Staff Security Governance Engineer, Policies & Standards

JobgetherBrussels (Firmensitz, recherchiert)Job.bopublished 10/01/2026
Must-have:CloudAISecurityRemote

Accountabilities: Own the complete lifecycle of security policies, standards, procedures, and guidelines, including drafting, stakeholder review, approval, publication, periodic review, and retirement.

Define and operate a risk-based exception management process covering approvals, expiration tracking, adherence trends, and recommendations for policy improvements.

Manage policy attestation activities, investigate non-adherence, and develop measurable indicators of policy effectiveness and adoption.

Monitor emerging regulations and security standards, including AI-focused requirements, and collaborate with Legal to assess their impact and update policies ahead of compliance deadlines.

Maintain mappings between internal policies and frameworks such as SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF to enable requirements to be reused effectively.

Conduct targeted internal assessments, coordinate remediation efforts, and support audits through evidence collection, testing, and remediation management.

Support customer security questionnaires and meetings while identifying recurring customer needs that can be addressed through stronger policies and self-service resources.

Identify and implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, and assessment activities in partnership with GRC Engineering.

Provide technical and program leadership across Security, Product, Legal, and Engineering, influencing stakeholders without direct authority while mentoring colleagues and helping shape the Security Governance roadmap.

Requirements

10+ years of experience in security governance, GRC, IT risk, or a related field, with hands-on ownership of policy and standards lifecycles and a track record of measurable outcomes.

Strong working knowledge of security and compliance frameworks including SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF, with the ability to apply them in practical operational environments.

Understanding of cloud, SaaS, and DevSecOps practices, with the ability to create security policies that are clear, practical, and actionable for engineering teams.

Strong risk-based approach, balancing regulatory and compliance requirements with real-world security risks and operational needs.

Demonstrated experience using automation or AI to reduce manual governance, risk, and compliance activities.

Excellent written and verbal communication skills, with the ability to translate technical and regulatory concepts for engineers, executives, auditors, customers, and other stakeholders.

Proven ability to collaborate effectively across Security, Product, Legal, and Engineering teams and influence decisions without direct authority.

Experience leading complex or ambiguous technical programs and mentoring other professionals through design, review, and implementation.

Certifications such as CISSP, CISM, CISA, or similar credentials are highly desirable.

Benefits

Base salary range of USD $168,000–$238,000 per year for eligible U.S.-based positions.

Equity compensation and Employee Stock Purchase Plan.

Benefits supporting health, finances, and overall well-being.

Flexible Paid Time Off.

Parental Leave.

Growth and Development Fund to support ongoing learning and professional development.

Team Member Resource Groups and an inclusive workplace culture.

Fully remote work environment with an asynchronous, documentation-driven way of working.

Opportunity to work on high-impact security governance initiatives spanning Security, Product, Legal, and Engineering.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1