Compliance Enablement Technical Program Manager

Sophos
Canada
Workplace: RemoteFull time109,000 - 181,000Function: Program & Project Management (PMO)Education: bachelorsSkills: ["Program management","Mentoring","Leadership","Written communication","Verbal communication","Technical discussions","Stakeholder communication","Technical-to-compliance translation"]

Serve as the Trust & Assurance team’s technical SME for compliance automation. Lead control mapping, evidence collection, and continuous monitoring workflows within the GRC platform, partnering with engineering to embed compliance into engineering processes. Translate technical controls into automated checks, manage compliance stack integrations with cloud and internal systems, and drive initiatives end-to-end while communicating compliance risk and program progress to technical and non-technical stakeholders.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sophos
Sophos
1 week ago

Compliance Enablement Technical Program Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live
Reposted: similar role first listed 5 months ago

Job Summary

Serve as the Trust & Assurance team’s technical SME for compliance automation. Lead control mapping, evidence collection, and continuous monitoring workflows within the GRC platform, partnering with engineering to embed compliance into engineering processes. Translate technical controls into automated checks, manage compliance stack integrations with cloud and internal systems, and drive initiatives end-to-end while communicating compliance risk and program progress to technical and non-technical stakeholders.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Program & Project Management (PMO)
Seniority: Mid level

Key Responsibilities

  • •Serve as the team’s technical authority and technical SME/primary point of contact for Trust & Assurance.
  • •Lead control mapping, evidence collection, monitoring workflows, and manage integrations connecting the GRC platform to cloud platforms and internal systems.
  • •Establish control monitoring by translating controls into automated, continuous checks to expand monitoring coverage.
  • •Ensure controls remain audit-ready by maintaining accountable owners, supporting gap assessments, and rolling out new frameworks.
  • •Partner with engineering to embed compliance requirements into workflows from the start and manage delivery while keeping stakeholders aligned.

Pay and Benefits

Salary: 109,000 - 181,000

Key Requirements

  • •4+ years in GRC, compliance, or a technical role supporting cybersecurity programs, including leading programs and mentoring others.
  • •Strong program and project management skills, delivering across multiple teams.
  • •Knowledge of cybersecurity compliance frameworks (NIST 800-53, ISO 27001, SOC 2, and/or FedRAMP) with audit experience.
  • •Enough technical depth to reason about cloud infrastructure (AWS, Azure, or GCP), APIs, and data flows, and interpret technical work with AI assistance.
  • •Experience with a GRC or compliance-automation platform (e.g., LogicGate, ServiceNow, Drata) and comfort using AI tools in compliance workflows.
Experience:GRCComplianceCybersecuritySaaSGovCloudFinTechRegulated environments
Education:Bachelor's in Cybersecurity, Information Technology, Computer Science, or a related field
Skills:Program managementMentoringLeadershipWritten communicationVerbal communicationTechnical discussionsStakeholder communicationTechnical-to-compliance translation
Certifications:CISSPCISMCISACCSPCCSKISO 27001 Lead Auditor
Tech Stack:NIST 800-53ISO 27001SOC 2FedRAMPAWSAzureGCPLogicGateServiceNowDrataPythonAI toolsOSCALTenableSplunkGitTerraformPuppetJenkinsCI/CD

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Sophos
Provides enterprise cybersecurity software and services including endpoint protection, network security, cloud security, encryption, and managed threat response to protect organizations from advanced threats and ransomware.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Established Company
Valuation: Unicorn (USD 1B+)
Funding: Private Equity Backed
Headquarters: Abingdon, United Kingdom
Founded: 1985
WebsiteLinkedIn