Senior IRM Analyst
The Information Security Risk Team at MongoDB is the operational engine of the internal and third-party risk programs. Situated within the A…
The Information Security Risk Program Manager is the operational engine of the internal risk program. While the Risk Manager and Risk Director define the strategic roadmap, the Program Manager ensures the daily execution of that strategy. They are responsible for the "production line" of risk assessment: taking raw signals from the business, processing them through the established methodology, and outputting actionable risk decisions (Remediation or Acceptance).
The ultimate objective of this role is Reduction of Uncertainty. By managing the program effectively, the Program Manager ensures that MongoDB’s leadership has a clear, quantified view of the top risks facing the enterprise. They transform the Risk Register from a static spreadsheet into a dynamic governance tool that drives accountability.
The Program Manager must not be afraid to be in the trenches with the Engineering and Product teams. They are the primary face of the "Risk Intake Process," guiding stakeholders through the methodology. They are the gatekeeper of quality, ensuring that no risk enters the register until it has been properly scoped and quantified.
This role can be based in Dublin for our hybrid working model.
Responsibilities
Risk Identification & Assessment
Execute risk assessments under senior guidance - perform scoping, inherent risk scoring, control assessment, and residual risk calculation using established methodology
Conduct risk identification intake, manage the flow of requests from Jira Service Desk and the Issue Intake Tracker, review incoming submissions against entry criteria, assign Risk IDs, and replicate validated risks into the Risk Register
Act as the Triage Officer for incoming risk submissions, determine whether submissions represent strategic risks, operational issues, or duplicates. Filter noise to focus the team on signals
Develop risk scenarios for in-scope assets by working with asset owners and risk owners , identify threat communities, threat events, and
Neutral 2–4 sentence summary of what working at this company is like, drawn from public reviews and press coverage. Tone, collaboration style, pace, benefits highlights.
£45,000 – £60,000 (Glassdoor, Levels.fyi, 2025)
The Information Security Risk Team at MongoDB is the operational engine of the internal and third-party risk programs. Situated within the A…