Senior Manager, Policy and Controls Governance
MongoDB
| Company | MongoDB |
| Category | Legal & Compliance |
| Location | United States |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Manager |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives.
The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness.
This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives.
This role will be based remotely in the United States
Responsibilities:
Scope of Ownership
Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance
Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight
Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility
Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings
Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness
Program Leadership
Own and evolve the governance model for policies, standards, procedures and controls, ensuring clear accountability, consistent execution and audit-ready outputs
Lead the end-to-end policy lifecycle, including creation, review, approval, publication, maintenance, retirement and exception governance
Lead the controls governance program, including common controls framework ownership, framework revision management, control harmonization and periodic cross-functional control reviews
Own the governance model for ARC issues and remediation tracking, including workflows for intake, tracking, monitoring, closure validation and ongoing reporting
Ensure policies and controls remain aligned with compliance requirements, and translate framework changes into actionable program updates
People Management
Manage and develop team members responsible for policy governance, controls governance, and related operational processes by setting priorities, driving workload clarity, and coaching for strong execution
Establish a high bar for quality, accountability, and follow-through while supporting team growth through regular feedback and development
Cross-functional Partnership
Partner within ARC and across Security, Engineering, Product, and Legal teams to align requirements, resolve blockers, and drive timely decisions
Coordinate with policy owners, subject matter experts and operational stakeholders to drive timely reviews, required updates, and exception handling
Serve as a key point of contact for compliance audit support related to policy governance and controls governance processes and program documentation
Operational excellence and metrics
Define, maintain and evolve KPIs, KRIs, dashboards and reporting that measure policy lifecycle health, control maturity, audit readiness, exception trends and program performance
Oversee the systems that support the program, including Jira workflows, GRC platform, and related