Job Description
Protecting Dropbox and our users is critical to being worthy of trust. As a Governance, Risk & Compliance Manager at Dropbox, you will join a growing team to design, implement, and coordinate programs to promote user trust and manage risks to their data. You will work with teams across the organization, from Engineering, Product, & Infrastructure, to Sales to Customer Experience, in order to manage risks to Dropbox and users alike. You will work in depth with other parts of the business to ensure Dropbox meets our security, privacy, and regulatory commitments.
If you are passionate about protecting Dropbox and our users, are looking for an opportunity to stretch and grow yourself in a dynamic team, and thrive in an environment where you can constantly learn, then this role is for you.
Responsibilities- Promote and foster a culture of trust at Dropbox
- Design, implement, maintain, and improve programs to address key company risks and prepare internal teams for independent assessments against a wide variety of regulatory and compliance frameworks (ISO 27001, ISO 27017, ISO 27018, ISO 22301, ISO 27701, HIPAA)
- Solve a broad range of large, complex, cross-functional challenges such as SOC compliance, PCI compliance, ISMAP compliance, and/or SOX compliance
- Improve controls for internal systems, processes, and policies
- Facilitate ongoing risk and compliance initiatives and monitor control effectiveness
- Collaborate with internal teams and external auditors throughout compliance assessments
- Drive automation efforts across the Compliance function via SNOW tool
- Identify opportunities impacting the Compliance function and establish the strategy and cross-functional alignment to achieve these objectives
- Conduct gap assessments to identify areas of non-compliance or areas for improvement, and develop action plans to address these gaps
- Provide guidance to management on the impact of new laws and regulations and recommend changes in business practices where necessary
- 4+ years of experience building or maintaining programs to mitigate risks around security, confidentiality, integrity, availability, and privacy
- Experience facilitating or being the subject of SOC, ISO, HIPAA and/or FedRAMP audits at a fast-paced technology company, public accounting firm, or similar environment
- Experience partnering with Engineering, Product, & Development teams to define compliance needs in a multi-product environment
- Strong familiarity with a broad range of technical concepts relevant to cloud computing environments: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy
- Experience with implementing compliance programs for emerging new solutions
- Strong understanding of cloud-based technologies and their implications for governance, risk, and compliance
- Strong project management and organizational skills - must drive your own projects to completion, while also fostering collaboration and bringing teams together to achieve common objectives
- Great people skills and ability to work well in fast paced team environment with a wide range of technical and non-technical teams
- Excellent writing, communication, and organizational skills - strong attention to detail
- Passion to aim higher and develop new skills
- CISA, CISSP, CCSK, CIPP, or other professional certifications/associations a plus
Date Posted
06/08/2023
Views
4
Similar Jobs
Senior Design Manager (Infrastructure) - Canonical
Views in the last 30 days - 0
Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...
View DetailsProduct Manager Wallet SDKs - Startale
Views in the last 30 days - 0
The text describes a job alert system where applicants must mention UNSELFISH and use a specific tag to demonstrate they read the post It explains the...
View DetailsSenior Product Designer - Org & Security - Typeform
Views in the last 30 days - 0
This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...
View DetailsExecutive Director Patient Advocacy - Kyverna Therapeutics
Views in the last 30 days - 0
Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...
View DetailsMedical Affairs Writer Contract - Kyverna Therapeutics
Views in the last 30 days - 0
Kyverna Therapeutics seeks a Medical Affairs Writer to develop scientific publications and communications for cell therapy innovations The role requir...
View DetailsRecovery Analyst Underpayments - Trend Health Partners
Views in the last 30 days - 0
TREND Health Partners seeks an Underpayment Recovery Analyst to optimize client reimbursement through collaboration and detailed claim analysis The ro...
View Details