Global Product Regulatory Compliance Lead - Confluent
Introduction
At IBM Software, we transform client challenges into solutions. Building the world’s leading AI-powered, cloud-native products that shape the future of business and society. Our legacy of innovation creates endless opportunities for IBMers to learn, grow, and make an impact on a global scale. Working in Software means joining a team fueled by curiosity and collaboration. You’ll work with diverse technologies, partners, and industries to design, develop, and deliver solutions that power digital transformation. With a culture that values innovation, growth, and continuous learning, IBM Software places you at the heart of IBM’s product and technology landscape. Here, you’ll have the tools and opportunities to advance your career while creating software that changes the world.
Your role and responsibilities
Confluent an IBM company is pioneering a fundamentally new category of data infrastructure focused on data in motion. Have you ever found a new favorite series on Netflix, picked up groceries curbside at Walmart, or paid for something using Square? That's the power of data in motion in action — giving organizations instant access to the massive amounts of data that is constantly flowing throughout their business. At Confluent, we're building the foundational platform for this new paradigm of data infrastructure.
The Office of the CISO (OCISO) is part of Confluent's Trust and Security organization. Its mission is to earn and retain trust by championing Confluent's security, privacy, resilience, and compliance positions, thereby accelerating customer adoption and use of our platform and products.
We are looking for a senior individual contributor to build and own Product Regulatory Management — a net-new function responsible for assessing, implementing, and evidencing Confluent's product-level compliance across both IBM-driven and customer-driven regulations. This includes the substantial cross-domain regulatory body of work (privacy, AI, and other industry-specific obligations).
This person will operate as a key subject-matter expert and interface between IBM's Regulatory and Legal functions and Confluent R&D, driving the detailed impact analysis, applicability assessment, and control implementation. This role will also build Confluent's own capability to monitor and respond to indirect, customer-driven regulations flowing down from FSI, telco, healthcare, government, and other regulated customers.
Success in this role depends on the ability to build net-new processes, frameworks, and relationships from the ground up — while operating with strong autonomy and driving outcomes through influence rather than formal authority. The role requires both the credibility to engage regularly with senior leadership across Confluent R&D (Product, Engineering), the CISO organization, and enterprise Legal/regulatory counterparts at IBM, and the willingness to personally do the detailed analytical and program-building work day to day.
Primary Responsibilities
- End-to-End Ownership & Strategy — Build, scale, and manage the Product Regulatory Management function from the ground up, establishing the global strategy to assess, implement, and evidence Confluent’s product-level compliance across all direct and indirect obligations.
- Proactive Horizon Scanning & Deep Impact Analysis — Continuously track the global regulatory landscape in partnership with regional OCISO and enterprise regulatory teams to identify emerging frameworks, while independently conducting deep-dive applicability assessments to determine exact technical requirements and maintain compliance evidence for existing obligations.
- Technical Control Design & R&D Partnership — Act as the primary bridge between legal/regulatory mandates and technical execution, partnering extensively with R&D, Product, Engineering, and CISO leadership to translate and prioritize complex regulatory requirements into concrete, sustainable product and platform controls.
- Customer-Driven & Sector-Specific Compliance — Independently monitor, assess, and respond to strict regulatory flow-down obligations originating from highly regulated customer sectors—such as Financial Services, Healthcare, Telecom, and Government—ensuring alignment with frameworks like NIS2, GDPR, RegSCI, APRA, PRA, OCC, and MAS.
- Audit Readiness & Examination Defense — Serve as Confluent's primary Subject Matter Expert (SME) and front-line point of contact for regulatory-driven audits and examinations (e.g., under DORA) touching the product scope, directly producing the required evidence, documentation, and technical responses.
- Cross-Functional Alignment — Build and maintain strong working relationships across Confluent and enterprise Legal, Regulatory, and CISO organizations to align on qualified interpretations, ensure shared regulatory positions are understood, and secure necessary resources.
Required technical and professional expertise
- Minimum of 12 years of experience in information security, privacy, compliance, or regulatory roles, ideally within a cloud/SaaS provider or a highly regulated enterprise customer environment.
- Demonstrated experience building net-new compliance, privacy, or regulatory programs from the ground up without established precedent, operating with high autonomy as an individual contributor who drives outcomes through influence.
- Strong, current knowledge of global frameworks impacting cloud products, including privacy (e.g., GDPR), emerging AI regulations, and sector-specific regimes across financial services, telecom, healthcare, and government.
- Proven ability to translate complex legal requirements into concrete technical controls by working directly with Product and Engineering; requires a working understanding of Confluent’s platform or the ability to quickly build deep fluency in a cloud-native environment.
- A proven track record of engaging and influencing senior leadership across R&D, Legal, and the CISO organization, while remaining equally comfortable executing detailed, hands-on analytical and program work personally.
- Experience leading responses to customer due diligence, regulatory examinations, or third-party audits (including evidence management), backed by excellent communication skills tailored for legal, technical, and executive audiences.
Preferred technical and professional experience
- Direct experience with regulatory frameworks such as DORA, NIS2, GDPR, and other security, privacy, and compliance standards, as well as sector-specific regulators (e.g., PRA, BaFin, OCC, FFIEC, MAS, APRA).
- Experience working within or alongside a large enterprise partner ecosystem (e.g., a hyperscaler or major technology vendor relationship) and navigating shared or dependent compliance obligations.
- Experience with distributed, globally dispersed stakeholders and cross-functional teams spanning multiple regions and time zones
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.