Enterprise Risk Program Manager

Posted 2 Days Ago
Be an Early Applicant
4 Locations
Senior level
Cloud • Information Technology • Machine Learning
We empower creators and innovators with access to GPU resources they need to work more efficiently.
The Role
The Enterprise Risk Program Manager at CoreWeave will lead the Enterprise Risk Engineering Management program by fostering a risk-informed culture, conducting periodic risk assessments, managing compliance with frameworks, and supporting governance initiatives. The role involves collaboration with various internal stakeholders, tracking risks and mitigation plans, and maintaining risk program documentation.
Summary Generated by Built In

CoreWeave is the AI Hyperscaler™, delivering a cloud platform of cutting edge services powering the next wave of AI. Our technology provides enterprises and leading AI labs with the most performant, efficient and resilient solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers covering every region of the US and across Europe. CoreWeave was ranked as one of the TIME100 most influential companies of 2024.

As the leader in the industry, we thrive in an environment where adaptability and resilience are key. Our culture offers career-defining opportunities for those who excel amid change and challenge. If you’re someone who thrives in a dynamic environment, enjoys solving complex problems, and is eager to make a significant impact, CoreWeave is the place for you. Join us, and be part of a team solving some of the most exciting challenges in the industry.  

CoreWeave powers the creation and delivery of the intelligence that drives innovation. 

What you’ll do

  • Drive the Enterprise Risk Engineering Management (ERM) program by fostering a risk informed culture and regularly assessing exposures, identifying gaps, and supporting issues management resolution
  • Support the maturity of the ERM Program through assisting with the development of foundational and governance elements including standards, systems, tools, policies, workflows, and communications
  • Execute periodic control and engineering risk assessments against the multiple compliance frameworks we currently align to and may align to in the future (SOX, SOC 2, ISO 27001:2022, FedRAMP, etc.)
  • Assist in maintaining the documentation, prioritization, and tracking of items such as the company risk register and exceptions process
  • Perform analysis on regulatory changes, or organization changes, that may impact our Information Security requirements
  • Perform periodic Business Impact Analysis (BIA) assessments to support Business Continuity and Disaster Recovery programs
  • Work closely with internal stakeholders (Corporate IT, Legal, HR, Audit, and Product Team Members) on governance/compliance initiatives and enhancements to the monitoring of security controls
  • Provide ad-hoc risk consultation to executives, leaders and internal stakeholders to help manage risks in pursuit of business and strategic objectives
  • Act as a program manager, by developing and tracking risk register items and audit corrective action plans through remediation
  • Develop automated, repeatable and sustainable risk program registration, tracking and reporting program capabilities
  • Maintain the appropriate KPIs and KRIs related to an Enterprise Risk program
  • Review risk reporting, including but not limited to the status of key risks and related trends, the effectiveness of controls and responses/mitigation, key risk indicators, and exceptions, etc
  • Maintain and monitor ERM program policies and procedures
  • Maintain and mature GRC tool used to track risks, exceptions and remediation plans

Investing in our people is one of our top priorities, and we value candidates who can bring their diversified experiences to our teams. Here are some qualities we’ve found compatible with our team. We'd love to talk about whether this aligns with your experience and Interests and what you’re excited to work on next.

Minimum Qualifications

  • Bachelor's in Information Security, Computer Science, or related degree; Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) Certification or equivalent
  • Minimum of 5+ years work experience in IT/Security Compliance/Audit function (or equivalent)
  • Proven experience in compliance, risk management and/or IT security program management
  • In-depth knowledge of the industry's standards and regulations as well as common control sets (e.g. SOX, SOC 2, ISO 27001:2022, ISO 27701, NIST 800-53, NIST CSF, FedRAMP, GDPR and HIPAA)
  • In-depth understanding of concepts related to information security domains such as Cloud Computing, Physical Security, Third Party Risk Management (TPRM), Identity and Access Management, Data Security, Vulnerability and Patch Management, Malware Defenses, CIS Top 18 Controls
  • Strong relationship-building and interpersonal skills, needed to help influence decision makers and technology owners
  • Integrating new technologies into existing technology portfolios
  • Collaborating with cross-functional teams, including engineering, network and infrastructure
  • Excellent knowledge of reporting procedures and record-keeping
  • Ability to succeed in a team environment or work as an individual contributor

Preferred Qualifications

  • Strong understanding of GRC programs for cloud providers
  • Self-starter and requires minimal direction from leadership
  • Methodical and diligent with outstanding planning abilities
  • Able to meet deadlines and handle multiple priorities
  • Strong ability to negotiate with business partners to attain successful outcomes
  • Excellent communication skills
  • Strong project management skills with the ability to manage several large projects at the same time, keeping them on scope, on budget and on time
  • Ability to present and effectively communicate with all levels of the organization
  • Flexible with the ability to multitask, effectively prioritize and work under pressure
  • Advocate of continuous improvement and industry recognized best practice

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $130,000-$155,000. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.

What We Offer

The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.

In addition to a competitive salary, we offer a variety of benefits to support your needs, including:

  • Medical, dental, and vision insurance - 100% paid for by CoreWeave
  • Company-paid Life Insurance 
  • Voluntary supplemental life insurance 
  • Short and long-term disability insurance 
  • Flexible Spending Account
  • Health Savings Account
  • Tuition Reimbursement 
  • Mental Wellness Benefits through Spring Health 
  • Family-Forming support provided by Carrot
  • Paid Parental Leave 
  • Flexible, full-service childcare support with Kinside
  • 401(k) with a generous employer match
  • Flexible PTO
  • Catered lunch each day in our office and data center locations
  • A casual work environment
  • A work culture focused on innovative disruption

Our Workplace

At CoreWeave, we are committed to operating as a hybrid workplace, offering employees flexibility in how they structure their time between in-office and remote work. We recognize the significance of fostering connections, collaboration, and creativity within our office culture and its positive impact on our business. Our philosophy operating as a hybrid workplace underscores our dedication to enabling employees to tailor work-life balance to their individual preferences.

For those who do not live within 30 miles of one of our offices, we are open to considering remote work for candidates whose skills and experience strongly align with the role. While we prioritize a hybrid work environment for most roles, we understand the importance of flexibility and are open to remote work for specific positions and specialized skill sets. Onboarding is essential to your success. New employees not based out of an office will be invited to attend onboarding training at one of our hubs within their first month of employment. We continue to foster a collaborative environment by bringing teams together quarterly.


California Consumer Privacy Act - California applicants only

CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.

As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: [email protected].

Top Skills

Information Security

What the Team is Saying

Alex
Andy
Sasha
Louis
Taylor
Anthony
Ivy
Darrell
Yitzy
Nicolas
Vaibhav
Robert
The Company
HQ: Roseland, NJ
806 Employees
Hybrid Workplace
Year Founded: 2017

What We Do

CoreWeave, the AI Hyperscaler™, delivers a cloud platform of cutting-edge software powering the next wave of AI. The company's technology provides enterprises and leading AI labs with cloud solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers across the US and Europe. CoreWeave was ranked as one of the TIME100 most influential companies and featured on Forbes Cloud 100 ranking in 2024. Learn more at www.coreweave.com.

Why Work With Us

At CoreWeave we work hard, have fun and move fast! Today we are a small, growing team of intelligent, genuine people, that value different perspectives and approaches to solving complex problems. We foster an environment that champions collaboration and prioritizes innovative solutions. Here, you are surrounded by the best.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

CoreWeave Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
HQRoseland, NJ
Bellevue, WA
Brooklyn, NY
London, UK
Philadelphia, PA
Sunnyvale, CA
Learn more

Similar Jobs

CoreWeave Logo CoreWeave

Senior Application Security Engineer

Cloud • Information Technology • Machine Learning
4 Locations
806 Employees

CoreWeave Logo CoreWeave

Tech Lead Manager, PKI & Secrets Engineering

Cloud • Information Technology • Machine Learning
4 Locations
806 Employees

CoreWeave Logo CoreWeave

Senior Detection and Response Engineer

Cloud • Information Technology • Machine Learning
4 Locations
806 Employees

CoreWeave Logo CoreWeave

Senior Security Manager, Vulnerability Management

Cloud • Information Technology • Machine Learning
4 Locations
806 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account