FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

GRC Technical Program Manager
NetApp. Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications .
Posted 9/25/2026full-timeMorrisville • North Carolina • United StatesMid-LevelSenior💰 $129,200 - $192,500 per yearWebsite
Tech Stack
Tools & technologiesAWSAzureCloudKubernetes
About the role
Key responsibilities & impact- Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications
- Perform technical gap and risk assessments across infrastructure, applications, and cloud engineering processes
- Monitor controls and advise owners on remediation
- Translate regulatory and compliance controls into clear, measurable engineering and security requirements
- Identify manual compliance activities for automation
- Partner with engineering and security teams on automated detection, remediation, evidence collection, and continuous monitoring
- Apply AI and related tooling to improve compliance workflows
- Align Engineering, SRE, Product, Cloud Security, Legal, Privacy, and Corporate Security teams and drive cross-functional initiatives to completion
- Partner with Microsoft Azure, Google Cloud, and Amazon Web Services on shared compliance and security objectives
- Manage auditor and assessor relationships
- Present the organization’s technical security posture to leaders, auditors, and hyperscaler partners
- Improve policies, processes, security governance, and adoption of GRC tooling
Requirements
What you’ll need- 6+ years building and managing security risk and compliance programs, including ownership of large cross-functional programs through certification
- Deep knowledge of ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP
- Ability to convert controls into engineering requirements
- Direct experience partnering with engineering teams to deliver technical outcomes
- Exceptional stakeholder management and ability to influence senior stakeholders and external partners without direct authority
- Strong technical fluency in AWS and Azure, Kubernetes, containers, virtual machines, identity and access control, network security, cryptography, logging and monitoring, incident response, DevOps, and CI/CD
- Familiarity with cloud security capabilities, SIEM, vulnerability scanning, cloud security posture management, and endpoint detection and response
- Product-oriented problem solving, including investigating gaps, gathering requirements, and driving solutions to completion
- Bachelor’s or Master’s degree in Engineering, Computer Science, Information Technology, or a related field, or equivalent professional experience
- Professional certifications are advantageous, including CISA, CISSP, CRISC, CCSK, CCSP, CIPP, AWS certifications, or ISO 27001 Lead Implementer / Lead Auditor
Benefits
Comp & perks- Health Insurance
- Life Insurance
- Retirement or Pension Plans
- Paid Time Off
- Various Leave options
- Employee stock purchase plan
- Restricted stocks (RSU’s)
- Comprehensive benefits package