{"id":1291853,"url":"https://alion.io/job/netapp-grc-technical-program-manager","title":"GRC Technical Program Manager","company":{"id":58700,"name":"NetApp","domain":"netapp.com","url":"https://alion.io/company/netapp","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Eightfold","truth_index":{"grade":"B","score":75,"open_postings":28,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-27T05:45:00Z"}},"role":"Product","role_family":"Product","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["Usa, Japan"],"countries":["JP"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":129200,"max":192500,"currency":"USD","period":"year","gross":null,"usd_annual":192500},"salary_estimate":null,"experience_years_min":6,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"FedRAMP","optional":false},{"name":"GCP","optional":false},{"name":"Kubernetes","optional":false},{"name":"PCI DSS","optional":false},{"name":"SIEM","optional":false},{"name":"SOC 2","optional":false},{"name":"ISO 27001","optional":true},{"name":"NIST 800-53","optional":true},{"name":"NIST AI RMF","optional":true}],"status":"live","first_seen_at":"2026-08-18T15:42:08Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-27T23:42:34Z","board_verified":true,"closed_at":null,"days_open":40,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":40},"description":"Job Summary\nNetApp’s Cloud business seeks a Governance, Risk & Compliance (GRC) Technical Program Manager to join the Security & Compliance team. This compliance and program management role requires strong cloud technical fluency to prepare products for assessments and certifications, manage risk, translate requirements into testable controls, and improve the security posture. This is not a software engineering role. The position partners with engineering and security teams to automate compliance activities, detection, remediation, evidence collection, and monitoring, including through AI tooling. The role also aligns cross-functional stakeholders and represents the compliance program to leaders, auditors, and hyperscaler partners.\nLocation: RTP, Boston, Waltham\nJob Requirements\nDesign, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications.\nPerform technical gap and risk assessments across infrastructure, applications, and cloud engineering processes; monitor controls and advise owners on remediation.\nTranslate regulatory and compliance controls into clear, measurable engineering and security requirements.\nIdentify manual compliance activities for automation and partner with engineering and security teams on automated detection, remediation, evidence collection, and continuous monitoring.\nApply AI and related tooling to improve compliance workflows.\nAlign Engineering, SRE, Product, Cloud Security, Legal, Privacy, and Corporate Security teams and drive cross-functional initiatives to completion.\nPartner with Microsoft Azure, Google Cloud, and Amazon Web Services on shared compliance and security objectives.\nManage auditor and assessor relationships and clearly present the organization’s technical security posture.\nImprove policies, processes, security governance, and adoption of GRC tooling.\nRequired Qualifications\n6+ years building and managing security risk and compliance programs, including ownership of large cross-functional programs through certification.\nDeep knowledge of ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP, with demonstrated ability to convert controls into engineering requirements.\nDirect experience partnering with engineering teams to deliver technical outcomes.\nExceptional stakeholder management and ability to influence senior stakeholders and external partners without direct authority.\nStrong technical fluency in AWS and Azure, Kubernetes, containers, virtual machines, identity and access control, network security, cryptography, logging and monitoring, incident response, DevOps, and CI/CD.\nFamiliarity with cloud security capabilities, SIEM, vulnerability scanning, cloud security posture management, and endpoint detection and response.\nProduct-oriented problem solving with the ability to investigate gaps, gather requirements, and drive solutions to completion.\nPreferred Qualifications\nExperience with FedRAMP, GovRAMP, CMMC, CJIS, and NIST 800-53/800-171.\nExperience applying AI or large language model tooling to compliance workflows and familiarity with NIST AI RMF or ISO/IEC 42001.\nEducation\nBachelor’s or Master’s degree in Engineering, Computer Science, Information Technology, or a related field, or equivalent professional experience.\nProfessional certifications in security, compliance, or cloud are advantageous, including CISA, CISSP, CRISC, CCSK, CCSP, CIPP, AWS certifications, or ISO 27001 Lead Implementer / Lead Auditor.\nCompensation:\nThe target salary range for this position is 129,200 - 192,500 USD. The salary offered will be determined by the candidate's location, qualifications, experience, and education and may be outside of this range. The range is based on 'On Target Earnings’ (OTE) representing the total potential earnings, which is the sum of the base salary and potential commission earned when performance targets are achieved. Final compensation packages are competitive and in line with industry standards, reflecting a variety of factors, and include a comprehensive benefits package. This may cover Health Insurance, Life Insurance, Retirement or Pension Plans, Paid Time Off, various Leave options, employee stock purchase plan, and/or restricted stocks (RSU’s). These offerings are subject to regional variations and governed by local laws, regulations, and company policies. We will provide detailed information about the specific benefits for your region during the recruitment process.","description_format":"text","description_chars":4479,"description_truncated":false,"requirements":{"experience_years_min":6,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["Health insurance","Life insurance","Retirement plans"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Natural Resources","Cloud Platforms (IaaS & PaaS)","Digital Storage"],"lifecycle":[{"event":"open","at":"2026-09-26T07:57:33Z"}],"liveness":{"score":27,"band":"fade","label":"Fading","p_open":1,"p_active":0.495,"p_room":0.55,"age_days":39,"expected_fill_days":30,"reasons":["conf:7","stale_co","velocity","win:tail","comp:brand"],"computed_at":"2026-09-27T05:45:00Z"},"pay":{"stated_usd_annual":192500,"is_top_pay":false},"html_url":"https://alion.io/job/netapp-grc-technical-program-manager","json_url":"https://alion.io/job/netapp-grc-technical-program-manager.json","meta":{"generated_at":"2026-09-28T03:04:51Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1944,"day_limit":5000,"remaining_today":3056,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}