Risk and Audit Governance Program Manager

GoogleNew York City, San Bruno, Atlanta, New York, California, GeorgiaOn-siteFull-timeStaff, 8–12 yearsListed 34 minutes ago

Apply now

About this role

We are a center of excellence for YouTube's Global Vendor Operations, responsible for designing and managing the governance solutions that ensure our external workspace partners strictly adhere to all agreements, policies, and operational standards.

At YouTube, we believe that everyone deserves to have a voice, and that the world is a better place when we listen, share, and build community through our stories. We work together to give everyone the power to share their story, explore what they love, and connect with one another in the process. Working at the intersection of cutting-edge technology and boundless creativity, we move at the speed of culture with a shared goal to show people the world. We explore new ideas, solve real problems, and have fun — and we do it all together.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $136000 - $196000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google (https://www.google.com/about/careers/applications/benefits/).

Minimum qualifications:

- Bachelor's degree or equivalent practical experience.

- 7 years of experience in risk management, audit, compliance, vendor operations, or a related field.

- Experience leading cross-functional investigations (e.g., RCAs, post-mortems) and presenting findings to executive leadership or executive stakeholders.

- Experience utilizing AI tools, LLMs, or automation software to optimize operational workflows, governance processes, or data analysis.

Preferred qualifications:

- Deep understanding of vendor operations, physical/logical security protocols, and insider risk governance.

- Proven ability to navigate ambiguity, working independently as an executive individual contributor to build strategic programs from scratch.

- Strong analytical accuracy and a critical eye for validating automated outputs, managing edge cases, and maintaining strict quality control.

- Excellent communication skills with the ability to translate complex, technical control failures into clear business risks for non-technical stakeholders.

- Highly organized, detail-oriented problem solver with excellent written and verbal communication skills.

- Design and scale a vendor risk assessment and audit framework across GVO, establishing governance policies and playbooks.

- Leverage AI to automate auditing vendor compliance. Review outputs, resolve edge cases, and ensure strict vendor adherence and ongoing monitoring.

- Lead post-mortems and Root Cause Analysis (RCA) for vendor failures or security breaches, synthesizing findings into executive briefings.

- Act as the primary contact for cross-functional teams (e.g., Legal, Privacy) regarding vendor compliance, controls, and Business Continuity Planning.

- Develop a Corrective Action Plan process to track and validate audit remediations. Establish Key Risk Indicators (KRIs) and dashboards. Lead GVO education programs, training internal teams to identify vendor risks, understand control environments, and escalate issues.