ApplySarthi

Staff Security Governance Engineer, Policies & Standards

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

456 open governance roles across 116 companies are on ApplySarthi right now, most of them in Bengaluru (24), Hyderabad (17), Mumbai (10).

What governance roles keep asking for: Stakeholder management (20%), Python (13%), LLMs (12%) — counted across their open postings here.

SaaS jobs

Jobgether has 4,275 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for governance roles keep coming back to Stakeholder management, Python, LLMs. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with SaaS? Tell me one thing you learned the hard way.
  3. Tell me about an outage you handled. What did you learn from it?
  4. How do you decide what to monitor, and what should wake someone up at night?
  5. How would you cut the cloud bill of a system without hurting it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Staff Security Governance Engineer, Policies & Standards at Jobgether interview free →

Accountabilities:: Own the complete lifecycle of security policies, standards, procedures, and guidelines, including drafting, stakeholder review, approval, publication, periodic review, and retirement. Define and operate a risk-based exception management process covering approvals, expiration tracking, adherence trends, and recommendations for policy improvements. Manage policy attestation activities, investigate non-adherence, and develop measurable indicators of policy effectiveness and adoption. Monitor emerging regulations and security standards, including AI-focused requirements, and collaborate with Legal to assess their impact and update policies ahead of compliance deadlines. Maintain mappings between internal policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF to enable requirements to be reused effectively. Conduct targeted internal assessments, coordinate remediation efforts, and support audits through evidence collection, testing, and remediation management. Support customer security questionnaires and meetings while identifying recurring customer needs that can be addressed through stronger policies and self-service resources. Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment activities in partnership with GRC Engineering. Provide technical and program leadership across Security, Product, Legal, and Engineering, influencing stakeholders without direct authority while mentoring colleagues and helping shape the Security Governance roadmap. Requirements 10+ years of experience in security governance, GRC, IT risk, or a related field, with hands-on ownership of policy and standards lifecycles and a track record of measurable outcomes. Strong working knowledge of security and compliance frameworks including SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF, with the ability to apply them in practical operational environments. Understanding of cloud, SaaS, and DevSecOps practices, with the ability to create security policies that are clear, practical, and actionable for engineering teams. Strong risk-based approach, balancing regulatory and compliance requirements with real-world security risks and operational needs. Demonstrated experience using automation or AI to reduce manual governance, risk, and compliance activities. Excellent written and verbal communication skills, with the ability to translate technical and regulatory concepts for engineers, executives, auditors, customers, and other stakeholders. Proven ability to collaborate effectively across Security, Product, Legal, and Engineering teams and influence decisions without direct authority. Experience leading complex or ambiguous technical programs and mentoring other professionals through design, review, and implementation. Certifications such as CISSP, CISM, CISA, or similar credentials are highly desirable. Benefits Base salary range of USD $168,000–$238,000 per year for eligible U.S.-based positions. Equity compensation and Employee Stock Purchase Plan. Benefits supporting health, finances, and overall well-being. Flexible Paid Time Off. Parental Leave. Growth and Development Fund to support ongoing learning and professional development. Team Member Resource Groups and an inclusive workplace culture. Fully remote work environment with an asynchronous, documentation-driven way of working. Opportunity to work on high-impact security governance initiatives spanning Security, Product, Legal, and Engineering.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-01. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.