Jobs and Careers
BR

Sr Security and Compliance Engineer

Broadcom
United Statesfull_timeVerifiedPosted 27 Oct 2025
💰 $192,000/yr($120,000/yr$192,000/yr)

About the role

Please Note:

1. If you are a first time user, please create your candidate login account before you apply for a job. (Click Sign In > Create Account)

2. If you already have a Candidate Account, please Sign-In before you apply.

Job Description:

Broadcom seeks an experienced program manager with software engineering skills to lead security compliance and audit activities for its Enterprise Security Group (ESG) cybersecurity products. This strategic role involves driving various certifications (FIPS 140-3, Common Criteria, STIG development, country-specific), formal risk assessments for ESG’s SaaS products, internal security assessments during product release cycles, and customer audits across multiple product lines. 

This requires close collaboration engineering, ProdSec, InfoSec, and SaaS Operations teams to manage these certification and audit processes. This requires leading cross-functional initiatives and serving as a vital liaison between technical and non-technical stakeholders to ensure comprehensive and effective compliance.

The ideal candidate will facilitate interactions with third-party testing labs, auditors, advisors, and assessors, work with Sales and Support teams to respond to customer queries related to supplier risk assessments, and contribute to product standards, processes, and security domain documentation. A key focus will be on identifying opportunities for process improvement and standardization across the organization, with an emphasis on automation.

Responsibilities

  • Translate ESG business objectives into actionable GRC strategies, leveraging deep product and team process understanding to create clear compliance strategies.

  • Facilitate and complete all product certification activities, including financial stewardship and contract reviews as needed.

  • Achieve and maintain certifications, proactively identifying and mitigating risks for continuous compliance.

  • Support the ESG Product Security (ProdSec) team in security compliance activities (risk assessment, secure software development), providing expert guidance to enhance overall security posture.

  • Author and maintain required certification documents. 

  • Communicate and translate certification requirements (ISO, SSAE 18, NIST, etc.) to engineering teams, providing expert guidance.

  • Maintain current understanding of regulations; interpret and communicate changes and their implications to stakeholders.

  • Track milestones, proactively manage risks, and drive solutions to completion.

  • Drive completion of any customer supplier risk requests by leveraging existing information and resources.

  • Monitor schedule deviations and develop corrective actions.

  • Coordinate cross-timezone team activities, including occasional off-hours interaction.

  • Lead the identification, evaluation, and implementation of automation tools and processes for security compliance activities, including evidence collection, control validation, and reporting.

  • Develop and implement technical strategies for efficient and accurate evidence gathering, ensuring data integrity and audit readiness.

  • Collaborate with engineering, ProdSec, and InfoSec teams to integrate security compliance requirements into CI/CD pipelines and automated testing frameworks.

  • Identify opportunities for proactive risk identification and mitigation strategies across product lines, influencing product development and operational practices.

  • Exercise good judgment in achieving compliance objectives and resolving audit findings.

  • Independently manage and prioritize multiple security compliance projects, providing regular updates and data presentations to stakeholders.

Skills and Experience

  • Bachelor's degree and 8+ years of progressive experience in security compliance, audit, or program management, with a strong emphasis on cybersecurity products.

  • Self-starter with Driver personality.

  • Cybersecurity background, particularly cloud security.

  • Proven experience project managing security compliance audit or certification projects.

  • Ability to quickly grasp complex technical concepts and make them easily understandable.<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Broadcom

View company profile →