1

Risk Governance Jobs (NOW HIRING)

Role Description As a Risk & Governance Manager at Dropbox, you will join the Governance, Risk, & Compliance (GRC) team, you will help mature and scale programs that enable Dropbox to make thoughtful ...

Lead Adobe's Security Risk and Governance program by advancing the security risk strategy through qualitative and quantitative analysis. Improve decision-making using security insights, data ...

Lead Adobe's Security Risk and Governance program by advancing the security risk strategy through qualitative and quantitative analysis. Improve decision-making using security insights, data ...

next page

Showing results 1-20

Risk Governance information

See salary details

$22.5K

$118.3K

$210K

How much do risk governance jobs pay per year?

As of Jun 9, 2026, the average yearly pay for risk governance in the United States is $118,258.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,500.00 and $145,000.00 per year, depending on experience, location, and employer.

How does a Risk Governance professional typically collaborate with various departments within an organization?

Risk Governance professionals work closely with multiple departments such as compliance, internal audit, finance, and operations to ensure that risk management frameworks are effectively implemented. They facilitate regular risk assessments, lead cross-functional meetings to discuss emerging risks, and help departments develop mitigation strategies. This collaborative approach ensures that risk-related policies are consistently applied and that all teams are aligned with the organization’s risk appetite and regulatory requirements.

What is risk governance?

Risk governance refers to the frameworks, processes, and structures that organizations use to identify, assess, manage, and communicate risks. It ensures that risks are handled systematically and in alignment with the organization's objectives and regulatory requirements. Effective risk governance involves oversight by leadership, clear roles and responsibilities, and transparent communication about risks. This approach helps organizations make informed decisions, maintain compliance, and protect their reputation.

What are the key skills and qualifications needed to thrive in Risk Governance, and why are they important?

To succeed in Risk Governance, you need a strong background in risk management principles, regulatory frameworks, and analytical skills, often supported by a degree in finance, business, or related fields. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as FRM or CRISC is highly valued. Excellent communication, critical thinking, and stakeholder management abilities help professionals influence decision-making and ensure organizational buy-in. These competencies are crucial for identifying, assessing, and mitigating risks to protect the organization's assets and reputation.

What is the difference between Risk Governance vs Risk Analyst?

AspectRisk GovernanceRisk Analyst
Primary FocusEstablishing policies, frameworks, and oversight for risk managementIdentifying, analyzing, and assessing specific risks
CertificationsISO 31000, FRM, CRM often preferredFRM, CRM, or related certifications common
Work EnvironmentStrategic, policy-driven, often in senior or managerial settingsOperational, data-driven, often in teams or departments
Employer & Industry UsageFinancial institutions, corporations, regulatory bodiesFinancial firms, consulting, insurance, banking

Risk Governance focuses on creating and maintaining risk management frameworks and policies, ensuring organizational compliance and oversight. Risk Analysts, on the other hand, perform detailed risk assessments and data analysis to inform decision-making. Both roles are essential but differ in scope and responsibilities.

More about Risk Governance jobs
What cities are hiring for Risk Governance jobs? Cities with the most Risk Governance job openings:
What states have the most Risk Governance jobs? States with the most job openings for Risk Governance jobs include:
Infographic showing various Risk Governance job openings in the United States as of June 2026, with employment types broken down into 1% Internship, 3% As Needed, 67% Full Time, 24% Part Time, and 5% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $118,258 per year, or $56.9 per hour.
Risk & Governance Manager

Full-time

Posted yesterday


Job description

Role Description
As a Risk & Governance Manager at Dropbox, you will join the Governance, Risk, & Compliance (GRC) team, you will help mature and scale programs that enable Dropbox to make thoughtful, risk-informed decisions. This is a broad, cross-functional role supporting multiple areas of the GRC program, including enterprise risk management, AI governance, business resilience, third-party risk, internal controls, audit readiness, and risk reduction initiatives.
You will partner closely with teams across Security, Privacy, Engineering, Product, Legal, and Compliance to identify, assess, prioritize, and reduce risk across Dropbox's products, services, and operations. This role is ideal for someone who enjoys working across domains, can bring structure to ambiguous problems, and is comfortable translating complex technical, regulatory, and business considerations into practical governance programs.
Additionally, you will be responsible for implementing programs and controls to help us maintain user trust and adhere to Dropbox's AI principles and trust policies. You will help both Dropbox and our customers make informed decisions about the use of AI products and services.
Responsibilities
Governance Program Management
  • Support the design, implementation, and continuous improvement of Dropbox's Governance, Risk, and Compliance programs, including quantitative risk management (FAIR), governance, controls, compliance readiness, issue management, and risk reporting.
  • Plan and execute risk assessments, gap analyses, certification readiness activities, compliance reviews, and audit support processes across areas such as security, privacy, AI, reliability, third-party services, and operational risk.
  • Partner with cross-functional stakeholders to identify risks, assess impact and likelihood, define mitigation plans, assign owners, and track risk reduction efforts through completion.
  • Drive risk reduction projects that strengthen Dropbox's control environment, improve operational maturity, and help teams make risk-informed decisions.
  • Coordinate improvements to internal risk management systems, workflows, documentation, reporting, and policies to increase consistency, transparency, and program effectiveness.
  • Collaborate with internal and external auditors throughout compliance engagements, including evidence collection, stakeholder coordination, gap remediation, and management reporting.
  • Support risk reviews of third-party service providers and help connect third-party findings to broader enterprise risk, compliance, and customer trust objectives.
  • Lead or support complex, cross-functional governance initiatives, such as software asset management, control rationalization, audit readiness, or risk remediation programs.
  • Play an active role in risk incident readiness and response by helping teams prepare for, mitigate, respond to, recover from, and learn from risk events.

AI Governance
  • Help implement, maintain, and mature programs that support Dropbox's AI governance framework, company AI Principles, legal and regulatory obligations, and customer trust commitments.
  • Partner with Product, Engineering, Security, Privacy, Legal, Compliance, and business teams to assess AI use cases and define practical governance requirements for intake, documentation, review, approval, monitoring, and issue remediation.
  • Support AI risk assessments that consider security, privacy, transparency, reliability, misuse, bias and fairness, data governance, compliance, and operational risk.
  • Translate emerging AI regulatory, ethical, and industry expectations into scalable internal policies, standards, controls, and operating practices.
  • Develop metrics, KPIs, dashboards, and reporting to communicate AI governance maturity, risk posture, compliance status, and remediation progress to stakeholders and leadership.
  • Provide risk-informed guidance to stakeholders and leadership on AI governance decisions, policy updates, regulatory developments, and responsible AI practices.

Business Resilience and Operational Risk
  • Support Dropbox's business resilience program, including business continuity planning, business impact assessments, tabletop exercises, incident readiness, recovery planning, and after-action reviews.
  • Partner with key teams to identify critical services, dependencies, operational risks, continuity requirements, and resilience gaps.
  • Drive or support tabletop exercises and scenario-based reviews for key teams, helping document lessons learned, owners, timelines, and follow-up actions.
  • Track resilience risks and remediation activities, escalating themes, blockers, and emerging risks to appropriate stakeholders or governance forums.
  • Help connect business resilience work to broader risk management, compliance, customer trust, audit readiness, and incident response objectives.
Requirements
  • 7+ years of experience building or maintaining risk, governance, compliance, audit, business resilience, security, privacy, or related programs
  • Experience at a publicly traded, fast paced SaaS company
  • Experience managing and reducing AI, security, privacy, or reliability risks
  • Knowledge of FAIR quantitative risk methodologies
  • Familiarity with a broad range of technical concepts relevant to cloud computing and SaaS environments: logical access, agile development process, security architecture, information security, network security, and privacy
  • Strong project management and organizational skills
  • Collaborative working style and strong relationship-building skills, with the ability to work effectively with both technical and non-technical teams
  • Excellent writing, communication, organizational skills, and strong attention to detail
  • Ability to confidently convey nuanced information to senior leaders
  • Related professional certifications such as AIGP (AI Governance Professional) or CIPP (Certified Information Privacy Professional) preferred
Preferred Qualifications
  • Deep subject matter knowledge in AI governance, security, privacy, or reliability risk, i.e. sufficient technical knowledge to have effective conversations with Dropbox engineers
  • Self starter and ability to navigate ambiguity, proven history of owning and delivering a project end-to-end, has strong Executive presence
  • Experience completing complex cross-functional projects that can turn into self-sustaining programs as part of a risk team
Compensation
US Zone 1
This role is not available in Zone 1
US Zone 2
$160,700-$217,300 USD
US Zone 3
$142,800-$193,200 USD