IRM Analyst

· Remote

Location

Remote

Type

Full Time

Job Description

IRM Analyst

Posted 9 Minutes Ago
Easy Apply
Be an Early Applicant
Hiring Remotely in United States
Remote or Hybrid
96K-165K Annually
Mid level
Big Data • Cloud • Software • Database
MongoDB empowers innovators to create transform and disrupt industries by unleashing the power of software and data.
The Role
The Program Manager executes the internal risk program conducting risk assessments managing requests and enhancing risk visibility through effective communication and detailed reporting.
Summary Generated by Built In

The Information Security Risk Program Manager is the operational engine of the internal risk program. While the Risk Manager and Risk Director define the strategic roadmap the Program Manager ensures the daily execution of that strategy. They are responsible for the "production line" of risk assessment: taking raw signals from the business processing them through the established methodology and outputting actionable risk decisions (Remediation or Acceptance).

The ultimate objective of this role is Reduction of Uncertainty. By managing the program effectively the Program Manager ensures that MongoDB’s leadership has a clear quantified view of the top risks facing the enterprise. They transform the Risk Register from a static spreadsheet into a dynamic governance tool that drives accountability.

The Program Manager must not be afraid to be in the trenches with the Engineering and Product teams. They are the primary face of the "Risk Intake Process" guiding stakeholders through the methodology. They are the gatekeeper of quality ensuring that no risk enters the register until it has been properly scoped and quantified.

This role can be based remotely in the United States.

Responsibilities

Risk Identification & Assessment

  • Execute risk assessments under senior guidance - perform scoping inherent risk scoring control assessment and residual risk calculation using established methodology
  • Conduct risk identification intake manage the flow of requests from Jira Service Desk and the Issue Intake Tracker review incoming submissions against entry criteria assign Risk IDs and replicate validated risks into the Risk Register
  • Act as the Triage Officer for incoming risk submissions determine whether submissions represent strategic risks operational issues or duplicates. Filter noise to focus the team on signals
  • Develop risk scenarios for in-scope assets by working with asset owners and risk owners identify threat communities threat events and impact categories
  • Draft Risk Assessment Memos that tell a cohesive story from risk statement to risk rating to actionable recommendation. Progressively build toward independently authored memos that require minimal review notes
  • Monitor and flag emerging risk signals including AI-related risks (model integrity data poisoning shadow AI third-party AI dependencies) and escalate with documented analysis for integration into the risk framework

Control Identification Mapping & Assessment

  • Identify and document controls that mitigate assessed risks map controls to specific risk scenarios and applicable framework requirements (NIST SP 800-53 ISO 27001 SOC 2)
  • Assess the design adequacy of controls evaluate whether each control is appropriately designed to address the risk it is mapped to and document findings with supporting rationale
  • Assess the operating effectiveness of controls collect and evaluate evidence to determine whether controls are functioning as designed over the assessment period and document results
  • Document control gaps and support remediation tracking maintain clear records of where controls are missing partially effective or require compensating controls. Track remediation progress
  • Maintain control-to-framework mappings to ensure risk assessment outputs directly support audit and certification evidence packages (FedRAMP SOC 2 ISO 27001 PCI-DSS)

Risk Categorization & Governance

  • Apply the established risk taxonomy and categorization methodology consistently across all assessed risks
  • Process risk acceptance requests in Jira validate completeness ensure documented context and stakeholder sign-off confirm time-bound conditions and flag concerns to the Senior lead
  • Maintain the Risk Register risk inventory and supporting trackers with obsessive attention to data integrity no missing dates undefined owners or stale entries. A Risk Register with governance gaps is a program failure

Reporting & Stakeholder Engagement

  • Contribute to KRI data collection and dashboard inputs support accurate timely reporting that feeds executive risk dashboards and governance forum materials
  • Engage directly with technical stakeholders (engineering product infrastructure teams) during risk assessments ask informed questions gather evidence and document findings
  • Progressively build the technical fluency to lead stakeholder conversations independently develop working proficiency in cloud-native architectures SaaS security models and common technical controls (IAM encryption network segmentation logging/monitoring)
  • Translate technical findings into clear business-relevant risk language in all written work products

Policy Process & Governance Hygiene

  • Support drafting and maintaining risk procedures guidelines and assessment templates across the IRM program scope
  • Execute governance hygiene data quality tracker maintenance workflow adherence evidence organization and documentation standards
  • Manage the risk assessment pipeline in Jira create and maintain workflows dashboards and use JQL to track the assessment ticket lifecycle
Requirements
  • 3–5 years of experience in Information Security Governance Risk and Compliance (GRC) or Enterprise Risk Management
  • Experience performing risk assessments — including risk identification inherent/residual risk scoring and documentation of findings
  • Experience identifying documenting and evaluating controls — including assessment of design adequacy and operating effectiveness
  • Strong working knowledge of NIST CSF NIST SP 800-30/39/53 and ISO/IEC 27005 — ability to use these frameworks as a library of controls and risk guidance
  • Advanced proficiency in Excel/Google Sheets (pivot tables VLOOKUP complex formulas) for risk data analysis and reporting
  • Jira proficiency — managing projects creating workflows and dashboards and using JQL
  • Ability to write clear concise and defensible Risk Assessment Memos
  • Obsessive attention to detail regarding data integrity and documentation quality
  • Foundational understanding of cloud-native architectures and common technical controls (IAM encryption logging/monitoring network segmentation) — with a commitment to building deeper technical fluency
  • Awareness of AI risk concepts and willingness to develop expertise in emerging AI risk and regulatory landscape
  • A strong track record of collaborating effectively across teams and levels
  • Bachelor's degree in Cybersecurity Information Systems Business Administration or a related field
  • Certifications: At least one of the following certifications is required - CRISC CISM CISSP or CISA
About MongoDB

MongoDB is built for change empowering our customers and our people to innovate at the speed of the market. We have redefined the database for the AI era enabling innovators to create transform and disrupt industries with software. MongoDB’s unified database platform the most widely available globally distributed database on the market helps organizations modernize legacy workloads embrace innovation and unleash AI. Our cloud-native platform MongoDB Atlas is the only globally distributed multi-cloud database and is available across AWS Google Cloud and Microsoft Azure.

With offices worldwide and over 60000 customers including 75% of the Fortune 100 and AI-native startups relying on MongoDB for their most important applications we’re powering the next era of software.

Our compass at MongoDB is our Leadership Commitment guiding how and why we make decisions show up for each other and win. It’s what makes us MongoDB. 

To drive the personal growth and business impact of our employees we’re committed to developing a supportive and enriching culture for everyone. From employee affinity groups to fertility assistance and a generous parental leave policy we value our employees’ wellbeing and want to support them along every step of their professional and personal journeys. Learn more about what it’s like to work at MongoDB and help us make an impact on the world!

MongoDB is committed to providing any necessary accommodations for individuals with disabilities within our application and interview process. To request an accommodation due to a disability please inform your recruiter.

MongoDB Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type and makes all hiring decisions without regard to race color religion age sex national origin disability status genetics protected veteran status sexual orientation gender identity or expression or any other characteristic protected by federal state or local laws.

Req ID: 1273425625

MongoDB’s base salary range for this role is posted below. Compensation at the time of offer is unique to each candidate and based on a variety of factors such as skill set experience qualifications and work location. Salary is one part of MongoDB’s total compensation and benefits package. Other benefits for eligible employees may include: equity participation in the employee stock purchase program flexible paid time off 20 weeks fully-paid gender-neutral parental leave fertility and adoption assistance 401(k) plan mental health counseling access to transgender-inclusive health insurance coverage and health benefits offerings. Please note the base salary range listed below and the benefits in this paragraph are only applicable to U.S.-based candidates.

MongoDB’s base salary range for this role in the U.S. is:
$96000$165000 USD

What the Team is Saying

Sunsharay
Sachin
Bianca
Garaudy
Erica
Ava
May
Am I A Good Fit?
beta
Expert contributor network
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York NY
5550 Employees
Year Founded: 2008

What We Do

The database market is big. How big? Well according to IDC it’ll reach $153 billion by 2027. And MongoDB is at the forefront of that innovation with thousands of customers across the globe. We empower developers and businesses to build and deploy the applications they want wherever they want.

Why Work With Us

We are ambitious. We are passionate about creativity. And we believe the best paths are the ones we have yet to forge.

Gallery

MongoDB Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

MongoDB provides multiple working model options for our employees including the flexibility to work from home to opportunities for collaboration and social interaction in a MongoDB office.

Typical time on-site: Flexible
HQNew York NY
Company Office Image
Sydney Aus
Austin TX
Company Office Image
Barcelona Catalonia
Company Office Image
Ciudad de México Ciudad de México
Gurugram Haryana
Company Office Image
Hanyang KR
Company Office Image
London GB
Company Office Image
Milano IT
Company Office Image
Palo Alto CA
Paris FA
San Francisco CA
São Paulo BR
Company Office Image
Singapore
Learn more

Similar Jobs

MongoDB

Senior IRM Analyst

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
97K-189K Annually

MongoDB

Principal Analyst GTM Operations

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
8 Locations
5550 Employees
84K-165K Annually

MongoDB

Staff Software Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
2 Locations
5550 Employees
173K-297K Annually

MongoDB

Solutions Architect

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
5 Locations
5550 Employees
104K-204K Annually
Apply Now

Date Posted

05/01/2026

Views

0

Back to Job Listings Add To Job List Company Profile View Company Reviews
Neutral
Subjectivity Score: 0

Similar Jobs

142,000+ Jobs Tracked
12,400+ Companies
1,930 Categories