Security Engineer (L5) - Governance and Assurance

1 Month ago • All levels • Cyber Security • $100,000 PA - $720,000 PA

Job Summary

Job Description

Netflix seeks a second-line Enterprise Governance and Assurance Engineer (L5) to support its continued growth and innovation while mitigating existential risks. Responsibilities include designing and implementing automation for partner trust and SOX processes; designing security controls and risk assessment frameworks; developing policies and compliance programs; evaluating risks; creating reporting metrics; leading cross-functional projects; documenting assurance failures; integrating GRC systems; and serving as a policy and control alignment expert. The ideal candidate is a GRC generalist with experience in security, risk, governance, audit, and compliance, ideally with understanding of studio and content development. This role requires strong technical writing, critical thinking, and the ability to influence business partners and mentor other teams.
Must have:
  • SOX compliance expertise
  • GRC generalist experience
  • Automation design & implementation
  • Risk assessment & policy development
  • Strong technical writing & critical thinking
  • Cross-functional project leadership
Good to have:
  • Studio/content development understanding
  • Experience with NIST CSF 2.0, ISO 27001, PCI DSS
  • International standards experience (GDPR, NIS-2, etc.)
  • Audit experience
Perks:
  • Comprehensive health plans
  • Mental health support
  • 401(k) retirement plan with employer match
  • Stock option program
  • Disability programs
  • Flexible time off
  • Paid leave of absence programs

Job Details

Netflix is one of the world's leading entertainment services, with 283 million paid memberships in over 190 countries enjoying TV series, films and games across a wide variety of genres and languages. Members can play, pause and resume watching as much as they want, anytime, anywhere, and can change their plans at any time.

Netflix is seeking a second-line Enterprise Governance and Assurance Engineer (L5). The ideal person will be a strong Governance, Risk, and Compliance (GRC) generalist with a deep passion for governance. We seek a problem-solver with a comprehensive understanding of the regulatory landscape and cloud technologies. Experience in security, risk, governance, audit, process excellence, and compliance is mandatory, an understanding of studio and content development is a plus.

The Team

The Enterprise Governance & Assurance organization is responsible for helping Netflix take the appropriate security and technology risks to support continued growth and rapid innovation while protecting the company from existential harm. This role sits in our Governance, Compliance, and Engineering team and supports the business in improving decision-making by understanding our risks.

Key Responsibilities:

  • Design and implement automation for partner trust, assurance, compliance, and regulatory activities, especially for SOX processes. Design and oversee security controls, risk assessment frameworks, policy development, and compliance programs.

  • Evaluate risks and develop security standards, procedures, guidelines, and policies for information and data governance in collaboration with the business areas.

  • Develop reporting metrics, dashboards, and evidence artifacts demonstrating the value of governance. 

  • Create, optimize, and support cross-functional working groups and projects to enhance the efficacy and effectiveness of policy and guidance across the organization.

  • Document and report assurance failures, inconsistencies, and gaps to stakeholders.

  • Integrate GRC systems with cross-functional stakeholder systems to ensure accuracy and consistency. 

  • Be the subject matter expert for policy development and control alignment. 

  • Enterprise risk management and business continuity experience helpful

In your day-to-day, you will need to exercise sound judgment, curiosity, and flexibility in making trade-offs between short versus long-term security and business goals. You will demonstrate resilience and navigate difficult situations with composure and tac, to achieve a great outcome for the business. You will succeed in this role by regularly analyzing your performance with a critical eye. A broad understanding of the Netflix business and its partnerships is required. This position will also provide training, advice, and mentorship to other teams throughout Netflix on the value of governance.

What You'll Bring:

  • Strong technical writing and critical thinking skills grounded in enterprise governance principles, quantitative risk analysis, and meeting people where they are with an eye toward maturing the governance program. 

  • Data (including metadata), information (throughout its lifecycle), identity, and privacy governance skills and knowledge required.

  • Well-versed in SOX compliance regulations, specifically control design for user access review automation and integration of various tools and applications.

  • Expertise with frameworks such as NIST CSF 2.0, ISO 27001, PCI DSS, etc.

  • Experience with international standards (GDPR, NIS-2, Cyber Resilience Act, K-ISMS (Korea).

  • Audit experience is a significant advantage. Additional qualities include careful consideration of control design, optimization of effective controls to meet control objectives, and achieving compliance as a byproduct of well-designed control implementation and assurance monitoring.

  • Ability to influence and lead business partners and supporting teams.

  • Resilience and composure in navigating difficult situations.

  • An eagerness to gain a comprehensive understanding of Netflix's business and partnerships. A person well-versed in risk appetite/tolerance and how it can be adapted for different tolerances in different parts of the business while still meeting control objectives is the type of mindset we seek.

  • Ability to provide training, advice, and mentorship to other teams.

Cultural attributes:

  • Ability to align with Netflix's unique culture .

  • Document compliance that satisfies regulators, brings consistency to procedures/guidance, and meets people where they are, while living Netflix’s culture principles of “context not control” and “guardrails not rules.”  

Compensation:

Generally, our compensation structure consists solely of an annual salary; we do not have bonuses. You choose each year how much of your compensation you want in salary versus stock options. To determine your personal top of market compensation, we rely on market indicators and consider your specific job family, background, skills, and experience to determine your compensation in the market range. The range for this role is 100,000 - $720,000.

Benefits:

Netflix provides comprehensive benefits including Health Plans, Mental Health support, a 401(k) Retirement Plan with employer match, Stock Option Program, Disability Programs, Health Savings and Flexible Spending Accounts, Family-forming benefits, and Life and Serious Injury Benefits. We also offer paid leave of absence programs.  Full-time hourly employees accrue 35 days annually for paid time off to be used for vacation, holidays, and sick paid time off. Full-time salaried employees are immediately entitled to flexible time off. See more detail about our Benefits here

Culture: 

Netflix is a unique culture and environment.  Learn more .

We are an equal-opportunity employer and celebrate diversity, recognizing that diversity of thought and background builds stronger teams. We approach diversity and inclusion seriously and thoughtfully. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

is a Netflix value and we strive to host a meaningful interview experience for all candidates. If you want an accommodation/adjustment for a disability or any other reason during the hiring process, please send a request to your recruiting partner.

We are an equal-opportunity employer and celebrate diversity, recognizing that diversity builds stronger teams. We approach diversity and inclusion seriously and thoughtfully. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

Job is open for no less than 7 days and will be removed when the position is filled.

Similar Jobs

PwC - IN-Senior Associate_ MDMS Expert _Utility Transformation  _Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
3 Months ago
Scanline VFX - Senior Pipeline Developer (Maya)

Scanline VFX

Toronto, Ontario, Canada (Remote)
3 Months ago
Paypal - Senior Director, Global B2B Growth

Paypal

San Jose, California, United States (Hybrid)
4 Months ago
Life church - Director of Product Design

Life church

Edmond, Oklahoma, United States (On-Site)
3 Months ago
Bazaarvoice - Staff DevOps Engineer

Bazaarvoice

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
PwC - Oracle EPM - Associate

PwC

Mumbai, Maharashtra, India (On-Site)
3 Months ago
PwC - Assurance Technology Risk & Quality Manager

PwC

Dublin, County Dublin, Ireland (On-Site)
3 Months ago
PwC - CD&E-ServiceNow developer -Associate 2-Hyderabad

PwC

Hyderabad, Telangana, India (On-Site)
2 Months ago
PwC - IN_Associate_Internal Audit_Internal Audit Services_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
1 Month ago
PwC - IN_Manager_Tech Lead Payments_FS  tech _Advisory _Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

DNEG - Pipeline ATD

DNEG

Mumbai, Maharashtra, India (On-Site)
3 Months ago
Workato - Commercial Account Executive

Workato

Tokyo, Japan (On-Site)
3 Months ago
Salesforce - Entreprise Account Executive - Germany - Healthcare & Life Sciences

Salesforce

Frankfurt, Hessen, Germany (On-Site)
4 Months ago
ARA - Intermediate Unreal Technical Artist - Remote Opportunity Available!

ARA

Raleigh, North Carolina, United States (Remote)
6 Months ago
Bally's Interactive - Technician - Surveillance

Bally's Interactive

Chicago, Illinois, United States (On-Site)
2 Months ago
Evolution - Studio Interior Designer

Evolution

Riga, Latvia (On-Site)
1 Month ago
Paypal - iOS Developer - Recent Graduate

Paypal

Stockholm, Stockholm County, Sweden (On-Site)
4 Months ago
Netflix - Engineering Manager, Workstations Platform

Netflix

Los Gatos, California, United States (On-Site)
1 Month ago
ByteDance - Optical system engineer - Pico Lab -(AR)- San Jose

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
Outplay - Product Marketing Manager

Outplay

(Hybrid)
1 Week ago

Get notifed when new similar jobs are uploaded

Jobs in United States

Epic Games - QA Lead

Epic Games

Cary, North Carolina, United States (On-Site)
4 Weeks ago
ION - Principal Business Consultant - Endur

ION

Houston, Texas, United States (On-Site)
3 Months ago
Sports radar - Synergy Sports Showcase Softball/Baseball Video Scouts

Sports radar

Alabama, New York, United States (On-Site)
3 Months ago
ByteDance - HR Business Partner

ByteDance

Seattle, Washington, United States (On-Site)
2 Weeks ago
PENN Interactive - Graphic Designer

PENN Interactive

Philadelphia, Pennsylvania, United States (On-Site)
2 Months ago
ByteDance - Research Scientist in Molecular Dynamics

ByteDance

Seattle, Washington, United States (On-Site)
3 Months ago
Match Group - Sr. Product Manager, Safety Experience

Match Group

Palo Alto, California, United States (Hybrid)
3 Months ago
The Walt Disney Company - Senior Software Engineer - Ad Platform

The Walt Disney Company

Glendale, California, United States (On-Site)
1 Week ago
BANDAI NAMCO - Social Marketing Coordinator

BANDAI NAMCO

Santa Clara, California, United States (Hybrid)
1 Week ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Senior Experimentado - Application support analyst

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
3 Months ago
ION - Intermediate IT Auditor, Italy

ION

Pisa, Tuscany, Italy (On-Site)
3 Months ago
Applike - IT Security Manager (f/m/d)

Applike

Hamburg, Hamburg, Germany (Hybrid)
4 Weeks ago
Varonis  - Product Security GRC

Varonis

Morrisville, North Carolina, United States (On-Site)
3 Months ago
Electronic Arts - Security Data Engineer

Electronic Arts

Guildford, England, United Kingdom (On-Site)
1 Month ago
Trend Micro - Automotive Research Engineer - Threat Intelligence & Content Creation (VicOne)

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
PwC - Consultant Expérimenté / Manager Cybersécurité | CDI | H/F

PwC

Toulouse, Occitanie, France (On-Site)
4 Months ago
PwC - IN_Manager_Tech Lead Payments_FS  tech _Advisory _Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
3 Months ago
Microsoft - Software Engineer

Microsoft

Cambridge, England, United Kingdom (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

About The Company

Netflix is one of the world's leading entertainment services with over 247 million paid memberships in over 190 countries enjoying TV series, films and games across a wide variety of genres and languages. Members can play, pause and resume watching as much as they want, anytime, anywhere, and can change their plans at any time.

Tokyo, Japan (On-Site)

Seoul, South Korea (On-Site)

Los Angeles, California, United States (On-Site)

New York, New York, United States (Hybrid)

Los Gatos, California, United States (On-Site)

State Of São Paulo, Brazil (On-Site)

United States (Remote)

Amsterdam, North Holland, Netherlands (On-Site)

Los Gatos, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Netflix

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug