Posted in

Cloud Governance & Regulatory Compliance Officer

Cloud Governance & Regulatory Compliance Officer

CompanyState Street
LocationBurlington, MA, USA
Salary$70000 – $115000
TypeFull-Time
Degrees
Experience LevelMid Level

Requirements

  • Knowledge of cloud and platform governance, compliance, and regulatory frameworks such as (but not limited to) NIST, CIS, SOC-2, DORA, GDPR, CCPA
  • Ability to align cloud security and operations strategies with financial services regulations.
  • Experience with Cloud native and Cloud Agnostic governance and compliance tools (e.g., Azure Policy, AWS Config, Jupiter One).
  • Knowledge of financial services industry regulations impacting cloud adoption and platform architecture.
  • Experienced in using Risk Management Framework tools such as Archer for issues and controls management
  • Strong communication skills and ability to conduct meetings with cross functional teams involving Information Security Officers, Platform Engineers, Compliance teams, and Business Risk Managers in addition to product engineers and heads.
  • Strong technical writing and documentation skills for regulatory frameworks and audit reporting.

Responsibilities

  • Ensure cloud governance frameworks align with financial regulatory requirements.
  • Provide governance oversight of all operational activities and projects, ensuring compliance with regulatory and operational governance standards.
  • Document governance frameworks and controls to support regulatory audits and assessments.
  • Interface with internal audit and Office of COO Project Managers to help provide compliance evidence and documentation for all cloud operational activities.
  • Develop and implement governance automation solutions to enforce compliance at scale.
  • Support continuous monitoring frameworks to proactively detect non-compliance in cloud deployments.
  • Conduct periodic compliance assessments on cloud security posture across Azure and AWS
  • Provide governance oversight of Vulnerability Management by interfacing with SRE (Site Reliability Engineering) and BRM (Business Risk Management) teams.
  • Periodically review and assess container vulnerability reports for any compliance violations with a call to action where necessary.

Preferred Qualifications

    No preferred qualifications provided.