, make sense of incomplete or conflicting information, and move difficult work forward. You will help shape the substance of governance reviews, connect ideas and evidence across teams, and develop recommendations that are both well-founded and practical. The work requires someone who can use established approaches where they fit, recognize when circumstances call for a different approach, and update their thinking as new evidence emerges. You should bring sound judgment, a willingness to experiment and learn, and the program-management discipline to turn good analysis into action. Depending on your experience and the team’s needs, your work may focus on safety advisory and board-level oversight, deployment governance, or standards and strategic partner commitments. In this role, you will: Bring together technical, policy, and operational inputs to develop coherent assessments, recommendations, and decision materials for governance bodies and senior leaders. Work through emerging or ambiguous questions, test assumptions, identify gaps or conflicting evidence, and help determine what additional analysis or decisions are needed. Engage critically with research, evaluations, safeguar

AWSRestAIGo
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -79.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Secure Manufacturing & Stealth (SMS) team protects OpenAI’s most sensitive product, manufacturing, launch, and partnership work from theft, leakage, espionage, and unauthorized disclosure. We operate across physical, digital, human, and third-party domains, building practical protections that allow teams to move quickly while preserving strict need-to-know controls. About the Role We are seeking a senior Secure Manufacturing & Stealth Partner to serve as the dedicated SMS owner for Marketing. This person will build trusted relationships across Marketing, understand launches and sensitive information flows, identify secrecy risks early, and embed practical controls into planning, creative production, events, agencies, vendors, media, and executive communications. The role owns the Marketing relationship while coordinating shared SMS capabilities when investigative, prototype-handling, regional, or other specialist support is needed. In this role you will: Serve as the primary SMS Partner and trusted adviser to Marketing, building a deep understanding of its priorities, planning cycles, launches, events, external partners, and sensitive information flows. Identify secrecy and information-exposure risks early, then translate SMS requirements into practical controls that protect sensitive work without unnecessarily slowing execution. Build, document, and socialize durable operating mechanisms for compartmentalization, need-to-know access, agencies and vendors, sensitive creative production, events, demonstrations, launch preparation, codenames, watermarking, and password controls. Assess and approve Marketing systems and information workflows, identify gaps or duplication, establish secure handling requirements, and advise AI-native Marketing initiatives on permissions, data governance, and operational tracking. Coordinate

AWSGitRestAI
🔔

Get new information security governance jobs in United States by email

Daily job updates · Unsubscribe anytime