Himalayas logo
KongKO

GRC Program Manager

Speed up time to market by unleashing developer productivity, automating security, and streamlining API management.

Kong

Employee count: 201-500

India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Are you ready to power the World's connections?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

The Compliance Program Manager is responsible for end-to-end ownership of Kong’s compliance programs, acting as an internal auditor, ensuring continuous audit readiness, and managing external audits across Kong’s product portfolio.

This role leads compliance monitoring activities, identifies and tracks control gaps, maintains security policies and processes, and works closely with Customer Assurance, Security, Engineering, and Product teams to drive remediation and obtain/maintain certifications such as ISO 27001, and SOC 2 Type II.

Key Responsibilities

  • Act as an internal auditor, continuously assessing the effectiveness of security and compliance controls across Kong’s products.

  • Ensure ongoing audit readiness for compliance frameworks including ISO 27001 and SOC 2 Type II.

  • Provide clear guidance on compliance requirements and expectations.

  • Plan and execute internal control reviews and readiness assessments.

  • Identify control gaps and weaknesses across Kong’s products and supporting processes.

  • Assess gaps against applicable compliance frameworks and regulatory requirements.

  • Document findings, risks, and recommendations in a clear and actionable manner.

  • Collaborate closely with Customer Assurance SMEs to remediate identified compliance gaps for their assigned products, and align customer-facing assurance responses with actual control implementation

  • Partner with Security, Engineering, SRE, Product, Legal, and IT teams to drive remediation efforts.

  • Track remediation activities and ensure timely closure of findings.

  • Provide risk-based guidance and prioritization to stakeholders.

  • Own and execute continuous compliance monitoring activities across all Kong products.

  • Validate that controls remain implemented and effective as products, systems, and processes evolve.

  • Monitor changes to compliance frameworks and assess their impact on Kong’s control environment.

  • Maintain compliance dashboards, metrics, and reporting for leadership.

  • External Audit Management

    • Own and manage external audits and assessments end-to-end, including auditor engagement and coordination, audit planning and timelines, evidence request management

    • Facilitate evidence collection, validation, and submission across teams.

    • Serve as the primary point of contact for auditors and assessors.

    • Track audit findings and ensure appropriate remediation and closure.

  • Security Policy & Process Management

    • Own the development, maintenance, and periodic review of security and compliance policies, standards, and procedures

    • Ensure policies remain aligned with compliance framework requirements, and actual operational practices

    • Drive policy awareness and adoption across the organization

    • Support updates to policies based on audit findings, risk assessments, and organizational changes

    Required Qualifications

    • 8+ years of experience in Compliance, GRC, Security, or Risk Management roles.

    • Strong working knowledge of ISO 27001 and SOC 2 Type II.

    • Proven experience acting as an internal auditor or compliance program owner.

    • Hands-on experience managing external audits and assessments.

    • Experience supporting multiple products or business units in a SaaS or technology organization.

    • Understanding of control design, implementation, and testing.

    • Familiarity with risk assessment and continuous compliance models.

    • Ability to understand and assess controls in SaaS, cloud, and hybrid environments.

    • Experience working with Engineering and SRE teams on technical controls.

    • Strong documentation and evidence management skills.

    • Excellent written and verbal communication skills.

    • Ability to clearly explain compliance requirements and audit findings to technical and non-technical stakeholders.

    • Strong cross-functional collaboration and stakeholder management skills.

    • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent experience.

    • Certifications such as CISSP, CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor are preferred, but not mandatory.

About Kong:

Kong Inc., a leading developer of cloud API technologies, is on a mission to enable companies around the world to become “API-first” and securely accelerate AI adoption. Kong helps organizations globally — from startups to Fortune 500 enterprises — unleash developer productivity, build securely, and accelerate time to market. For more information about Kong, please visit www.konghq.com or follow us on X @thekonginc.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Manager

Location requirements

Hiring timezones

India +/- 0 hours

About Kong

Learn more about Kong and their company culture.

View company profile

Speed up time to market by unleashing developer productivity, automating security, and streamlining API management.

Kong powers the API world

Kong provides the foundation that enables any company to become an API-first company — speeding up time to market, creating new business opportunities, and delivering superior products and services.

Built on the world’s most adopted API gateway, Kong’s unified cloud API platform delivers fast, reliable, secure digital experiences. With Kong, organizations can increase developer productivity, security, and performance at scale with a single easy-to-use platform for API management, service mesh, and ingress controller.

We put customers at the heart of everything we do. That’s why everyone from e-commerce startups to the world’s leading biotech companies trust Kong to run mission-critical applications.

We embody open source and everything it stands for. We foster a culture of individualism — encouraging our people to bring new ideas and innovations, regardless of level and function.

How we do it

We’re passionate about solving the challenges that will fundamentally shape the future of tech. If you believe in taking ownership of your work, making an impact, and having fun along the way, come join us!

Global: Be Inclusive. We work together from anywhere to achieve our common goals. Our differences make us stronger.

Real: Be Authentic. We are genuine, pricipled and confident without arrogance. Show respect and kindness, especially in tough moments.

Unstoppable: Be Relentlessly Resourceful. We work with purpose, obsession and grit. It takes muscle to do hard things and doing hard things builds muscle.

Champions: Be Customer Obsessed. We care. Customers are everything, we put them at the center of everything you do. We are all empowered to make an impact.

Explorers: Be Curious. We value ideas over hierarchy. Never accept the status quo. We make bold bets, fail, and learn everyday. There is always a way.

Own It: Be an owner. We are drivers not passengers and own the quality and outcomes of our work.

Employee benefits

Learn about the employee benefits and perks provided at Kong.

View benefits

Unplug Days

Kong encourages taking well-deserved long weekends where the entire team unplugs to rest and recharge.

Equity Participation

Kongers are offered stock options to share in the success of the company, aligning employee and company growth.

Virtual Team Events

Kong hosts virtual events, donut chats, trivia, and fitness challenges to keep team members connected and engaged.

Office Stipend

Kong offers an office stipend to help employees build a home office environment tailored to support their productivity.

View Kong's employee benefits
Claim this profileKong logoKO

Kong

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

59 remote jobs at Kong

Explore the variety of open remote roles at Kong, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Kong

Remote companies like Kong

Find your next opportunity by exploring profiles of companies that are similar to Kong. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan