Jobiba hiring network

Senior Security Risk Management Framework Engineer Jobs

7,292 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current senior security risk management framework engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.

CH
Cohere Health
📍 Hyderabad• Full-time
15 days ago

Opportunity Overview: We’re looking for a senior-level automation engineer who will help raise the bar on release quality, environment reliability, and change safety across Cohere’s platform. You’ll partner closely with Product, Engineering, Platform, and SRE to build scalable automation, guardrails, and validation systems that reduce production risk while increasing delivery velocity. This is not a “test scripts only” role. You’ll shape automation strategy, embed quality into the SDLC, and help define how changes move safely from dev → staging → UAT → prod in a fast-moving healthcare platform. You’ll help define how quality scales as Cohere grows. This role has real influence over release safety, platform reliability, and how engineering teams ship software in a regulated, high-impact domain. You won’t just test features — you’ll shape how Cohere delivers them safely to production. What you’ll do: Own and evolve Cohere’s end-to-end test automation strategy across UI, API, config changes, and critical workflows Design and maintain scalable E2E automation frameworks for multi-tenant, payer-specific workflows Build automated validation for deployment guardrails, release readiness, and production change safety Partner with Platform/DevOps to integrate automation into CI/CD pipelines and deployment workflows Create automated coverage for high-risk paths (authorization flows, partner integrations, file pipelines, feature flags, config changes) Drive test reliability, flake reduction, and actionable failure signals Define and enforce quality gates for prod releases, blue/green and canary deployments, and config changes Collaborate with Product and Engineering to ensure business outcomes are testable, measurable, and observable Improve test data management and environment stability to enable reliable automation at scale Mentor engineers on testability, automation best practices, and quality-first development Partner with SRE and Security to ensure production readines

typescriptawsci/cd
View job →
CH
Cohere Health
📍 Hyderabad• Full-time
15 days ago

Opportunity Overview: We’re looking for a senior-level automation engineer who will help raise the bar on release quality, environment reliability, and change safety across Cohere’s platform. You’ll partner closely with Product, Engineering, Platform, and SRE to build scalable automation, guardrails, and validation systems that reduce production risk while increasing delivery velocity. This is not a “test scripts only” role. You’ll shape automation strategy, embed quality into the SDLC, and help define how changes move safely from dev → staging → UAT → prod in a fast-moving healthcare platform. You’ll help define how quality scales as Cohere grows. This role has real influence over release safety, platform reliability, and how engineering teams ship software in a regulated, high-impact domain. You won’t just test features — you’ll shape how Cohere delivers them safely to production. What you’ll do: Own and evolve Cohere’s end-to-end test automation strategy across UI, API, config changes, and critical workflows Design and maintain scalable E2E automation frameworks for multi-tenant, payer-specific workflows Build automated validation for deployment guardrails, release readiness, and production change safety Partner with Platform/DevOps to integrate automation into CI/CD pipelines and deployment workflows Create automated coverage for high-risk paths (authorization flows, partner integrations, file pipelines, feature flags, config changes) Drive test reliability, flake reduction, and actionable failure signals Define and enforce quality gates for prod releases, blue/green and canary deployments, and config changes Collaborate with Product and Engineering to ensure business outcomes are testable, measurable, and observable Improve test data management and environment stability to enable reliable automation at scale Mentor engineers on testability, automation best practices, and quality-first development Partner with SRE and Security to ensure production readines

typescriptawsci/cd
View job →
M
Mongodb
📍 United States• Full-time• From $114K/yr
1mo ago

The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives. The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness. This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives. This role will be based remotely in the United States Responsibilities: Scope of Ownership Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness Program Leadership Own

mongodbawsazure
View job →
AI
AlphaSense India
📍 India• Full-time• Remote
15 days ago

About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Role AlphaSense is maturing its security risk management program and needs a Senior Risk Analyst to be a core builder and operator of that function. You will design, implement, and mature a risk framework that spans information security, AI, and operational risk—building toward a program that is quantitative-leaning, connected to live data sources, and actionable at every altitude from service owner to executive leadership. You will establish risk identification and scoring methodologies, own the enterprise risk register, and produce risk intelligence that drives real decisions. You will also support the TPRM function led by a dedicated TPRM lead, contributing to assessments and risk tracking as needed. You approach this with an AI-native mindset: using AI to monitor threat landscapes, analyze risk data, draft risk narratives, and surface emerg

REMOTEjavascriptpythonjava
View job →
W
12 days ago

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: As the Technology Risk & Governance Lead, you will help establish and mature WPP’s Enterprise Technology Risk function. Reporting to the Director of Technology Risk & CRC Strategy, you will lead technology risk management and governance initiatives, develop a growing team of risk SMEs, and drive a modern, data-led and automation-first approach to risk management. The successful candidate will work across technology, security, assurance and business teams to ensure risks are identified, assessed, communicated and managed effectively. What you'll be doing: Lead the development and maturity of WPP’s technology risk management framework and processes. Facilitate risk assessments, scenario analysis and risk-based decision making across Enterprise Technology. Maintain technology risk registers, issue management processes and remediation tracking. Produce high-quality management reporting, dashboards and risk insights for senior stakeholders. Drive continuous improvement through automation, workflow optimisation, analytics and agentic AI. Partner with Enterprise Securit

airecruitment
View job →
W
WPP
📍 Chennai• Full-time
15 days ago

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Technology Risk & Governance Lead will help establish and mature WPP’s Enterprise Technology Risk function. Reporting to the Director of Technology Risk & CRC Strategy, the role will lead technology risk management and governance initiatives, develop a growing team of risk SMEs, and drive a modern, data-led and automation-first approach to risk management. The successful candidate will work across technology, security, assurance and business teams to ensure risks are identified, assessed, communicated and managed effectively. What you'll be doing: • Lead the development and maturity of WPP’s technology risk management framework and processes. • Facilitate risk assessments, scenario analysis and risk-based decision making across Enterprise Technology. • Maintain technology risk registers, issue management processes and remediation tracking. • Produce high-quality management reporting, dashboards and risk insights for senior stakeholders. • Drive continuous improvement through automation, workflow optimisation

aigorust
View job →

Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. Join Micron as a Senior Manager, Logistics Security Program, where you will have the outstanding opportunity to lead a world-class global security initiative! This role is critical in ensuring the flawless implementation of our logistics security strategy, encouraging collaboration with key partners, and advancing our program to new heights. Responsibilities: Direct Micron’s worldwide logistics security initiative for valuable shipments, establishing strategy, governance, standards, controls, and performance expectations throughout the transportation network. Lead and expand a distributed team of logistics security experts while promoting uniform performance across Asia Pacific, the Americas, Europe, and other priority regions. Maintain a risk-based shipment security framework that assesses lane, geography, modality, theft history, business impact, recovery capability, and other key risk factors. Establish and enforce logistics provider security requirements, including cargo tracking, route compliance, geofencing, chain of custody, tamper detection, monitoring, blocking issue, and recovery protocols. Partner multi-functionally with Procurement, Logistics, Global Security, Legal, Risk, Finance, and business collaborators to integrate security requirements into contracts, procedures, governance, and scorecards. Coordinate logistics security vendors and providers, including selection, performance management, service levels, monitoring operations, recovery capabilities, and corrective ac

aifinancesupply chain
View job →
S
15 days ago

Senior Compliance Specialist Position Description SingleStore is building a real-time data platform that helps organizations transact, analyze and act on data in a single system. We are committed to operating with strong security, privacy and resilience standards across our products, services and internal operations. We are seeking an experienced and highly motivated Senior Compliance Specialist to help scale our security, privacy and compliance programs. This role will be responsible for maintaining key certifications, driving cross-functional compliance initiatives, overseeing development and management of our privacy program, supporting compliance with the Digital Operational Resilience Act (DORA), and helping mature our Business Continuity Management System (BCMS). The ideal candidate is practical, organized and collaborative, with experience translating regulatory and framework requirements into durable operational processes across technical and business teams. Job Responsibilities Support governance activities across the security, privacy and compliance program, including maintaining Information Security Management System documentation, evidence, policies, procedures and audit trails. Help maintain and improve active certifications and attestations such as ISO/IEC 27001, SOC 2 Type II, HIPAA and PCI DSS, while coordinating with stakeholders across the business to ensure ongoing compliance. Drive readiness efforts for new compliance objectives, certifications and customer-driven assurance requirements. Participate in enterprise risk management activities, including risk methodology, risk assessments, treatment planning and follow-up with risk owners. Oversee the development, implementation and ongoing management of SingleStore’s privacy program in partnership with Legal, Security, IT and business stakeholders. Support compliance with applicable privacy and data protection requirements, including operationalizing controls and processes needed to meet regu

sqlgitai
View job →
T
Twilio
📍 - US• Full-time• Remote• $117K – $146.2K/yr
1mo ago

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Senior Program Manager, Disaster Recovery. About the job This position is needed to lead the disaster recovery (DR) program. This leader is responsible for communicating, developing, implementing, maintaining and managing the governance of the enterprise disaster recovery management (DRM) program. The objective of this program is to support product and IT systems' resilience and timely recovery, regardless of cause. Responsibilities In this role, you’ll: Lead the annual plan development, review, and executive sign-off lifecycle for critical product and non-product systems Actively integrate disaster recovery vulnerabilities, Service Readiness Framework (SRF) findings, and exercise gaps into existing risk frameworks to quantify, score, and systematically drive down operational risk across the company. Author clear program updates, annual compliance metrics, and formal responses to internal and external audit finding

REMOTEawsrestai
View job →

The BU CISO is a senior leadership role responsible for overseeing the cybersecurity posture, strategy, and risk management within a specific business unit (BU) of the organization. This role will ensure that cybersecurity initiatives are aligned with the strategic goals of the business unit, while maintaining overall compliance with corporate security standards, policies, and regulatory requirements. The BU CISO will work closely with business unit leaders, IT, legal, and compliance teams to create and implement robust cybersecurity frameworks, address emerging risks, and safeguard the organization’s critical assets. Source: Adani Group | Job ID: 56131

Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle. As a Senior Staff Analyst, you’ll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need — their regulatory environment, their audit calendar, their risk appetite, their control expectations — well enough to have the evidence ready before the request arrives. You’ll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful. This is deliberately a hands-on senior individual contributor role. You’ll spend your time in audits, in customer conversations, and in the detail of controls and evidence — not in a management chain. If you’ve got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own. Here’s a breakdown of what you’ll do (not all of it, just the important stuff): Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams. Lead customer security audits and assessments hands-on — scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners. Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about. Anticipate requirements before they’re raised, tracking regulatory change, industry expectations and each account’s compliance calendar so documentation and evidence are staged in advance. Act

reactawsgit
View job →
C
15 days ago

POSITION SUMMARY The Consultant is responsible for supporting the Consulting Services Team in delivering cybersecurity, privacy, and compliance services across a diverse portfolio of client engagements. This role operates as a flexible, deployable resource, contributing to multiple concurrent or sequential engagements based on business needs. This role requires proactive initiative to study, ask questions, and rapidly learn the organization’s solutions, methodologies, and delivery standards. Consultants must be comfortable transitioning between engagements, adapting quickly to new client environments, and delivering value immediately. Consultants focus on executing client deliverables, enhancing service quality, and improving project efficiency under the guidance of senior team members. They are expected to develop broad subject matter expertise, contribute to process improvements, and build trusted relationships across a variety of clients and internal teams. SPECIFIC JOB RESPONSIBILITIES Serve as a deployable consulting resource, supporting multiple client engagements across varying industries, with a focus on healthcare. Adapt quickly to new client environments, priorities, and team structures while maintaining high-quality delivery. Support the execution of cybersecurity and compliance consulting engagements under senior leadership guidance. Work closely with clients to collect data, conduct risk assessments, gap analyses, and document findings. Assist in evaluating client security postures, including vulnerability management, compliance alignment, and risk exposure. Develop and contribute to recommendations aligned with industry frameworks such as NIST, ISO 27001, CIS Controls, and HIPAA. Support clients in designing and implementing security controls, policies, and procedures.

airustexcel
View job →
T
Twilio
📍 - Canada• Full-time• Remote• $99.8K – $124.7K/yr
1mo ago

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work , and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. . Hiring and how we work We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings. . See yourself at Twilio Join the team as Twilio’s next Security Risk Senior Analyst. About the job The Senior Security Risk Analyst will be a key member of the One Twilio Risk Management program, focused on maturing our Security risk posture by facilitating risk identification and treatment. The team works closely with our Product and Engineering teams to ensure all areas of cyber risk are identified across Twilio and that risk methodologies are operationally effective and in compliance with regulations (e.g. Cybersecurity and/or Telecom / sector-specific regulations) and industry best practice security measures (e.g. NIST RMF, AI RMF, COSO, ISO 31000). This role provides an exciting opportunity for experienced risk professionals who are passionate about risk management and ready to contribute to the continued growth and maturity of risk practices within a dynamic organization like Twilio. Responsibilities In this role, you’ll: Execute and improve upon daily operations

REMOTErestai
View job →
R
Roblox
📍 San Mateo• Full-time• From $209.3K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr

awsgitai
View job →
L
26 days ago

At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive. Lyft connects people to transportation to change the way we live and get around our communities. Our drivers and passengers entrust Lyft with their personal information and travel details to get where they are going and expect us to keep that data safe. Lyft's Privacy and Compliance team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer obligations We conduct security risk assessments, consult with organizational stakeholders, monitor and continuously improve Lyft's Information Security program, facilitate third-party security audits, work with engineering teams to implement, automate, and monitor security controls, develop policies, and advise on all matters related to information security assurance. We also conduct risk assessments of our third parties to ensure we understand and can mitigate any associated risk. We are looking for a highly motivated, organized, and detail-oriented individual to join our Privacy and Compliance team. As a senior member of this team, you will support our third party risk management program by conducting risk assessments and recommending mitigations. You will also help our Customer Trust team by completing inbound security and data protection questionnaires from potential partners and customers. Responsibilities: Third Party Risk Assessments Review vendor or partner requests from internal stakeholders, understanding the business purpose Work with external stakeholders to collect relevant security and data protection information from third parties Review the information and accurately assess and document the risk, and propose potential mitigations Security Questionnaires Draft responses to customer security questionnaires (e.g., CAIQ, SIG) and assist in the ma

restmicroservicesai
View job →
🔔

Get new senior security risk management framework engineer jobs by email

Daily job updates · Unsubscribe anytime