Skip to main content
Search jobs

Search jobs

Only cities with current job openings will appear in search. Please sign up for job alerts if your city is not listed.

Own Every Moment at NetApp

At NetApp, your ideas power innovation. We lead in intelligent data infrastructure—delivering unified storage, integrated data services, and solutions that help organizations unlock the full potential of their data, from AI to multicloud.

Ready to innovate and contribute to our path to $10B? Here, you'll collaborate with passionate teams, tackle real-world challenges, and see your impact in how customers transform and grow. If you're ready to bring curiosity, creativity, and drive to every moment, NetApp is where your journey begins. Join teams that innovate to elevate, drive results, and excel together across every function.

GRC Technical Program Manager

Morrisville, North Carolina, United States
Job category: Cloud Job ID: 136171-en_US
Apply

Job Summary

NetApp’s Cloud business seeks a Governance, Risk & Compliance (GRC) Technical Program Manager to join the Security & Compliance team. This compliance and program management role requires strong cloud technical fluency to prepare products for assessments and certifications, manage risk, translate requirements into testable controls, and improve the security posture. This is not a software engineering role. The position partners with engineering and security teams to automate compliance activities, detection, remediation, evidence collection, and monitoring, including through AI tooling. The role also aligns cross-functional stakeholders and represents the compliance program to leaders, auditors, and hyperscaler partners.

Location: RTP, Boston, Waltham

Job Requirements

  • Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications.
  • Perform technical gap and risk assessments across infrastructure, applications, and cloud engineering processes; monitor controls and advise owners on remediation.
  • Translate regulatory and compliance controls into clear, measurable engineering and security requirements.
  • Identify manual compliance activities for automation and partner with engineering and security teams on automated detection, remediation, evidence collection, and continuous monitoring.
  • Apply AI and related tooling to improve compliance workflows.
  • Align Engineering, SRE, Product, Cloud Security, Legal, Privacy, and Corporate Security teams and drive cross-functional initiatives to completion.
  • Partner with Microsoft Azure, Google Cloud, and Amazon Web Services on shared compliance and security objectives.
  • Manage auditor and assessor relationships and clearly present the organization’s technical security posture.
  • Improve policies, processes, security governance, and adoption of GRC tooling.

Required Qualifications

  • 6+ years building and managing security risk and compliance programs, including ownership of large cross-functional programs through certification.
  • Deep knowledge of ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP, with demonstrated ability to convert controls into engineering requirements.
  • Direct experience partnering with engineering teams to deliver technical outcomes.
  • Exceptional stakeholder management and ability to influence senior stakeholders and external partners without direct authority.
  • Strong technical fluency in AWS and Azure, Kubernetes, containers, virtual machines, identity and access control, network security, cryptography, logging and monitoring, incident response, DevOps, and CI/CD.
  • Familiarity with cloud security capabilities, SIEM, vulnerability scanning, cloud security posture management, and endpoint detection and response.
  • Product-oriented problem solving with the ability to investigate gaps, gather requirements, and drive solutions to completion.

Preferred Qualifications

  • Experience with FedRAMP, GovRAMP, CMMC, CJIS, and NIST 800-53/800-171.
  • Experience applying AI or large language model tooling to compliance workflows and familiarity with NIST AI RMF or ISO/IEC 42001.

Education

  • Bachelor’s or Master’s degree in Engineering, Computer Science, Information Technology, or a related field, or equivalent professional experience.
  • Professional certifications in security, compliance, or cloud are advantageous, including CISA, CISSP, CRISC, CCSK, CCSP, CIPP, AWS certifications, or ISO 27001 Lead Implementer / Lead Auditor.

Compensation:
The target salary range for this position is 129,200 - 192,500 USD. The salary offered will be determined by the candidate's location, qualifications, experience, and education and may be outside of this range. The range is based on 'On Target Earnings’ (OTE) representing the total potential earnings, which is the sum of the base salary and potential commission earned when performance targets are achieved. Final compensation packages are competitive and in line with industry standards, reflecting a variety of factors, and include a comprehensive benefits package. This may cover Health Insurance, Life Insurance, Retirement or Pension Plans, Paid Time Off, various Leave options, employee stock purchase plan, and/or restricted stocks (RSU’s). These offerings are subject to regional variations and governed by local laws, regulations, and company policies. We will provide detailed information about the specific benefits for your region during the recruitment process.

At NetApp, we embrace a hybrid working environment designed to strengthen connection, collaboration, and culture for all employees. This means that most roles will have some level of in-office and/or in-person expectations, which will be shared during the recruitment process.

Equal Opportunity Employer:

NetApp is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination based on age, race, color, gender, sexual orientation, gender identity, national origin, religion, disability or genetic information, pregnancy, protected veteran status, and any other protected classification.

Why You'll Thrive at NetApp

At NetApp, you won't wait for the perfect moment—you'll make it. The early planning, the extra thought, the bold idea that turns good into great: That's how our people operate and how we continue to push the boundaries of data infrastructure.

NetApp is the trusted partner for organizations transforming data into opportunity. As the only enterprise-grade storage service natively embedded in Google Cloud, AWS, and Microsoft Azure, we empower customers to run everything from traditional workloads to enterprise AI with unmatched performance, resilience, and security.

Our culture

We celebrate mold breakers, bold thinkers, and problem solvers. We reward initiative, impact, and ownership. We provide flexibility so you can balance professional ambition with your personal life. Here, differences are not just welcomed—they drive everything we do.

If you're ready to innovate, rise to the challenge, and own every moment - make your next move your best one. Apply now.

Submitting an Application

To ensure a streamlined and fair hiring process for all candidates, our team only reviews applications submitted through our company website. This practice allows us to track, assess, and respond to applicants efficiently. Emailing our employees, recruiters, or Human Resources personnel directly will not influence your application.

AI Disclosure

For select roles, some stages of our hiring process may use artificial intelligence tools to help evaluate applications and candidate selection. These tools support—rather than replace—human decision-making.

Apply

Jobs for you

Your recently viewed jobs will appear here.

You have no saved jobs. Start browsing jobs here

Recruitment scam warning

When conducting a job search, you’re bombarded with outreach. Here are tips to keep you safe from recruitment fraud.

Stay protected from job fraud

Equal Opportunity Employer*

NetApp is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination based on age, race, color, gender, sexual orientation, gender identity, national origin, religion, disability or genetic information, pregnancy, protected veteran status and any other protected classification. We pledge to take every reasonable step to ensure that our applicants and employees are respected, treated fairly and with dignity. See the EEO poster, Know your rights poster, and NetApp EEO policy. NetApp makes reasonable accommodations, consistent with applicable laws, for religious purposes and for the known physical or mental limitations of an otherwise qualified applicant or employee with a disability, who can perform the essential job functions unless undue hardship would result.

State-specific postings/notices to applicants regarding contract compliance can be found here in English and here in Spanish, and fair employment practice information can be found here.

Reasonable Accommodations

At NetApp, we are committed to fostering an inclusive and accessible workplace where individuals with disabilities can thrive. In alignment with our values, NetApp provides reasonable accommodations and adjustments where possible to qualified applicants and employees with disabilities, in accordance with employment rights and regulations relevant to their country of employment, to ensure equal access to employment opportunities and job performance.

Applicants who would like to request an accommodation or adjustment are encouraged to Contact Us. Each request will be assessed on a case-by-case basis, in accordance with applicable laws and our commitment to equity and belonging within our culture, values and business practices. Requests will be handled confidentially and respectfully, and we will work collaboratively to identify effective solutions.

  • For reasonable accommodations in Germany, click here.
  • For reasonable accommodations in France, click here.
  • For reasonable accommodations in The Netherlands, click here.

Please note that we do not accept unsolicited resumes to the above email address.

Data privacy

We care about your privacy and, therefore, ask that you read our Candidate Privacy Notice before you submit any personal information to us.

NetApp does not carry out any solely automated decision making (i.e. the process of making a decision by automated means without any human involvement) in determining your suitability or eligibility for specific roles.

However, the processing of your personal information is carried out with the aid of manual and automated tools. In particular, NetApp may use an automated employment evaluation tool or similar tool as one of several tools, actions, and/or steps to assist with NetApp’s review of candidate applications for various hiring needs.

Currently, when addressing certain hiring needs, NetApp uses the following tools: 

  • Eightfold (eightfold.ai): This tool can provide an initial ranking of a candidate’s skills and experience, based on information provided by the applicant in the application and/or supporting documentation, in comparison to the NetApp designated key requirements of a specific role. Additionally, the tool may be used to help review and/or rank internal employees seeking promotion or other internal mobility. An independent audit of the Eightfold Matching Model tool can be found at https://eightfold.ai/nyc-eightfoldmatching-model. 
  • Findem (findem.ai): This tool is used to help identify candidates whose skills and experience may be relevant to open roles at NetApp, using publicly available professional information. Findem may also be used to assist with candidate matching, AI-assisted screening, and recruitment communications. 

Our talent acquisition team or our recruiters will ultimately select the candidates for further consideration, following human review of any automated evaluation results and associated underlying documentation (or lack thereof) submitted with the candidates’ application. 

Candidates may request an alternative selection process which will not be subject to the Eightfold matching tool or to any electronic automated employment evaluation by contacting NetApp at careers@netapp.com. To bypass the Eightfold matching tool or any electronic automated employment evaluation, you must include a resume and job ID with your email to careers@netapp.com and you must include in the subject line of your email: Data Privacy Request. Candidates who have questions or want to request additional information on the source of data, type of data, and/or collection of data related to the candidate review process should contact NetApp at careers@netapp.com

Note: Eightfold is not applicable to temporary hiring opportunities. If you are interested in temporary roles, you can apply via a third-party site managed by our preferred supplier, Magnit Global. Magnit Global will provide its own privacy disclosures for your review as part of the application process.

Submitting an application

To ensure a streamlined and fair hiring process for all candidates, our team reviews apcplications submitted through our company website only. This practice allows us to track, assess, and respond to applicants efficiently. Emailing our employees, recruiters, or Human Resources personnel directly will not influence your application.

AI Disclosure

For select roles, some stages of our hiring process may use AI-powered tools to assist with tasks such as identifying relevant candidates, matching skills and experience to role requirements, and conducting initial screenings. These tools support - rather than replace - human decision-making. To learn more, please see our AI Transparency Statement. If you would prefer not to engage with an AI-assisted process, you can request an alternative by contacting careers@netapp.com. Choosing an alternative process will not impact your candidacy in any way.