As a Senior Governance & Risk Compliance Program Manager on the Governance, Risk, & Compliance team, you will play a crucial role in building Compliance across our product set.
Protecting Dropbox and our users is critical to being worthy of trust. As a Compliance Program Manager at Dropbox, you will join a growing team to design, implement, and coordinate programs to promote user trust and manage risks to their data. You will work with teams across the organization, including Engineering, Product, Design, and Sales, in order to manage risks to Dropbox and users alike. You will work in depth with other parts of the business to ensure Dropbox meets our security, privacy, and regulatory commitments.
If you are passionate about protecting Dropbox and our users, are looking for an opportunity to stretch and grow yourself in a dynamic team, and thrive in an environment where you can constantly learn, then this role is for you.
Responsibilities- Promote and foster a culture of trust within and outside of Dropbox.
- Partner with teams to execute on cross-team and/or multi-phase projects from design through implementation against a wide variety of regulatory and compliance frameworks, especially AI-specific standards/frameworks
- Identify the right solutions to clarify and solve ambiguous, open-ended problems across various compliance programs.
- Mature our overall compliance program. Improve and implement controls for internal systems, processes, and policies through bold and innovative approaches and leveraging automation and AI-enabled processes
- Facilitate ongoing AI Governance, Risk and Compliance initiatives and monitor control effectiveness.
- Collaborate with internal teams and external auditors throughout compliance assessments.
- Play an active part in responding and mitigating compliance challenges across multiple time zones and jurisdictions.
- Drive automation efforts across the Compliance function via the AI-enabled GRC automation tools
- Identify opportunities impacting the Compliance function and establish the strategy and cross-functional alignment to achieve these objectives.
- Conduct gap assessments to identify areas of non-compliance or areas for improvement, and develop action plans to address these gaps.
- Provide guidance to management on the impact of new laws and regulations and recommend changes in business practices where necessary.
- 7+ years of experience building or maintaining programs to mitigate risks around security, confidentiality, integrity, availability, and privacy
- Independently leads cross-team and/or multi-phase projects from design through implementation
- Identifies the right solutions to clarify and solve ambiguous, open-ended problems
- Consistently utilize AI tools to enhance workflows, evaluate outputs with critical judgment, and help others adopt tools where appropriate.
- Experience facilitating or being the subject of SOC, ISO, HIPAA and/or PCI audits at a fast-paced technology company, public accounting firm, or similar environment
- Experience partnering with Engineering, Product, & Development teams to define compliance needs in a multi-product environment
- Strong familiarity with a broad range of technical concepts relevant to cloud computing environments: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy
- Experience with implementing compliance programs for emerging new products, including AI enabled products
- Strong understanding of cloud-based technologies and their implications for governance, risk, and compliance, with a focus on AI compliance needs
- Strong project management and organizational skills - must drive your own projects to completion with high-level direction from a manager, while also fostering collaboration and bringing teams together to achieve common objectives.
- Great people skills and ability to work well in fast paced team environment with a wide range of technical and non-technical teams
- Excellent writing, communication, and organizational skills - strong attention to detail
- Passion to aim higher and develop new skills
- CISA, CISSP, CCSK, CIPP, or other professional certifications/associations required
- Experience in scaling compliance programs within high-growth technology environments — Demonstrated ability to design, implement, and mature compliance frameworks in dynamic, fast-paced organizations where systems, processes, and regulatory expectations evolve rapidly.
- Moderate technical fluency to partner effectively with engineering and product teams — Ability to translate compliance requirements into actionable technical solutions, with working knowledge of cloud infrastructure, data privacy, security/AI controls.
- Executive communication and stakeholder management skills — Proven ability to distill complex compliance and regulatory topics into clear, actionable insights for senior leaders, while fostering alignment across technical and non-technical stakeholders.
US Zone 1
This role is not available in Zone 1
Skills Required
- 7+ years building or maintaining programs to mitigate risks around security, confidentiality, integrity, availability, and privacy
- Independently lead cross-team and/or multi-phase projects from design through implementation
- Ability to identify solutions for ambiguous, open-ended compliance problems
- Consistently utilize AI tools to enhance workflows and evaluate outputs with critical judgment
- Experience facilitating or being the subject of SOC, ISO, HIPAA and/or PCI audits at a technology company, public accounting firm, or similar environment
- Experience partnering with Engineering, Product, and Development teams to define compliance needs in a multi-product environment
- Strong familiarity with cloud-relevant technical concepts: logical access control, secure coding principles, security architecture, information and network security, and privacy
- Experience implementing compliance programs for emerging products, including AI-enabled products
- Strong project management and organizational skills; drive projects to completion with high-level direction
- Excellent writing, communication, and interpersonal skills; ability to work across technical and non-technical teams in fast-paced environments
- CISA, CISSP, CCSK, CIPP, or other professional certifications/associations required
- Experience scaling compliance programs in high-growth technology environments
- Moderate technical fluency to translate compliance requirements into technical solutions for engineering/product teams
- Executive communication and stakeholder management skills to present complex compliance topics to senior leaders
Dropbox Compensation & Benefits Highlights
How does Dropbox ensure its pay and bonus plans are competitive?
Dropbox ensures base pay and bonuses are competitive by benchmarking pay using formal compensation surveys to create salary ranges and bonus targets, and conducting twice-yearly reviews aligned with performance.
Employees describe pay and bonuses as competitive and performance-driven.
Dropbox Insights
What We Do
We're a global community of bold visionaries and resourceful doers who are shaping the future of Dropbox—and with it the future of work. Our Virtual First model combines the flexibility of a distributed workplace with the power of human connection, making space for both meaningful work and meaningful relationships. With our start-up mindset and enterprise-level opportunities, you can be who you are and grow into who you’re meant to be. Here, you can own your impact to make work more intuitive, joyful, and human—for you as a Dropboxer and for hundreds of millions of people worldwide. If you're ready to push boundaries—and yourself—Dropbox is ready for you.
Why Work With Us
We believe people do their best work when empowered with autonomy and harmony, and we understand there’s no substitute for human connection. Our Virtual First model combines the flexibility of remote work with the power of in-person collaboration to create the best of both worlds: a distributed workplace, anchored in community.
Gallery
Dropbox Offices
Remote Workspace
Employees work remotely.
While remote work is the primary experience for our employees, we also prioritize opportunities for quarterly in-person collaboration knowing that connection is vital to a thriving workforce. We focus on how we work, not where we work.










