Information Security Risk Manager

Full Time
San Francisco, CA
Areas of Interest: Information Assurance (IA) Compliance
report a problem

Reporting directly to the Director of Risk and Compliance, the Senior Analyst role will primarily be responsible for security & governance over Ancestry’s Personally Identifiable Information( PII) and General Data Protection Regulation (GDPR) programs. The Senior Analyst will liaise with various teams to provide input and ensure the GDPR program is a success. This role will also establish and maintain a governance program to ensure ongoing compliance and strong controls over customer data. This position will require both a compliance and IT background and will be a multi-faceted role. Additional responsibilities will be added to the role as processes stabilize.

What you will do:

  • Governance over PII identification, collection, minimization, appropriate use, information sharing, proper handling and disposal.
  • Govern and coordinate relevant IT Risk activities (e.g., Audit, Regulatory, risk assessment, control testing, monitoring, vulnerability management, risk reporting) and remediation of identified gaps and issues.
  • Work closely with Chief Privacy Officer and serve as the IT Security Department subject matter expert regarding PII and GDPR approach and policies.
  • Communicate GDPR project release status and feedback to product teams and other stakeholders
    May own the successful delivery of multiple projects
  • Advise colleagues and business clients on privacy requirements, compliance responsibilities and methods to protect Ancestry’s sensitive customer data.
  • Interact with and develop a productive working relationship with all levels of management and process owners.
  • Periodically participate in the execution of SOX IT compliance activities by gathering information on control effectiveness.


  • Bachelor’s Degree or higher strongly preferred with experience in IT Audit or Advisory, IT Risk & Compliance, or Information Security
  • Minimum 3-5 years of work related experience in information technology compliance
  • Demonstrate knowledge of technology processes, risks, infrastructure, information security, SDLC and platform services
  • Capable of identifying, evaluating and mitigating significant risks within an enterprise
  • Experience with cloud computing a plus
  • Ability to document and explain risks and vulnerabilities to both business and technical stakeholder
  • Influencing, negotiating, and relationship building skills are all needed for this role
  • Strong oral and written communication
  • Willingness to take on side projects within security operations
  • Self-governing, comfortable working with minimal oversight and unstructured tasks
  • Possess strong analytical skills attention to detail
  • Estimated 20 % travel

Additional Information

We’re a cutting-edge tech company with a very human mission—to help every person discover, preserve, and share the story of what led to them. Combining the rich information in family trees and historical records with the genetic details revealed in DNA, we create unique experiences that give people a new understanding of their lives, because connecting all the pieces of our family story can give us the deepest sense of who we are.

For more information on what we do and why you would want to work at Ancestry, visit our careers

Ancestry is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at Ancestry via-email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of Ancestry. No fee will be paid in the event the candidate is hired by Ancestry as a result of the referral or through other means . 

Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.

Share this job:


Ancestry is the global leader in family history and consumer genomics, harnessing a powerful combination of information, science, and technology to develop new experiences to help everyone, everywhere discover the story of what led to them. Ancestry offers a suite of family history products and services including AncestryDNA, Archives, ProGenealogists, and Fold3.

AncestryDNA is the world's largest consumer genomics database providing consumers insights into their ancestral origins. The service enables customers to not only uncover their ethnic mix and rich family stories, but discover distant relatives with a common ancestral match, and help solve the toughest family mysteries.

Ancestry by the numbers:
  • Since 1996, more than 20 billion records have been added, and users have created more than 80 million family trees on the Ancestry flagship site and its affiliated international websites.
  • More than 4 million people genotyped in the AncestryDNA database.
‚ÄčThe company has more than 1,400 employees in locations across the globe. Headquartered in Utah, Ancestry has offices in San Francisco, Dublin, London, Sydney, Munich, and Stockholm.

There’s power in knowing who you are and where you come from. This is the driving force behind everything we do. We’re passionate about using technology to create simple, useful, and delightful experiences that enrich lives and connect families. We’re continually looking for talented, hard-working individuals who are passionate about bringing this mission to life.

Consumer genomics, Family history, Data science, and Handwriting recognition
Visit Ancestry's Social Media pages:
Company Type: Privately Held