Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
NetApp

GRC Technical Program Manager

NetApp

. Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications .

Posted 9/25/2026full-timeMorrisville • North Carolina • United StatesMid-LevelSenior💰 $129,200 - $192,500 per yearWebsite

Tech Stack

Tools & technologies
AWSAzureCloudKubernetes

About the role

Key responsibilities & impact
  • Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications
  • Perform technical gap and risk assessments across infrastructure, applications, and cloud engineering processes
  • Monitor controls and advise owners on remediation
  • Translate regulatory and compliance controls into clear, measurable engineering and security requirements
  • Identify manual compliance activities for automation
  • Partner with engineering and security teams on automated detection, remediation, evidence collection, and continuous monitoring
  • Apply AI and related tooling to improve compliance workflows
  • Align Engineering, SRE, Product, Cloud Security, Legal, Privacy, and Corporate Security teams and drive cross-functional initiatives to completion
  • Partner with Microsoft Azure, Google Cloud, and Amazon Web Services on shared compliance and security objectives
  • Manage auditor and assessor relationships
  • Present the organization’s technical security posture to leaders, auditors, and hyperscaler partners
  • Improve policies, processes, security governance, and adoption of GRC tooling

Requirements

What you’ll need
  • 6+ years building and managing security risk and compliance programs, including ownership of large cross-functional programs through certification
  • Deep knowledge of ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP
  • Ability to convert controls into engineering requirements
  • Direct experience partnering with engineering teams to deliver technical outcomes
  • Exceptional stakeholder management and ability to influence senior stakeholders and external partners without direct authority
  • Strong technical fluency in AWS and Azure, Kubernetes, containers, virtual machines, identity and access control, network security, cryptography, logging and monitoring, incident response, DevOps, and CI/CD
  • Familiarity with cloud security capabilities, SIEM, vulnerability scanning, cloud security posture management, and endpoint detection and response
  • Product-oriented problem solving, including investigating gaps, gathering requirements, and driving solutions to completion
  • Bachelor’s or Master’s degree in Engineering, Computer Science, Information Technology, or a related field, or equivalent professional experience
  • Professional certifications are advantageous, including CISA, CISSP, CRISC, CCSK, CCSP, CIPP, AWS certifications, or ISO 27001 Lead Implementer / Lead Auditor

Benefits

Comp & perks
  • Health Insurance
  • Life Insurance
  • Retirement or Pension Plans
  • Paid Time Off
  • Various Leave options
  • Employee stock purchase plan
  • Restricted stocks (RSU’s)
  • Comprehensive benefits package