Program Manager, Commercial Compliance
MongoDBNew York City; United StatesPosted 3 April 2026
Job Description
Description:
The Compliance team at MongoDB manages the strategy, execution, and maintenance of our global security certifications and regulatory requirements. We ensure that our cloud database products meet the rigorous security standards required by our customers in the most highly regulated industries worldwide.
We act as the primary interface between external auditors and our internal Product, Engineering, and Legal teams. Our goal is to translate complex regulatory requirements into scalable operational processes, maintaining a compliant and audit-ready posture across our diverse portfolio.
The Program Manager / Senior Analyst is a mid-to-senior level individual contributor role responsible for leading high-stakes audits and specialized compliance workstreams. Unlike the Analyst level, this role takes full ownership of complex international frameworks—such as IRAP and ENS High—and manages the relationship with our Financial Services customers during audit deep-dives. You will lead internal audit cadences and perform gap analyses for new market expansions.
Responsibilities:
Lead the end-to-end execution of specialized external audits (e.g., ENS High, IRAP, ISO 22301) and coordinate all phases from initial scoping to final certification
Serve as the lead point of contact for Financial Services customer audits, facilitating meetings, responding to security questionnaires, and defending our control environment to external stakeholders
Lead internal audit cadences and drive the POAM tracking process, ensuring technical teams remediate findings within required SLAs
Map new regulatory requirements to our central control framework, performing gap analyses to identify where existing controls can be leveraged for new certifications
Conduct NIST CSF or similar maturity assessments to monitor the effectiveness of the Compliance Program and report findings to team leads
Author and review customer-facing security documentation, ensuring it accurately reflects our technical controls and architectural guardrails
Partner with Engineering and Product leads to implement compliance-by-design, ensuring future product roadmaps align with global regulatory shifts
Requirements:
7+ years in GRC, Information Security, or IT Audit, specifically within a high-growth SaaS/Cloud environment
Deep understanding of cloud security principles (AWS/GCP/Azure) and a proven track record leading technical audits for ISO 27001, SOC 2, or ENS High
Solid grasp of audit processes, terminology, and risk assessment standards. Certifications such as CISA, CRISC, CISSP, or ISO Lead Implementer are highly preferred
Exceptional ability to lead meetings with external customers and auditors, translating technical complexities into business risk and compliance assurance
Advanced proficiency in Jira for tracking control performance data and managing high-volume remediation workflows
Practical experience performing gap analyses and maturity assessments at an enterprise level
Responsibilities Expectations
You are expected to be a subject matter expert who can operate with minimal supervision
You don't just track tasks; you own the success of the program
You are expected to navigate complex audit negotiations with external parties and drive internal technical teams toward compliance milestones without disrupting innovation
Scope Complexity
The scope is international and technically diverse. You will manage overlapping audit cycles across different global jurisdictions (e.g., Spain, Australia, US) and complex industry sectors
You are responsible for identifying how a single technical control can satisfy multiple global regulatory requirements simultaneously
Authority Impact
You have the authority to lead audit engagements and represent MongoDB’s security posture to sophisticated Financial Services customers
Your impact is direct: by securing and maintaining these certifications, you enable our sales organization to close enterprise-level deals in hig ... (truncated, view full listing at source)
Apply Now
Direct link to company career page
AI Resume Fit Check
See exactly which skills you match and which are missing before you apply. Free, instant, no spam.
Check my resume fitFree · No credit card