Global Cybersecurity Compliance Manager
Job Summary
The Global Cybersecurity Compliance Manager role is a key leadership position responsible for leading an international team of compliance, controls, and policy professionals within Global Security. This role provides people management, operational direction, and HR oversight for a geographically distributed team, including performance management, coaching, career development, capacity planning, prioritization, team operating rhythms, and talent planning. The Global Cybersecurity Compliance Manager partners with NetApp Business Unit Leaders across the enterprise to communicate, verify, and track internal cybersecurity compliance with NetApp policies and standards, industry requirements, external certification controls, regulatory expectations, and customer-required controls. The role also directs the narrative and execution of NetApp’s audit and compliance program, including the intake, coordination, documentation, implementation, and management of customer, regulatory, and internal audit requirements; development and maintenance of compliance controls; identification and escalation of risks; and documentation of issues in a system of record.
Job Responsibilities
- Lead, coach, and manage a team of six compliance, controls, and policy professionals within Global Security, including role clarity, workload prioritization, delegation, accountability, project planning, and delivery from inception through completion.
- Perform core people-management and HR responsibilities, including performance reviews, goal setting, development planning, coaching, feedback, recognition, succession planning, team engagement, hiring support, onboarding, and budget management.
- Lead control testing and compliance discussions related to frameworks such as ISO 27001, SOC 2, NIST 800-53, CIS benchmarks, and other applicable requirements; provide executive-ready status updates, risk insights, and remediation expectations to senior leaders.
- Oversee the intake, assignment, quality review, and timely completion of customer cybersecurity questionnaires and due diligence requests from Sales, ensuring accurate responses, clear ownership, and consistent communication across stakeholders.
- Partner with business units, internal control owners, and cross-functional peers to appropriately scope, validate, test, and document control statements, ensuring clear accountability and defensible evidence for audit and compliance requirements.
- Collaborate with internal business unit leaders and geographically distributed teams to gather, validate, and provide evidence and information for internal audits, external audits, regulatory inquiries, customer assessments, and certification activities.
- Identify, communicate, and escalate gaps in processes, control effectiveness, policy adherence, compliance obligations, and remediation ownership to senior leadership across the enterprise, as appropriate.
- Manage the review of customer and partner contracts for information security, compliance, audit, and control requirements; coordinate business, legal, security, and technical input to ensure commitments are understood and achievable.
- Ensure Global Security policies, standards, procedures, control documentation, and supporting artifacts are documented, reviewed, maintained, and updated in alignment with customer expectations, regulatory obligations, audit requirements, and internal governance cadence.
Job Requirements
- Bachelor's degree in business, accounting, finance, computer science, information systems, engineering, or a related field strongly preferred; equivalent combination of education and experience may be substituted in lieu of degree.
- At least five (5) years of GRC (governance, risk, compliance) experience with methodologies, activities, tools and enablers in a technology related industry or eight (8) – ten (10) years of experience in business process analysis, project methodology, or systems development life cycle through education or on-the-job experience, required.
- Demonstrated experience leading compliance, controls, policy, audit, or risk-management teams within a global security, cybersecurity, technology, or regulated enterprise environment.
- Strong understanding of compliance and regulatory areas such as GDPR, DFARS/NIST 800-171, NIST 800-53, ISO 27001, DORA, and related risk events, with the ability to translate requirements into clear controls, ownership expectations, and executive-level risk communication.
- Excellent written and verbal communication skills, including the ability to communicate expectations, performance feedback, audit status, risk, and compliance requirements clearly to employees, peers, business leaders, and senior executives.
- Strong analytical and problem-solving skills
- Demonstrated ability to work effectively with people from different disciplines, regions, cultures, and technical backgrounds, including the ability to influence without direct authority and build alignment across distributed teams.
- Ability to adapt to a dynamic, rapidly changing business, technical, regulatory, and organizational environment while maintaining team focus, accountability, engagement, and delivery discipline.
- Preferred Qualifications
- Information security related training or certifications such as CISA, CISSP or CRISC
- Prior experience directly managing senior individual contributors, or specialized compliance professionals in a global cybersecurity, security governance, risk, compliance, controls, or policy function.
- Experience building team operating models, improving team execution, developing talent, and translating business priorities into measurable team goals and outcomes.
- Experience performing information security audits or risk assessments
- Familiarity with security audit, risk management, policy governance, controls management, and compliance operating models, including how these functions scale across a global enterprise.
- Knowledge of emerging regulatory requirements, including the Digital Operational Resilience Act (DORA), artificial intelligence (AI) governance, and evolving customer compliance expectations, with the ability to guide teams through new or changing obligations.
