Jobs and Careers
ED

Staff Security Program Manager (GRC)

EDB
Remote - United States, United StatesRemotefull_timeVerifiedPosted 11 Mar 2025

About the role

A Little About Us

EDB provides a data and AI platform that enables organizations to harness the full power of Postgres for transactional, analytical, and AI workloads across any cloud, anywhere. EDB empowers enterprises to control risk, manage costs and scale efficiently for a data and AI led world. Serving more than 1,500 customers globally and as the leading contributor to the vibrant and fast-growing PostgreSQL community, EDB supports major government organizations, financial services, media and information technology companies. EDB’s data-driven solutions enable customers to modernize legacy systems and break data silos while leveraging enterprise-grade open source technologies. EDB delivers the confidence of up to 99.999% high availability with mission critical capabilities built in such as security, compliance controls, and observability. For more information, visit www.enterprisedb.com

**Candidates note: This is 100% remote position for candidates based in the US (EST/CST time zones preferred).

As a Staff Security Program Manager on the Information Security team, you will play a pivotal role in leading the transformation of our security program to drive business growth and mitigate information risks. You will collaborate with multiple teams, acting as a key driver for our security and compliance initiatives, both internally for software development and delivery, and externally as we pursue industry-standard compliance accreditations. This role is responsible for understanding and translating security frameworks, partnering with stakeholders on control design, supporting implementation, and establishing automated auditing. You will be a vital participant in customer diligence activities, reinforcing EDB’s security and compliance posture.

EDB is undergoing a significant security program transformation, and you will be a leading voice of change. This role requires a blend of strategic planning, project management, and security expertise. You will be responsible for developing and maintaining controls, policies, and procedures, while also driving the execution of projects to enhance our security posture. We are looking for individuals who thrive in a global, distributed environment with flexible work schedules.

What your impact will be: 

  • Lead the transformation of EDBs common controls framework and associated policies and procedures to support business growth and reduce information risks.
  • Contribute to the annual planning process for Information Security initiatives, ensuring alignment with business objectives.
  • Oversee and drive security and compliance initiatives, including maintaining industry-standard accreditations.
  • Lead, coordinate, and manage audits, working with internal teams and third-party auditors.
  • Educate and consult with control owners on effective control environments and audit evidence.
  • Manage the Plan of Action and Milestones (POAM) related to security exceptions, ensuring timely completion.
  • Forge essential working relationships with engineering leadership, product management, and executive management.
  • Participate in customer security diligence efforts, managing questionnaires and requests while continuously improving the efficiency and effectiveness of the response process.
  • Identify, develop, and implement metrics that effectively measure the performance and effectiveness of our information security initiatives.

What you will bring:

  • Proven experience in information security and compliance, including project management.
  • Strong understanding of cybersecurity principles, frameworks, and best practices.
  • Experience working with external auditors and a strong understanding of audit methodology.
  • Technical aptitude to navigate compliance controls and cloud security best practices.
  • Strong experience with auditing security objectives of SOC2, PCI, HIPAA, FedRAMP (800-53), ISO 27001.
  • Proven project management skills, with the ability to manage multiple projects simultaneously.
  • Excellent organizational and time management skills, with the ability to prioritize and multitask.  
  • Excellent communication skills to keep internal and external stakeholders aligned.
  • Drive, a proactive attitude, and thorough attention to detail.

What will give you an edge:

  • Certified Information Security Auditor (CISA) or Certified Information Systems Security Professional (CISSP) certifications
  • Experience with Hyperproof GRC Platform and Jira
  • Project Management certification

Compensation Range (DOE/Location)= $170-$190k base salary + annual variable bonus

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

EDB

View company profile →