> Markdown version of [/jobs/ext/2718527-sr-information-security-governance-manager](https://www.wearedevelopers.com/jobs/ext/2718527-sr-information-security-governance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Information Security Governance Manager - **Company:** SonarSource US, Inc. - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Information Systems, Identity and Access Management, Security Support Provider Interface, SONAR (Symantec), Large Language Models, Prompt Engineering, Software Security - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/sr-information-security-governance-manager-sonarsource-8009046 ## About the Role * Unwavering Customer Obsession: You view security as an enabler. You are dedicated to building solutions that allow teams to move fast and innovate without compromising the safety of the organization or our users. * Extensive Multi-Domain InfoSec Expertise: Deep, extensive experience and knowledge across multiple security domains, examples include Cloud Security, GRC (Governance, Risk, and Compliance), Identity & Access Management (IAM), or Application Security. You are considered a reference by teams and leaders in your areas of expertise. * AI Proficiency: Demonstrated ability to leverage AI tools and develop complex prompts to solve non-linear security problems and automate repetitive governance tasks. Ability to establish best practices for AI-driven security workflows that others can adopt. * Strategic Security Documentation: Ability to draft sophisticated policy language, control descriptions, and executive-level reports that bridge the gap between technical reality and business risk. Able to communicate strategic matters effectively to varying and diverse audiences. * Technical Diplomacy & Strategic Communication: Exceptional communication skills with the ability to influence cross-functional stakeholders, explain complex security requirements to non-technical peers in a way that fosters collaboration, and fully own complex problem resolution from communication through execution. * Autonomous Leadership & Organizational Acumen: Strong organizational skills to manage multiple high-stakes remediation projects simultaneously under broad objectives with minimal supervision. Ability to take part in critical, high-impact decisions, mitigate risk within the domain, and proactively influence cross-functional teams to achieve ambitious objectives and model best practices. Additional commentsThis role is based in Austin, TX. We are unable to consider candidates unwilling to be in Austin, but we are willing to relocate the right candidate. ## Description The primary goal of the Information Security team is to build trust with our rapidly growing customer base by ensuring the Sonar organization meets a high level of security to protect our customers. As a member of the Information Security team, you will be based in Sonar's Austin office leading the Security Governance and Customer Trust domains of our security risk management program. You will also support security incidents from time to time as needed. Your positive contributions will significantly impact the growth of the business through Sonar's "collective intelligence" mindset., * Customer Interaction: Manage and participate in a clear process to provide clear security answers to our customers and internal users. This includes information on our Trust Center and also meeting with customers to provide required information. * Trust System Management: Ensure our customer trust systems are accurate and support federated security support across Sonar. Drive improvements and enhanced capability implementation in our tooling. * AI Prompt Engineering: Develop and refine prompts and automated workflows using LLMs to enhance our abilities in ensuring security information systems are valid and up to date. * Security Initiative Leadership: Support assigned security initiatives, ensuring they are delivered on time, within scope, and aligned with the broader InfoSec roadmap. Take part in critical, high-impact technical and strategic decisions, proactively influencing cross-functional teams to achieve ambitious objectives. * Coaching & Cross-Functional Quality: Coach and mentor team members and cross-functional colleagues on complex problem-solving, risk management methodologies, and security best practices. Take ownership of broader cross-functional execution and quality standards to raise the bar across the InfoSec program. * Security Governance: Own and maintain Sonar's security governance program and associated artifacts. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)