Salary
💰 $211,000 - $315,000 per year
Tech Stack
AWSAzureCloudGoogle Cloud Platform
About the role
- Lead strategy, execution, and maintenance of commercial security certifications (e.g., ISO 27001, SOC 2 Type 2, PCI DSS) and manage the entire certification lifecycle
- Lead Public Sector team to drive acquisition and maintenance of public sector certifications and authorizations (e.g., FedRAMP, CMMC, DoD SRG)
- Define and help execute a regulator-influencer strategy; engage with regulatory bodies, industry working groups, and standards organizations
- Oversee all statutory security audits, coordinating with internal teams and external auditors, including financial and privacy audits
- Build and maintain relationships with external audit firms; manage and optimize audit engagements and global delivery models
- Co-develop, champion, implement and drive automation and AI strategies to streamline audit processes and reduce audit fatigue
- Establish and drive certification and audit operations metrics; provide executive-level reporting and risk remediation
- Lead, mentor, and grow a team of security professionals focused on certifications, audit, and compliance
- Enable new markets and workloads and foster and maintain trust with Snowflake's global customer base
- Report directly to the Senior Director of Security Trust
Requirements
- 10+ years of experience in security governance, risk, and compliance (GRC) with a strong focus on security certifications and audit management
- Proven track record of leading organizations through complex security certifications, compliance, and security governance (e.g., FedRAMP, ISO 27001, SOC 2, PCI DSS)
- Deep understanding of commercial and public sector security compliance frameworks and requirements
- Experience engaging with and influencing regulatory bodies
- Strong knowledge of audit methodologies and experience managing external audit relationships
- Strong understanding of leveraging data and automation to deliver high efficiency and quality audits
- Demonstrated ability to build, lead, and develop high-performing teams
- Exceptional communication, interpersonal, collaboration, and presentation skills
- Ability to thrive in a fast-paced, dynamic, and rapidly growing environment
- Bachelor's degree in Computer Science, Information Security, or a related field; Master's degree preferred
- Relevant industry certifications such as CISM, CISA, CISSP, or equivalent are highly desirable
- Experience with cloud security platforms and architectures (AWS, Azure, GCP)
- Strong program management skills, with experience managing complex, cross-functional security initiatives
- Public speaking, publications or presentations on security certifications, audit, or compliance topics
- Demonstrated experience utilizing Snowflake (or similar analytics and data platforms / tools) for data analysis, reporting, and dashboarding related to security compliance and audit metrics
- Familiarity with data privacy regulations such as GDPR, CCPA, etc.