Himalayas logo
KongKO

Compliance Program Manager

Speed up time to market by unleashing developer productivity, automating security, and streamlining API management.

Kong

Employee count: 201-500

India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Are you ready to power the World's connections?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

Role Summary

This senior individual contributor with program ownership responsibility is a high-impact role supporting customer trust, audits, and revenue enablement. The Compliance Program Manager is responsible for customer-facing security and compliance assurance for a designated Kong product, while also owning the PCI-DSS compliance program and certification lifecycle for that product.

This role acts as the primary Subject Matter Expert (SME) for customer assurance, audit readiness, and PCI-DSS controls, partnering closely with Engineering, SRE, Product, Legal, and Compliance teams. The role is critical to maintaining customer trust, supporting sales motions, and ensuring ongoing regulatory and industry compliance.

Key Responsibilities

  • Manage the end-to-end PCI DSS compliance program, ensuring adherence to the latest v4.0 standards.

  • Conduct regular internal assessments and readiness reviews for Reports on Compliance (ROC).

  • Serve as the Customer Assurance SME for one assigned Kong product (Dedicated Cloud Gateways).

  • Support all customer assurance requests for the assigned product, including security questionnaires, due diligence reviews and compliance inquiries

  • Attend customer calls as required to explain the product’s security posture, compliance controls, and audit status.

  • Ensure responses are accurate, consistent, and aligned with approved Kong messaging.

  • For customer assurance requests involving multiple Kong products, collaborate with other product SMEs to deliver coordinated, consistent and high-quality responses

  • Ensure alignment between product-specific responses and Kong’s broader security and compliance posture.

  • Cater to audit evidence requirements for the assigned product.

  • Partner with the Compliance Program Manager and internal stakeholders to ensure ongoing audit readiness for frameworks such as ISO 27001, SOC 2 Type II.

  • Validate that security and compliance controls are documented, implemented, and supported by appropriate evidence.

  • Drive the implementation of security and compliance best practices across the assigned product.

  • Foster strong cross-functional collaboration across Security, Engineering, SRE, Product, Legal, and Sales teams.

  • Promote secure-by-design and compliance-by-design principles in product development and operations.

  • Identify control gaps and drive remediation efforts with Engineering and Product teams.

  • Participate in cross-training initiatives with other Customer Assurance and Compliance SMEs.

PCI-DSS Program Ownership (Product-Specific)

  • Own end-to-end PCI-DSS compliance for the assigned Kong product, including:

    • Scope definition and validation

    • Control implementation and documentation

    • Evidence collection and maintenance

    • Annual PCI-DSS assessments and certification

  • Act as the primary point of contact for PCI-related matters, including:

    • Internal stakeholders

    • Qualified Security Assessors (QSAs)

    • Customer PCI inquiries

  • Ensure PCI controls are embedded into product architecture and operational processes.

  • Track PCI requirements, changes, and remediation activities to maintain continuous compliance.

Required Qualifications

  • 8+ years of experience in Customer Assurance, Security Compliance, GRC, or Trust roles

  • Demonstrated experience owning end-to-end PCI-DSS compliance programs

  • Experience supporting customer-facing security and compliance engagements

  • Prior experience working in SaaS, cloud, or infrastructure platforms

  • Strong hands-on knowledge of PCI-DSS

  • Experience managing audits, assessments, and evidence collection

  • Understanding of shared responsibility models and cloud security controls

  • Understanding of APIs, cloud-native architectures, or platform security is a strong plus

  • Excellent written and verbal communication skills

  • Ability to translate complex compliance requirements into customer- and engineer-friendly language

  • Comfortable engaging with enterprise customers, auditors and QSAs, and internal leadership and cross-functional teams

  • Bachelor’s degree in Information Security, Computer Science, or a related field, or equivalent practical experience

  • PCI Professional (PCIP), PCI Internal Security Assessor (ISA), CISSP, CISA, CRISC, or ISO 27001 certifications preferred but not mandatory

About Kong:

Kong Inc., a leading developer of cloud API technologies, is on a mission to enable companies around the world to become “API-first” and securely accelerate AI adoption. Kong helps organizations globally — from startups to Fortune 500 enterprises — unleash developer productivity, build securely, and accelerate time to market. For more information about Kong, please visit www.konghq.com or follow us on X @thekonginc.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Manager

Location requirements

Hiring timezones

India +/- 0 hours

About Kong

Learn more about Kong and their company culture.

View company profile

Speed up time to market by unleashing developer productivity, automating security, and streamlining API management.

Kong powers the API world

Kong provides the foundation that enables any company to become an API-first company — speeding up time to market, creating new business opportunities, and delivering superior products and services.

Built on the world’s most adopted API gateway, Kong’s unified cloud API platform delivers fast, reliable, secure digital experiences. With Kong, organizations can increase developer productivity, security, and performance at scale with a single easy-to-use platform for API management, service mesh, and ingress controller.

We put customers at the heart of everything we do. That’s why everyone from e-commerce startups to the world’s leading biotech companies trust Kong to run mission-critical applications.

We embody open source and everything it stands for. We foster a culture of individualism — encouraging our people to bring new ideas and innovations, regardless of level and function.

How we do it

We’re passionate about solving the challenges that will fundamentally shape the future of tech. If you believe in taking ownership of your work, making an impact, and having fun along the way, come join us!

Global: Be Inclusive. We work together from anywhere to achieve our common goals. Our differences make us stronger.

Real: Be Authentic. We are genuine, pricipled and confident without arrogance. Show respect and kindness, especially in tough moments.

Unstoppable: Be Relentlessly Resourceful. We work with purpose, obsession and grit. It takes muscle to do hard things and doing hard things builds muscle.

Champions: Be Customer Obsessed. We care. Customers are everything, we put them at the center of everything you do. We are all empowered to make an impact.

Explorers: Be Curious. We value ideas over hierarchy. Never accept the status quo. We make bold bets, fail, and learn everyday. There is always a way.

Own It: Be an owner. We are drivers not passengers and own the quality and outcomes of our work.

Employee benefits

Learn about the employee benefits and perks provided at Kong.

View benefits

Unplug Days

Kong encourages taking well-deserved long weekends where the entire team unplugs to rest and recharge.

Equity Participation

Kongers are offered stock options to share in the success of the company, aligning employee and company growth.

Virtual Team Events

Kong hosts virtual events, donut chats, trivia, and fitness challenges to keep team members connected and engaged.

Office Stipend

Kong offers an office stipend to help employees build a home office environment tailored to support their productivity.

View Kong's employee benefits
Claim this profileKong logoKO

Kong

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

60 remote jobs at Kong

Explore the variety of open remote roles at Kong, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Kong

Remote companies like Kong

Find your next opportunity by exploring profiles of companies that are similar to Kong. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan