> Markdown version of [/jobs/ext/2499663-security-governance-manager](https://www.wearedevelopers.com/jobs/ext/2499663-security-governance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Governance Manager - **Company:** Yext, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $136,800.0 - $228,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Cyber Security, Data Security, Decision Support Systems, Information Technology Audit, IT Management, Internet Security, PRINCE2, Zero Trust Network Access, Information Technology, CIS Benchmarks - **Published:** August 21, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-security-governance-manager-new-york-ny--86f59375-21dd-4ad6-8abc-c90ea3115f94 ## About the Role 7+ years of experience in cybersecurity, IT governance, risk management, or related fields. Proven track record in program management or governance within a security or risk context. Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001, CIS Controls). Experience creating executive-level metrics and dashboards. Excellent communication and presentation skills, with the ability to convey technical concepts in business terms. Bonus Points Prior experience working in a CISO office or security governance function. Familiarity with regulatory and compliance standards across multiple industries. Project management certification (PMP, PRINCE2, or similar) or governance certifications (CGEIT, CRISC, CISM). Bachelor's or Master's degree in Information Security, IT, Business, or related, Analysis Skills, Artificial Intelligence (AI), Brand Strategy, Budget Management, CISM - Certified Information Security Manager, Capacity Requirements Planning (CRP), Cloud Computing, Communication Skills, Computer Security, Continuous Improvement, Decision Support, Establish Priorities, Finance, ISO (International Organization for Standardization), IT Governance, Industry Standards, Information Technology/Systems Audit, Information/Data Security (InfoSec), Internal Audit, International Electro-Technical Commission (IEC), Internet Security, Leadership, Mentoring, Metrics, Online Communications, PRINCE2, Performance Analysis, Performance Metrics, Presentation/Verbal Skills, Program Evaluation, Project Management Certification, Project Management Professional (PMP), Project Tracking, Project/Program Management, Regulatory Compliance, Regulatory Requirements, Reporting Dashboards, Resource Management, Risk, Risk Analysis, Risk Management, Security Monitoring, Social Media, Time Management, U.S. National Institute of Standards and Technology (NIST), Writing Skills ## Description We are seeking a highly motivated Senior Security Governance Manager to strengthen our cybersecurity program and ensure effective governance across key initiatives. This role will serve as a trusted advisor to the CISO, overseeing cybersecurity risk management, developing control & prioritization frameworks, and creating metrics that measure program maturity, risk assessment/reduction, and business alignment. The ideal candidate is a strategic thinker who can balance governance discipline with business agility, ensuring that security investments deliver measurable outcomes. What You'll Do Program Oversight & Governance Oversee the execution of cybersecurity initiatives, ensuring alignment with business objectives, compliance obligations, and risk management priorities. Develop and maintain a comprehensive security governance framework aligned with industry standards (NIST CSF 2.0, ISO/IEC 27001, or SOC 2). Manage the Threat Management program, which assesses, identifies, quantifies, and prioritizes risk reduction. Maintain an up-to-date catalog of cybersecurity projects and initiatives, tracking progress, risks, and dependencies to ensure effective management and oversight. Build and facilitate governance channels, such as Risk advisories/meetings, to provide visibility, accountability, and decision-making support. Author and enforce technical security policies that are practical, enforceable, and aligned with legal requirements (GDPR, CCPA, etc.). Maintain the existing working group meetings to identify new risks, track remediation progress, and manage the threat register. Prioritization & Strategic Alignment Develop and maintain a cybersecurity control & project prioritization framework based on business risk, regulatory requirements, and resource capacity. Conduct technical risk assessments of cloud environments, third-party vendors, and internal systems to identify vulnerabilities and mandate remediation. Partner with security leaders, IT, Internal Audit, Engineering, and business stakeholders to recommend the sequencing of initiatives that maximize impact. Provide the CISO with clear recommendations on project trade-offs and resource allocation before executing projects. These outcomes should be based on outstanding risk to the business. Metrics & Reporting Define and track key performance indicators (KPIs) and key risk indicators (KRIs) to measure the effectiveness of security programs and identify areas for improvement. Build executive-level dashboards and reports that translate technical program data into business-relevant insights. Support board and executive reporting by providing crisp, data-driven updates on program status and risk posture. Risk & Compliance Alignment Ensure that security initiatives support compliance requirements, as applicable, by partnering with the Security Assurance & Finance team. Collaborate with Enterprise Risk Management and Internal Audit teams to maintain alignment between cybersecurity program maturity and business outcomes. Leadership & Stakeholder Engagement Act as the lead Project Manager for security transformations, ensuring that complex technical deployments (like Zero Trust architecture or AI-driven monitoring) are delivered on time and within budget. Act as a bridge between technical teams and senior management, ensuring clear communication of priorities, risks, and progress. Influence and educate stakeholders on cybersecurity governance principles and the business value of security investments. Mentor team members and foster a culture of accountability and continuous improvement. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)