We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program — ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust. About the Role You will own Plaid’s Security Contracts workstream end-to-end—the DRI for how security contract reviews get done, how fast they move, and how the program improves over time. You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they n
Jobs in United States
Information Security Governance in United States
15 active opportunities · Updated September 2026
Showing
15 jobs
Explore current information security governance jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role: You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary The Executive Director - Business Information Security Officer (BISO) will serve as a senior leader and trusted security advisor supporting all CVS Health lines of business, with accountability for leading the BISO team and driving mission, vision, and governance model. This individual will provide senior‑level leadership, strategic and tactical guidance for a world‑class enterprise cybersecurity program. As a business enabler, the BISO is an effective communicator with the technical aptitude to embed security strategy and risk‑based decision‑making into all aspects of the business. The BISO understands security risks, threats, vulnerabilities, control frameworks, and security technologies and translates their impact in business terms. The BISO must be capable of working closely with senior IT business leaders, executive leadership, and business subject matter experts (SMEs). This role requires demonstrated leadership, exceptional organizational skills, strong business and financial acumen, and the ability to influence and drive change at scale across the organization. <
From $209.3K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr
From $233.6K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior Manager of Infrastructure Security. You will help shape the future of Platform Security at Roblox. We work closely with Production IAM, Network Security, and Cloud Security at Roblox. You Will: Identify security gaps and threats in our cloud and on premise infrastructure, partnering with Governance Risk and Compliance teams to create standards and policies along the way. This will help Roblox meet regulatory and compliance requirements. Harden our infrastructure by introducing secure by default configurations, designs and guardrails for all developers at Roblox. Own and drive solutions that enable Roblox engineers to design, build, and use infrastructure securely at scale. Work closely with other InfoSec teams (AppSec, D&R, GRC, CorpSec, CloudSec, NetSec) and partner with engineering teams across Roblox, specifically the Infrastructure organization, to ensure the secure outcomes of security and product driven initiatives. You Have: 5+ years of experience writing code and/or relevant technical experience. Experience with
From $243.3K/yr
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Enterprise Security Engineer, you will play a critical role in executing Roblox’s Enterprise Security Strategy. You will design, deploy, and manage security solutions to protect Roblox’s corporate infrastructure and ensure secure, compliant operations across the organization. Working closely with Corporate Engineering and Trust & Safety teams, you will translate business requirements into robust security implementations that enable secure productivity while mitigating risk. You will be reporting directly to the Senior Manager of Enterprise Security Engineering. You'll partner with security professionals across the Information Security organization, and work cross-functionally with teams throughout Roblox to drive security initiatives that scale with our business. You will: Evaluate and implement security technologies and vendor solutions to ensure alignment with enterprise security requirements, compliance standards, and overall risk management strategy Lead and drive initiatives across core security domains, including Endpoint Security, SaaS Security, Identity & Access Management (IAM), Agentic AI Governance, and Supply Chain Security. Collaborate closely with IT, engin
About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure, protecting sensitive data, and meeting global compliance standards are essential to our success and societal impact. Security at OpenAI is a cross-cutting function that spans infrastructure, applied engineering, legal, policy, and product. Technical Program Managers (TPMs) play a critical leadership role in aligning teams and delivering execution at scale and this role will be foundational in shaping how we secure OpenAI’s systems, users, and commitments. About the Role We’re seeking a Senior Technical Program Manager to drive cross-functional security, privacy, IT and compliance initiatives at the intersection of infrastructure, product, and policy. You will execute complex programs that reduce internal data access, prevent misuse, and ship security capabilities. You will focus your efforts on the most critical initiatives within Security, crossing the spectrum of insider threat, information security, physical security, and information technology challenges. This role is deeply technical and execution-focused. It requires a structured operator who thrives in ambiguity, partners effectively across boundaries, and applies principled judgment to scale trust, governance, and security across OpenAI’s systems and products. In this role, you will: Drive execution of critical security and compliance programs such as vulnerability management, merger and acquisition security and integration, infrastructure hardening, and datacenter security management. You will need to deeply collaborate on technical architecture and resolve technical problems in partnership with engineering. Partner with IT, Infrastructure, Application, Legal, Privacy, and Security teams to build scalable programs, and deliver critical security outcomes across multiple disciplines, including insider threat, information
Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat
From $210K/yr
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: As Drata scales, we want our security and GRC leadership to be able to meet our customers’ needs in more places at once—in strategic customer conversations, on stage at industry events, and in the broader conversations happening across our security and GRC communities. We’re looking for a Field Chief Information Security Officer to join Drata’s Security & GRC organization, repo
About the Team OpenAI’s Governance team helps shape how the company responsibly develops and deploys increasingly capable AI. We bring together technical evidence, policy, and operational perspectives to help the company address emerging risks, resolve difficult questions, and make well-supported decisions. Our work includes shaping and improving governance practices, supporting effective oversight, developing clear assessments and recommendations, and ensuring that decisions lead to action. We work closely with research, safety, security, legal, and product teams to identify gaps, reconcile different views, and improve our approach as capabilities and circumstances change. About the Role We are looking for a curious, high-agency Research Program Manager who can reason from first principles, make sense of incomplete or conflicting information, and move difficult work forward. You will help shape the substance of governance reviews, connect ideas and evidence across teams, and develop recommendations that are both well-founded and practical. The work requires someone who can use established approaches where they fit, recognize when circumstances call for a different approach, and update their thinking as new evidence emerges. You should bring sound judgment, a willingness to experiment and learn, and the program-management discipline to turn good analysis into action. Depending on your experience and the team’s needs, your work may focus on safety advisory and board-level oversight, deployment governance, or standards and strategic partner commitments. In this role, you will: Bring together technical, policy, and operational inputs to develop coherent assessments, recommendations, and decision materials for governance bodies and senior leaders. Work through emerging or ambiguous questions, test assumptions, identify gaps or conflicting evidence, and help determine what additional analysis or decisions are needed. Engage critically with research, evaluations, safeguar
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Secure Manufacturing & Stealth (SMS) team protects OpenAI’s most sensitive product, manufacturing, launch, and partnership work from theft, leakage, espionage, and unauthorized disclosure. We operate across physical, digital, human, and third-party domains, building practical protections that allow teams to move quickly while preserving strict need-to-know controls. About the Role We are seeking a senior Secure Manufacturing & Stealth Partner to serve as the dedicated SMS owner for Marketing. This person will build trusted relationships across Marketing, understand launches and sensitive information flows, identify secrecy risks early, and embed practical controls into planning, creative production, events, agencies, vendors, media, and executive communications. The role owns the Marketing relationship while coordinating shared SMS capabilities when investigative, prototype-handling, regional, or other specialist support is needed. In this role you will: Serve as the primary SMS Partner and trusted adviser to Marketing, building a deep understanding of its priorities, planning cycles, launches, events, external partners, and sensitive information flows. Identify secrecy and information-exposure risks early, then translate SMS requirements into practical controls that protect sensitive work without unnecessarily slowing execution. Build, document, and socialize durable operating mechanisms for compartmentalization, need-to-know access, agencies and vendors, sensitive creative production, events, demonstrations, launch preparation, codenames, watermarking, and password controls. Assess and approve Marketing systems and information workflows, identify gaps or duplication, establish secure handling requirements, and advise AI-native Marketing initiatives on permissions, data governance, and operational tracking. Coordinate
Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. We are part of Micron Technology’s Enterprise Infrastructure & Security (EIS) organization, where we build and run the platforms that power Micron’s global business. Within EIS, the PMO drives how complex technology initiatives come to life; raising delivery standards, strengthening execution, and enabling transformation at scale. We work across regions and subject areas, and we are deeply invested in modern delivery and AI-enabled ways of working. This IT Project Manager role is a critical addition to the EIS PMO. You will lead high-impact initiatives that support AI transformation, operational excellence, and a future ready workforce. This role brings experienced leadership, structure, and critical thinking to complex programs, while also uplifting delivery capability across the PMO through example and mentorship. Responsibilities: Lead complex Infrastructure and Security projects through initiation, planning, execution, and closeout, ensuring projects are delivered on time, within scope, and within budget, with measurable business impact Manage scope, schedule, budget, risks, dependencies, and change with transparency Convert strategic priorities, including AI enablement, into actionable delivery plans Establish governance, execution rigor, and delivery structure across projects Align project delivery with Micron’s strategic roadmap, including AI enablement and operational excellence priorities Mentor PMO team members and
About the Team: We are a small and fast-moving partnerships team that shapes and executes OpenAI’s most important collaborations. Your mission is to identify, structure, and scale partnerships that expand how businesses adopt and benefit from OpenAI. You will work across priority sectors, including legal, professional services, information services, and other B2B categories, while maintaining the flexibility to pursue the highest-impact opportunities as the market evolves. About the Role: You are a senior business development and partnerships leader with strong judgment, high ownership, and a track record of originating and closing complex partnerships. You can move from market strategy and executive engagement through deal development, launch, and growth. You combine strategic thinking, commercial discipline, and hands-on execution, and you can create clarity and momentum across multiple internal and external stakeholders. Key Responsibilities: Develop a portfolio strategy for high-impact B2B partnerships. Identify and prioritize partners based on customer reach, differentiated data or workflows, distribution, strategic value, and growth potential. Originate, structure, negotiate, and launch complex product and commercial partnerships. Build joint value propositions and business plans spanning integration, distribution, go-to-market, and customer adoption. Lead executive relationships and establish durable cross-functional partnership governance. Coordinate product, engineering, sales, marketing, legal, finance, security, policy, and operations to deliver partnership outcomes. Translate partner and market insight into product strategy and new partnership models. Track adoption, pipeline, revenue impact, strategic milestones, and partner performance, and communicate progress and risks clearly. Qualifications: 10+ years of experience in strategic partnerships, business development, enterprise technology, or platform ecosystems. Proven experience personally originatin
The NVIDIA DGXC Data Services team builds cloud-native systems, frameworks, and services for managing data across hybrid and multi-cloud infrastructure. We are building the next-generation data and storage infrastructure to solve some of the hardest problems in AI: storage, access, ingestion, governance, observability, and data management for exabyte-scale, high-performance GPU-based training and inference jobs. Our work gives NVIDIA teams the foundational capabilities they need to build, train, deploy, and operate AI products at scale without reinventing critical data infrastructure for every workload. What you will be doing: Build cloud-native data and storage services for hybrid and multi-cloud infrastructure, including dataset discovery, ingestion, governance, checkpointing, observability, and low-latency access. Develop scalable cloud-native services and APIs that support exabyte-scale, high-performance GPU training and inference workflows. Work closely with product managers, internal AI teams, platform teams, and partner engineering teams to understand requirements and turn them into reliable production systems. Collaborate with SRE, operations, and support teams to improve service reliability, performance, observability, on-call readiness, and operational scale. Use modern software engineering practices, including AI-assisted and agentic development workflows, while maintaining high standards for design, testing, security, and verification. What we need to see: BS in Computer Science, Information Systems, Computer Engineering, or equivalent experience, with 5+ years of software engineering experience. Strong foundation in algorithms, data structures, distributed systems, and practi
Other cities to consider
More places hiring for this role
Get new information security governance jobs in United States by email
Daily job updates · Unsubscribe anytime