ISO 42001 Compliance Manager

Box
Redwood City, California
Workplace: HybridFull timeUSD 129,500 - 175,000 annuallyFunction: Legal, Risk & ComplianceExperience: 4+ yearsEducation: bachelorsSkills: ["Communication","Stakeholder management","Organizational skills","Cross-functional collaboration","Process improvement"]

Own and drive Box’s ISO 42001 (AIMS) compliance certification program, including yearly ISO certification cycles, internal AI governance effectiveness assessments, and remediation of control gaps. Lead external audits with third-party auditors, maintain auditor relationships, and operate across multiple frameworks (ISO, PCI, NIST, AICPA SOC). Communicate compliance posture and program progress to technical and non-technical stakeholders while improving processes and building scalable governance.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Box
Box
16 hours ago

ISO 42001 Compliance Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own and drive Box’s ISO 42001 (AIMS) compliance certification program, including yearly ISO certification cycles, internal AI governance effectiveness assessments, and remediation of control gaps. Lead external audits with third-party auditors, maintain auditor relationships, and operate across multiple frameworks (ISO, PCI, NIST, AICPA SOC). Communicate compliance posture and program progress to technical and non-technical stakeholders while improving processes and building scalable governance.
Location: Redwood City, California
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Manager level

Key Responsibilities

  • •Drive and lead Box’s annual ISO certification program for AIMS against ISO 42001.
  • •Create and own the AIMS program and assess AI governance effectiveness with internal teams.
  • •Execute external audits with third-party auditors and maintain auditor relationships.
  • •Work across ISO, PCI, NIST, and AICPA SOC (and related frameworks/standards) to support compliance needs.
  • •Communicate gaps to management, coordinate cross-functional remediation, and monitor compliance issues to closure.

Pay and Benefits

Salary: USD 129,500 - 175,000 annually
Equity and Bonus:Equity

Key Requirements

  • •4+ years leading and performing ISO 27001 audits (or equivalent technology/compliance role managing security audits).
  • •Familiarity with GCP cloud computing, AI architectures, data governance, and model validations.
  • •Security/compliance certifications such as CISSP, CISA, CIA, or CISM.
  • •Extensive knowledge of at least 2+ compliance frameworks including ISO 27001, ISO 27017, ISO 27018, ISO 42001, PCI, SOC, and NIST 800-53.
  • •BS in Business or Management Information Systems or equivalent work experience, with strong written/verbal communication and presentation skills.
Experience:4+ years
Education:Bachelor's in Business or Management Information Systems
Skills:CommunicationStakeholder managementOrganizational skillsCross-functional collaborationProcess improvement
Certifications:CISSPCISACIACISMISO 27001 Lead ImplementerISO 42001 Lead Auditor
Languages:English
Tech Stack:GCP

Company Brief

Box
Provides cloud content management, file sharing, and collaboration services for businesses, enabling secure content storage, workflow automation, and integrations with enterprise apps to manage and share files across organizations.
Industry: Enterprise Software
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Redwood City, United States
Founded: 2005
WebsiteLinkedIn