Minimum qualifications:
- Bachelor's degree in a technical field, or equivalent practical experience.
- 2 years of experience in program management.
- Experience working with established security compliance frameworks and certifications (e.g., SOC 2, ISO 27001, NIST 800-53, HIPAA, PCI DSS, CISSP, CISA, CIPP, ISO or equivalent).
- Experience in delivering information security or risk management focused projects, including control design, implementation, remediation, and testing.
Preferred qualifications:
- 2 years of experience managing cross-functional or cross-team projects.
- Experience assessing implementation of product level security controls.
- Experience with Governance, Risk, and Compliance (GRC) platforms.
- Familiarity with the concepts, architecture, and security/compliance offerings of Google Cloud.
- Familiarity with Google's internal GRC systems (e.g., Comply, GGRC).
About the job
A problem isn’t truly solved until it’s solved for all. That’s why Googlers build products that help create opportunities for everyone, whether down the street or across the globe. As a Technical Program Manager at Google, you’ll use your technical expertise to lead complex, multi-disciplinary projects from start to finish. You’ll work with stakeholders to plan requirements, identify risks, manage project schedules, and communicate clearly with cross-functional partners across the company. You're equally comfortable explaining your team's analyses and recommendations to executives as you are discussing the technical tradeoffs in product development with engineers.
The Cloud CISO Compliance and Certifications Team drives the compliance certification initiatives for products and services across Google Cloud. We are responsible for facilitating external audits, self attestations, and providing compliance advisory services for Google Cloud products. We partner directly with product and engineering teams throughout the product lifecycle. Our mission is to guide each product through its specific compliance journey, from design to launch and beyond.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $138000 - $197000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Manage the end-to-end lifecycle of certification programs, ensuring timely renewals and successful achievement of new Google Cloud compliance certifications. Leverage GRC tooling for program tracking, evidence collection, and status reporting.
- Work deeply with engineering and product teams to integrate compliance requirements into the development lifecycle of Google Cloud products and infrastructure. Provide technical guidance on control implementation.
- Assess and mitigate potential compliance impacts of significant technical changes.
- Lead the development, documentation, and validation of security and privacy controls within the designated Governance, Risk, and Compliance (GRC) systems to meet new or evolving certification standards.
- Track, support, and drive the remediation of identified compliance gaps or audit findings using data and workflows within GRC tools. Develop and monitor metrics to report on remediation progress and effectiveness.
