PitchMeAI
Dropbox

Governance, Risk, & Compliance Program Manager

Dropbox · United States

  • Hybrid
  • Full-time
  • $150,000 / year
  • United States

Job highlights

  • Manage compliance programs across Dropbox products.
  • Design and implement risk management programs.
  • Collaborate with Engineering, Product, and Sales teams.
  • Ensure adherence to security, privacy, and regulatory commitments.
  • Drive automation in compliance functions using AI.

About the role

About Dropbox

Dropbox isn’t just a workplace—it’s a living lab for more enlightened ways of working. We're a global community of bold visionaries and resourceful doers who are shaping the future of Dropbox—and with it the future of work. Our Virtual First model combines the autonomy of a distributed workplace with the power of human connection, making space for both meaningful work and meaningful relationships. With our start-up mindset and enterprise-level opportunities, you can be who you are and grow into who you’re meant to be. Here, you can own your impact to make work more intuitive, joyful, and human—for you as a Dropboxer and for hundreds of millions of people worldwide. If you're ready to push boundaries—and yourself— Dropbox is ready for you.

About the Team

The Dropbox Legal, Policy, Trust & Privacy Team safeguards our company to enable innovation while protecting our users, platform, and business. Our team navigates complex challenges at the intersection of technology and law, embracing agility to tackle the changing landscape while ensuring compliance and integrity. From governance to risk, compliance to public policy, we combine creative problem-solving with legal expertise to help our employees and users work securely, drive responsible growth, and shape the future of policy around technology. If you're excited about protecting trust in the digital age, join our Legal team. Areas of work include Governance, Risk, Compliance, Public Policy, Privacy, Intellectual Property, Commercial Contracts, Employment Law, and Regulatory Affairs.

Role Description

As a Compliance Program Manager on the Governance, Risk, & Compliance team, you will play a crucial role in building Compliance across our product set.

Protecting Dropbox and our users is critical to being worthy of trust. As a Compliance Program Manager at Dropbox, you will join a growing team to design, implement, and coordinate programs to promote user trust and manage risks to their data. You will work with teams across the organization, including Engineering, Product, Design, and Sales, in order to manage risks to Dropbox and users alike. You will work in depth with other parts of the business to ensure Dropbox meets our security, privacy, and regulatory commitments.

If you are passionate about protecting Dropbox and our users, are looking for an opportunity to stretch and grow yourself in a dynamic team, and thrive in an environment where you can constantly learn, then this role is for you.

Responsibilities

  • Promote and foster a culture of trust within and outside of Dropbox.
  • Partner with teams to execute on cross-team and/or multi-phase projects from design through implementation against a wide variety of regulatory and compliance frameworks, especially AI-specific standards/frameworks
  • Identify the right solutions to clarify and solve ambiguous, open-ended problems across various compliance programs.
  • Mature our overall compliance program. Improve and implement controls for internal systems, processes, and policies through bold and innovative approaches and leveraging automation and AI-enabled processes
  • Facilitate ongoing AI Governance, Risk and Compliance initiatives and monitor control effectiveness.
  • Collaborate with internal teams and external auditors throughout compliance assessments.
  • Play an active part in responding and mitigating compliance challenges across multiple time zones and jurisdictions.
  • Drive automation efforts across the Compliance function via the AI-enabled GRC automation tools
  • Identify opportunities impacting the Compliance function and establish the strategy and cross-functional alignment to achieve these objectives.
  • Conduct gap assessments to identify areas of non-compliance or areas for improvement, and develop action plans to address these gaps.
  • Provide guidance to management on the impact of new laws and regulations and recommend changes in business practices where necessary

Requirements

  • 4+ years of experience building or maintaining programs to mitigate risks around security, confidentiality, integrity, availability, and privacy
  • Independently executes and manages projects with high-level direction from a manager
  • Consistently utilize AI tools to enhance workflows, evaluate outputs with critical judgment, and help others adopt tools where appropriate.
  • Experience facilitating or being the subject of SOC, ISO, HIPAA and/or PCI audits at a fast-paced technology company, public accounting firm, or similar environment
  • Experience partnering with Engineering, Product, & Development teams to define compliance needs in a multi-product environment
  • Moderate familiarity with a broad range of technical concepts relevant to cloud computing environments: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy
  • Experience with implementing compliance programs for emerging new products, including AI enabled products
  • Moderate understanding of cloud-based technologies and their implications for governance, risk, and compliance, with a focus on AI compliance needs
  • Strong project management and organizational skills - must drive your own projects to completion with high-level direction from a manager, while also fostering collaboration and bringing teams together to achieve common objectives.
  • Great people skills and ability to work well in fast paced team environment with a wide range of technical and non-technical teams
  • Excellent writing, communication, and organizational skills - strong attention to detail
  • Passion to aim higher and develop new skills
  • CISA, CISSP, CCSK, CIPP, or other professional certifications/associations required

Preferred Qualifications

  • Experience in scaling compliance programs in high-growth technology company

Compensation

  • US Zone 2: $135,400—$183,200 USD
  • US Zone 3: $120,400—$162,800 USD

The range(s) listed above is the expected annual salary/OTE (On-Target Earnings) for this role, subject to change. Please note, OTE are for sales roles only. Salary/OTE is just one component of Dropbox’s total rewards package. All regular employees are also eligible for the corporate bonus program or a sales incentive (target included in OTE) as well as stock in the form of Restricted Stock Units (RSUs). Dropbox takes a number of factors into account when determining individual starting pay, including job and level they are hired into, location/metropolitan area, skillset, and peer compensation. We target most new hire offers between the minimum up to the middle of the range. Dropbox uses the zip code of an employee’s remote work location to determine which metropolitan pay range we use.

Benefits

Dropbox is committed to investing in the holistic health and wellbeing of all Dropboxers and their families. Our benefits and perks programs include, but are not limited to:

  • Competitive medical, dental, and vision coverage
  • 401(k) plan with a generous company match and immediate vesting
  • Flexible PTO/Paid Time Off, paid holidays, Volunteer Time Off, and more, allowing you time to unplug, unwind, and refresh
  • Income Protection Plans: Life and disability insurance
  • Business Travel Protection: Travel medical and accident insurance
  • Perks Allowance to be used on what matters most to you, whether that’s wellness, learning and development, food and groceries, and much more
  • Parental benefits including: Parental Leave, Child and Adult Care, Day Care FSA, Fertility Benefits, Adoption and Surrogacy Support, and Lactation Support
  • Access to over 10,000 global co-working spaces through Gable.tomaking it easy to book flexible workspaces for collaboration or individual work
  • Quarterly Cell phone and internet allowance
  • Mental health and wellness benefits
  • Disability and neurodivergence support benefits

Additional benefit details are available upon request.

Dropbox supports responsible use of AI for preparation, but misrepresentation of skills or experience is not permitted. See our AI philosophy.

Dropbox is an equal opportunity employer. We are a welcoming place for everyone, and we do our best to make sure all people feel supported and connected at work. A big part of that effort is our support for members and allies of internal groups like Asians at Dropbox, BlackDropboxers, enABLE, TODOS (Latinx), Pridebox (LGBTQ), Vets at Dropbox, and Women at Dropbox.

Key skills/competency

  • Governance
  • Risk Management
  • Compliance
  • Program Management
  • AI Governance
  • Cloud Computing
  • Regulatory Frameworks
  • Auditing
  • Project Management
  • Information Security

Skills & topics

  • Governance
  • Risk Management
  • Compliance
  • Program Manager
  • GRC
  • AI Governance
  • Cloud Compliance
  • Information Security
  • Regulatory Affairs
  • Data Privacy
  • SOC
  • ISO
  • HIPAA
  • PCI
  • Project Management
  • CISA
  • CISSP
  • CIPP
  • US Zone 2
  • US Zone 3
  • Virtual First

How to get hired

  • Tailor your resume: Highlight your 4+ years in risk mitigation, program management, and experience with SOC, ISO, HIPAA, or PCI audits. Emphasize AI tool utilization and cloud computing knowledge.
  • Craft a compelling cover letter: Express your passion for user trust and data protection at Dropbox. Clearly articulate how your skills align with building compliance programs for emerging products, especially AI.
  • Prepare for technical questions: Be ready to discuss your experience with cloud computing environments, security principles, and AI compliance needs. Showcase your understanding of regulatory frameworks.
  • Demonstrate your soft skills: Highlight your project management, organizational, and communication abilities. Provide examples of how you've worked effectively with cross-functional teams and driven projects to completion.
  • Research Dropbox's culture: Understand their Virtual First model, commitment to trust, and use of AI. Align your answers with their values of innovation and bold thinking.

Technical preparation

Master cloud security principles and AI compliance.,Practice facilitating SOC, ISO, HIPAA, PCI audits.,Learn to use AI GRC automation tools.,Understand technical concepts for cloud environments.

Behavioral questions

Describe a complex compliance problem you solved.,How do you foster a culture of trust?,Share an experience managing cross-functional projects.,How do you handle ambiguity and drive solutions?

Frequently asked questions

What is the salary range for a Governance, Risk, & Compliance Program Manager at Dropbox in US Zone 2?
For a Governance, Risk, & Compliance Program Manager role at Dropbox in US Zone 2, the expected annual salary range is $135,400 to $183,200 USD. This range is subject to change and is part of a total rewards package that includes corporate bonuses and stock options.
What are the key responsibilities of a Compliance Program Manager at Dropbox?
As a Compliance Program Manager at Dropbox, your key responsibilities include designing and implementing programs to promote user trust and manage data risks, partnering with Engineering, Product, and Sales teams to ensure compliance with security, privacy, and regulatory commitments, and driving automation efforts within the Compliance function using AI-enabled tools.
What specific technical skills are required for the Governance, Risk, & Compliance Program Manager role at Dropbox?
The role requires at least 4 years of experience in risk mitigation programs, familiarity with cloud computing environments (logical access control, agile development, secure coding, etc.), and a moderate understanding of AI compliance needs. Experience with SOC, ISO, HIPAA, or PCI audits is also essential.
Does Dropbox hire for remote roles, and how is location determined for pay?
Dropbox operates on a Virtual First model, offering remote work opportunities. The specific pay range for a role is determined by the employee's zip code, which is used to assign them to a 'Zone' (US Zone 1, 2, or 3) corresponding to different metropolitan pay ranges.
What professional certifications are required for the Governance, Risk, & Compliance Program Manager position at Dropbox?
Candidates for the Governance, Risk, & Compliance Program Manager role must hold a CISA, CISSP, CCSK, CIPP, or other relevant professional certification/association.
How does Dropbox approach the use of AI in its hiring and work processes?
Dropbox supports the responsible use of AI for preparation and work enhancement. Candidates are expected to consistently utilize AI tools to improve workflows and critically evaluate outputs. However, misrepresentation of skills or experience is not permitted. Their AI philosophy guides this approach.
What does Dropbox's total rewards package include beyond base salary?
Beyond the base salary, Dropbox's total rewards package includes eligibility for a corporate bonus program, stock in the form of Restricted Stock Units (RSUs), and other benefits such as competitive health coverage, a 401(k) with company match, and flexible PTO.
What is the company culture like at Dropbox for a Governance, Risk, & Compliance Program Manager?
Dropbox fosters a culture of trust, innovation, and growth within its Virtual First model. The Legal, Policy, Trust & Privacy team, in particular, navigates complex challenges at the intersection of technology and law, encouraging creative problem-solving and continuous learning.