Job Closed
This listing is no longer active.
Security Uncompromised
Principal Manager, Product Compliance
Location
United States
Posted
111 days ago
Salary
$220K - $240K / year
Seniority
Lead
Job Description
Principal Manager, Product Compliance
ExtraHop
• Manage and develop staff members under Product Compliance and fulfill people manager responsibilities • Direct Continuous Monitoring (ConMon) processes and ensure successful monthly reviews with ExtraHop and agency stakeholders in order to maintain FedRAMP authorization • Oversee and contribute to the vulnerability management lifecycle: triage, reporting, coordination with system owners, and remediation tracking • Manage the review of vulnerability findings and provide formal written responses for internal and external stakeholders, including customers • Assess and serve as a subject matter expert for regulatory and compliance requirements and best practices for various standards (e.g., CSA STAR, ISO 27001, FISMA, DORA, FINRA, DoDIN APL, NIAP, FIPS, CMMC, IL4/IL5) • Lead gap assessments and facilitate or support audits (including coordinating evidence collection and submission) • Develop and manage a product security compliance roadmap, incorporating input, feedback and data-driven requirements from Sales, Customer Success, Product Management, and R&D organizations; validate the roadmap with executive leadership; coordinate key activities across the organization to achieve roadmap milestones • Collaborate with Product Security and R&D staff to provide responses to customer and pre-sales inquiries about product security and related items • Collaborate with Product Security team members to develop and improve standards, policies, procedures, documentation, and training • Participate in security incident response activities, representing Product Security and R&D leadership in directing the execution of the IR Plan • Other duties as assigned
Job Requirements
- 12+ years of experience in cybersecurity, with a focus on compliance frameworks like FedRAMP, NIST SP800-53, SOC 2 and ISO 27001
- 5+ years of which should be hands-on experience specifically managing compliance programs, security assessments, or cloud security initiatives
- Bachelor's degree in a related field such as Cybersecurity, Computer Science, Information Systems, Engineering or other technical or management discipline
- Direct experience with the FedRAMP compliance framework, including security control requirements, documentation and assessment methodologies
- Technical knowledge of web application security and cloud security, including best practices and controls for cloud-based environments
- Proficient with security tools, including vulnerability scanners, ticketing systems (e.g., Jira), compliance reporting platforms, and SIEM tools
- Exceptional analytical skills to effectively manage and resolve security and compliance issues
- Proven ability to communicate complex security concepts to technical and non-technical audiences
- Strong project management skills with the ability to balance compliance initiatives and security operations
- Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder) or lawfully admitted into the U.S. as a refugee or granted asylum.
- Work cooperatively with others within the organization and other cross-functional stakeholders.
- Work well in fast-paced, high-stress environments.
- Has predictable, reliable attendance.
Benefits
- Health, Dental, and Vision Benefits
- Flexible PTO, Sick Time Prorated Based on Date of Hire, and All Federal Holidays (US Only) + 3 Days of Paid Volunteer Time
- Non-Commissioned Positions may be eligible to participate in the Annual Discretionary Bonus Plan
- FSA and Dependent Care Accounts + EAP, where applicable
- Educational Reimbursement
- 401k with Employer Match or Pension where applicable
- Pet Insurance (US Only)
- Parental Leave (US Only)
- Hybrid and Remote Work Model
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
• Design enterprise risk frameworks • Implement internal control systems • Govern financial and operational compliance • Reduce exposure across markets • Identify risk vectors and build mitigation protocols • Maintain risk registers and escalation thresholds • Ensure compliance across jurisdictions
• Contribute to preparation and delivery of regulatory submissions • Preparation and review of Marketing Authorization Applications & Variations • Responsible for project planning and set-up • Ensures client expectations for quality and timeliness are met • Identifies new opportunities through Change in Scope or add-on business • Produces quality work that meets expectations of PC and the client • Supports development of business solutions addressing specific client needs
• Manage end-to-end labeling lifecycle including preliminary assessment, implementation, and post-approval maintenance • Provide innovation and technical expertise for the creation, maintenance, and implementation of labeling to meet country-specific regulatory requirements • Execute labeling operations globally with precision and efficiency • Participate in a 'follow the sun' model to ensure timely execution of labelling activities across time zones • Prepare and review labelling documents for regulatory submissions and variations • Maintain labeling databases and tracking systems • Support global labelling harmonization initiatives • Collaborate with regional regulatory teams to ensure compliance with local requirements • Monitor regulatory intelligence related to labelling requirements
• Manage end-to-end labeling lifecycle including preliminary assessment, implementation, and post-approval maintenance • Provide innovation and technical expertise for the creation, maintenance, and implementation of labeling to meet country-specific regulatory requirements • Execute labeling operations globally with precision and efficiency • Participate in a 'follow the sun' model to ensure timely execution of labelling activities across time zones • Prepare and review labelling documents for regulatory submissions and variations • Maintain labeling databases and tracking systems • Support global labelling harmonization initiatives • Collaborate with regional regulatory teams to ensure compliance with local requirements • Monitor regulatory intelligence related to labelling requirements


