Senior IRM Analyst

· Remote

Location

Remote

Type

Full Time

Job Description

MongoDBJobs
Senior IRM Analyst

Senior IRM Analyst

Reposted 12 Hours Ago
Easy Apply
Be an Early Applicant
Hiring Remotely in United States
Remote or Hybrid
95K-187K Annually
Senior level
Big Data • Cloud • Software • Database
MongoDB empowers innovators to create transform and disrupt industries by unleashing the power of software and data.
The Role
The Senior IRM Analyst leads risk assessment methodology implementation conducts enterprise-level security assessments and ensures compliance with global regulations. They manage the risk assessment process and synthesize findings into risk reports collaborating with stakeholders across the organization.
Summary Generated by Built In

The Information Security Risk Team at MongoDB is the operational engine of the internal and third-party risk programs. Situated within the Assurance Risk and Compliance (ARC) organization the team is responsible for the "Reduction of Uncertainty" across the enterprise. We view this team as the "Operational Commander" of the risk function. The team oversees the entire lifecycle of risk identification assessment and treatment ensuring that MongoDB’s leadership has a clear quantified view of the top risks facing the organization. We are not just a compliance function; we are a "Risk Intelligence" unit that empowers the business to "Think Big" while keeping our eyes wide open to the risks we accept.

As the Senior Information Risk Analyst you will serve as the subject matter expert and primary executor of our risk function. Reporting directly to the Risk Director you will be responsible for conducting and owning the lifecycle of internal security assessments (annual + ad-hoc) applying risk methodology producing risk memos and working with asset/risk owners across the business that powers MongoDB’s growth. This is a pivotal moment for our Risk function as we scale operations to meet the demands of a $100B+ database market while navigating an increasingly rigorous regulatory landscape (DORA FedRAMP NIS2).

This role can be based remotely in the United States.

Responsibilities

Program Maturity

  • Risk Assessment Methodology Implementation: Lead the strategic roadmap to integrate the risk matrix into the risk framework
  • Regulatory Governance: Ensure the risk program complies with global regulations specifically DORA (EU) regarding ICT registers and FedRAMP Rev 5 supply chain controls. Maintain the Supply Chain Risk Management (SCRM) plan and oversee strict boundary protections for the "Atlas for Government" environment
  • Policy & Procedure Ownership: Maintain the Information Risk Management Procedure (ISQMS) ensuring that risk identification assessment and treatment processes are documented updated annually and followed consistently across the organization

Operational Execution

  • Experience conducting technical security risk assessments (infrastructure cloud application-level). Including experience in evaluating control effectiveness through technical evidence (configurations logs architecture diagrams)
  • Workflow Orchestration: Own the end-to-end risk assessment process
  • Inherent Risk Scoring: Validate the team’s application of the Risk Scoring formula.   Apply the risk scoring formula for baseline scores based on breach history (last 12 months) and weighted impact
  • Ensure the risk acceptance process has the right level of information and the appropriate stakeholders
  • Ticket Hygiene: Actively manage the Jira backlog to prevent "frozen tickets”

Monitoring and Reporting

  • Conduct annual enterprise security risk assessments and ad-hoc assessments as triggered by material changes incidents or new initiatives
  • Identify risk scenarios for the in-scope assets by working with the asset and risk owners
  • Assess the inherent risk and residual risk based on established risk assessment methodology and control assessments
  • Synthesize the analysis into high-quality Risk Assessment Memos. These documents must tell a cohesive story moving from the "Risk Statement" to the "Calculation Logic" to the final "Risk Rating"
  • Manage the risk acceptance process in JIRA review for appropriateness and accuracy
  • Maintain the Risk Management Dashboard and report on accurate risk metrics
Requirements
  • Professional Experience: 10+ years of experience in Information Security Governance Risk & Compliance (GRC)
  • Hands-on experience conducting enterprise-level security risk assessments end-to-end including scoping threat modeling control evaluation and executive reporting
  • Evaluate control effectiveness using technical evidence (configs logs architecture diagrams)
  • Perform threat modeling using established methodologies (STRIDE MITRE ATT&CK)
  • Deep operational understanding of risk assessment methodologies (NIST SP 800-30) and standard control frameworks (NIST CSF NIST SP 800-53 ISO 27001 SOC 2 SIG Core/Lite CAIQ)
  • Regulatory Knowledge: Comprehensive knowledge of DORA NIS2 FedRAMP Rev 5 (specifically Supply Chain/SCRM) GDPR and PCI-DSS requirements
  • Ability to write executive-level risk reports that translate technical flaws into business risks
  • A strong track record of collaborating effectively across teams and levels to influence change
  • Education: Bachelor’s degree in a relevant field (Cybersecurity Business Information Systems)
  • Certifications: CRISC CCSP CISSP CISA relevant cloud certifications

About MongoDB

MongoDB is built for change empowering our customers and our people to innovate at the speed of the market. We have redefined the database for the AI era enabling innovators to create transform and disrupt industries with software. MongoDB’s unified database platform the most widely available globally distributed database on the market helps organizations modernize legacy workloads embrace innovation and unleash AI. Our cloud-native platform MongoDB Atlas is the only globally distributed multi-cloud database and is available across AWS Google Cloud and Microsoft Azure.

With offices worldwide and over 60000 customers including 75% of the Fortune 100 and AI-native startups relying on MongoDB for their most important applications we’re powering the next era of software.

Our compass at MongoDB is our Leadership Commitment guiding how and why we make decisions show up for each other and win. It’s what makes us MongoDB. 

To drive the personal growth and business impact of our employees we’re committed to developing a supportive and enriching culture for everyone. From employee affinity groups to fertility assistance and a generous parental leave policy we value our employees’ wellbeing and want to support them along every step of their professional and personal journeys. Learn more about what it’s like to work at MongoDB and help us make an impact on the world!

MongoDB is committed to providing any necessary accommodations for individuals with disabilities within our application and interview process. To request an accommodation due to a disability please inform your recruiter.

MongoDB Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type and makes all hiring decisions without regard to race color religion age sex national origin disability status genetics protected veteran status sexual orientation gender identity or expression or any other characteristic protected by federal state or local laws.

Req ID: 1273387742

MongoDB’s base salary range for this role is posted below. Compensation at the time of offer is unique to each candidate and based on a variety of factors such as skill set experience qualifications and work location. Salary is one part of MongoDB’s total compensation and benefits package. Other benefits for eligible employees may include: equity participation in the employee stock purchase program flexible paid time off 20 weeks fully-paid gender-neutral parental leave fertility and adoption assistance 401(k) plan mental health counseling access to transgender-inclusive health insurance coverage and health benefits offerings. Please note the base salary range listed below and the benefits in this paragraph are only applicable to U.S.-based candidates.

MongoDB’s base salary range for this role in the U.S. is:
$95000$187000 USD

Skills Required

  • 10+ years of experience in Information Security Governance Risk & Compliance (GRC)
  • Hands-on experience conducting enterprise-level security risk assessments end-to-end
  • Deep operational understanding of risk assessment methodologies and standard control frameworks
  • Comprehensive knowledge of DORA NIS2 FedRAMP Rev 5 GDPR and PCI-DSS requirements
  • Ability to write executive-level risk reports
  • Education: Bachelor's degree in a relevant field
  • Certifications: CRISC CCSP CISSP CISA

What the Team is Saying

Sunsharay
Sachin
Bianca
Garaudy
Erica
Ava
May

MongoDB Compensation & Benefits Highlights

  • Parental & Family SupportParental leave is substantial and fully paid for new parents with additional paid flexibility to ease the return to work. Family‑building support reimburses eligible fertility adoption and surrogacy expenses up to a lifetime maximum in the U.S.
  • Healthcare StrengthHealth coverage includes multiple medical dental and vision options plus a One Medical membership for employees and dependents. Coverage extends to inclusive services such as gender‑affirmation care and dedicated menopause/low‑testosterone support alongside mental‑health resources.
  • Leave & Time Off BreadthFlexible PTO and observed company holidays provide meaningful time away from work. Return‑to‑work flexibility following parental leave further broadens overall time‑off support.

MongoDB Insights

Am I A Good Fit?
beta
Expert contributor network
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York NY
5550 Employees
Year Founded: 2008

What We Do

The database market is big. How big? Well according to IDC it’ll reach $153 billion by 2027. And MongoDB is at the forefront of that innovation with thousands of customers across the globe. We empower developers and businesses to build and deploy the applications they want wherever they want.

Why Work With Us

We are ambitious. We are passionate about creativity. And we believe the best paths are the ones we have yet to forge.

Gallery

MongoDB Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

MongoDB provides multiple working model options for our employees including the flexibility to work from home to opportunities for collaboration and social interaction in a MongoDB office.

Typical time on-site: Flexible
HQNew York NY
Company Office Image
Sydney Aus
Austin TX
Company Office Image
Barcelona Catalonia
Company Office Image
Ciudad de México Ciudad de México
Gurugram Haryana
Company Office Image
Hanyang KR
Company Office Image
London GB
Company Office Image
Milano IT
Company Office Image
Palo Alto CA
Paris FA
San Francisco CA
São Paulo BR
Company Office Image
Singapore
Learn more

Similar Jobs

MongoDB

Contract Sourcer Talent Discovery

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
85K-85K Annually

MongoDB

Cloud Operations Engineer (3rd Shift Weekend)

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
90K-176K Annually

MongoDB

Senior Site Reliability Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
9 Locations
5550 Employees
127K-249K Annually

MongoDB

Staff Software Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
151K-297K Annually
Apply Now

Date Posted

06/04/2026

Views

0

Back to Job Listings Add To Job List Company Profile View Company Reviews
Neutral
Subjectivity Score: 0
142,000+ Jobs Tracked
12,400+ Companies
1,930 Categories