Security Governance Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a highly motivated Senior Security Governance Manager to strengthen our cybersecurity program and ensure effective governance across key initiatives. This role will serve as a trusted advisor to the CISO, overseeing cybersecurity risk management, developing control & prioritization frameworks, and creating metrics that measure program maturity, risk assessment/reduction, and business alignment. The ideal candidate is a strategic thinker who can balance governance discipline with business agility, ensuring that security investments deliver measurable outcomes.
What You’ll Do
Program Oversight & Governance
Oversee the execution of cybersecurity initiatives, ensuring alignment with business objectives, compliance obligations, and risk management priorities.
Develop and maintain a comprehensive security governance framework aligned with industry standards (NIST CSF 2.0, ISO/IEC 27001, or SOC 2).
Manage the Threat Management program, which assesses, identifies, quantifies, and prioritizes risk reduction.
Maintain an up-to-date catalog of cybersecurity projects and initiatives, tracking progress, risks, and dependencies to ensure effective management and oversight. Build and facilitate governance channels, such as Risk advisories/meetings, to provide visibility, accountability, and decision-making support.
Author and enforce technical security policies that are practical, enforceable, and aligned with legal requirements (GDPR, CCPA, etc.).
Maintain the existing working group meetings to identify new risks, track remediation progress, and manage the threat register.
Prioritization & Strategic Alignment
Develop and maintain a cybersecurity control & project prioritization framework based on business risk, regulatory requirements, and resource capacity.
Conduct technical risk assessments of cloud environments, third-party vendors, and internal systems to identify vulnerabilities and mandate remediation.
Partner with security leaders, IT, Internal Audit, Engineering, and business stakeholders to recommend the sequencing of initiatives that maximize impact.
Provide the CISO with clear recommendations on project trade-offs and resource allocation before executing projects. These outcomes should be based on outstanding risk to the business.
Metrics & Reporting
Define and track key performance indicators (KPIs) and key risk indicators (KRIs) to measure the effectiveness of security programs and identify areas for improvement.
Build executive-level dashboards and reports that translate technical program data into business-relevant insights.
Support board and executive reporting by providing crisp, data-driven updates on program status and risk posture.
Risk & Compliance Alignment
Ensure that security initiatives support compliance requirements, as applicable, by partnering with the Security Assurance & Finance team.
Collaborate with Enterprise Risk Management and Internal Audit teams to maintain alignment between cybersecurity program maturity and business outcomes.
Leadership & Stakeholder Engagement
Act as the lead Project Manager for security transformations, ensuring that complex technical deployments (like Zero Trust architecture or AI-driven monitoring) are delivered on time and within budget.
Act as a bridge between technical teams and senior management, ensuring clear communication of priorities, risks, and progress.
Influence and educate stakeholders on cybersecurity governance principles and the business value of security investments.
Mentor team members and foster a culture of accountability and continuous improvement.
Requirements
7+ years of experience in cybersecurity, IT governance, risk management, or related fields.
Proven track record in program management or governance within a security or risk context.
Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001, CIS Controls).
Experience creating executive-level metrics and dashboards.
Excellent communication and presentation skills, with the ability to convey technical concepts in business terms.
Bonus Points
Prior experience working in a CISO office or security governance function.
Familiarity with regulatory and compliance standards across multiple industries.
Project management certification (PMP, PRINCE2, or similar) or governance certifications (CGEIT, CRISC, CISM).
Bachelor’s or Master’s degree in Information Security, IT, Business, or related, Analysis Skills, Artificial Intelligence (AI), Brand Strategy, Budget Management, CISM - Certified Information Security Manager, Capacity Requirements Planning (CRP), Cloud Computing, Communication Skills, Computer Security, Continuous Improvement, Decision Support, Establish Priorities, Finance, ISO (International Organization for Standardization), IT Governance, Industry Standards, Information Technology/Systems Audit, Information/Data Security (InfoSec), Internal Audit, International Electro-Technical Commission (IEC), Internet Security, Leadership, Mentoring, Metrics, Online Communications, PRINCE2, Performance Analysis, Performance Metrics, Presentation/Verbal Skills, Program Evaluation, Project Management Certification, Project Management Professional (PMP), Project Tracking, Project/Program Management, Regulatory Compliance, Regulatory Requirements, Reporting Dashboards, Resource Management, Risk, Risk Analysis, Risk Management, Security Monitoring, Social Media, Time Management, U.S. National Institute of Standards and Technology (NIST), Writing Skills
About the company
Yext (NYSE: YEXT) is the leading brand visibility platform, built for a world where discovery and engagement happen everywhere - across AI search, traditional search, social media, websites, and direct communications. Powered by over 2 billion trusted data points and a suite of integrated products, Yext provides brands the clarity, control, and confidence to perform across digital channels. From real-time insights to AI-driven recommendations and execution at scale, Yext turns a brand’s digital presence into a competitive advantage, which is only possible through our team of innovators and enthusiastic collaborators. Join us and experience firsthand why we are consistently recognized as a ‘Best Place to Work’ globally by industry leaders such as Built In, Fortune, and Great Place To Work!, Yext is an equal opportunity employer committed to building a results-driven, engaging culture where every employee has the opportunity to contribute to the success of the Company, perform at the highest possible level, and grow their skills and capabilities. Yext welcomes employees and applicants of all backgrounds and demographics, and does not engage in discrimination on the basis of any protected characteristic recognized under applicable law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. The Company believes a broad variety of life experiences across the Yext team is critical to its mission to help every business in the world be visible everywhere customers search. By seeking out fresh perspectives and fostering a positive interview experience and employee experience, Yext can remain at the forefront of innovation, and better serve its customers.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship
Dev Digest 138 - Are you secure about this?