Software Governance Senior Associate guiding open-source compliance, licensing, AI risk, and SBOM governance. Supporting Ciena’s networking infrastructure business through legal, technical, and cross-functional collaboration.
Responsibilities
Review and approve Software Bills of Materials (SBOMs) for products
Ensure open source software components are accurately identified and licensing, security, and intellectual property risks are assessed and addressed
Partner with engineering, product line management, and cross-functional teams on third-party, open source, and proprietary software use
Support identification and management of software licensing, intellectual property, security vulnerability, and AI-use risks
Maintain and improve Software Governance frameworks, processes, and tools
Ensure compliance with company policies, legal requirements, and industry standards
Contribute to policies, procedures, and best practices related to Software Governance
Collaborate on software inventory, compliance documentation, and customer disclosures
Build working relationships across teams to drive governance awareness, accountability, and adoption
Develop expertise in software licensing, intellectual property, and responsible AI use
Provide guidance on software licensing strategy and commercial licensing considerations
Support responsible AI governance initiatives
Contribute to enterprise policies, procedures, and Software Governance frameworks
Requirements
Foundational understanding of open source software and licensing concepts, including common license types and obligations
Knowledge of basic software licensing principles, including open source and commercial licensing models
Practical experience with software development environments and processes, and governance, compliance, and security within the lifecycle
Basic understanding of AI technologies and their use in software development and business contexts, including responsible use and risk awareness
Awareness of emerging AI trends and architectures, including generative AI and agentic systems, and their governance implications
Strong analytical and problem-solving skills
Ability to assess risks and recommend practical solutions with structured risk evaluations and documentation
Excellent communication skills for explaining technical or compliance-related topics to diverse audiences
Proven ability to collaborate effectively across cross-functional teams and build positive working relationships
Self-motivated with a strong desire to learn and grow into a broader governance and advisory role
Working knowledge of software composition analysis (SCA) tools and software vulnerability management practices
Deeper understanding of software intellectual property concepts, including copyright, licensing rights, and contractual obligations
Familiarity with secure software development lifecycle (SDLC) and integrated DevSecOps environments
Experience supporting or contributing to policy development, risk mitigation tracking, audits, or compliance
Familiarity with AI governance frameworks and standards, including NIST AI RMF and EU AI Act concepts
Experience identifying and assessing AI-related risks across the lifecycle, including privacy, bias, security, and regulatory exposure
Benefits
Development opportunities
Flexible work arrangements
Medical, dental, and vision plans
Participation in 401(K) (USA) & DCPP (Canada) with company matching
Employee Stock Purchase Program (ESPP)
Employee Assistance Program (EAP)
Company-paid holidays
Paid sick leave
Vacation time
Paid Family Leave and other leaves of absence
Discretionary incentive bonus eligibility for non-sales employees
Personal Information Protection Risk Advisor strengthening Desjardins's security posture and data - protection governance. Leading complex initiatives, policies, and risk solutions for Desjardins.
Personal Information Protection Risk Advisor strengthening Desjardins's security posture and data - protection governance. Leading complex initiatives, policies, and strategic risk solutions for Desjardins.
Conseiller technique chez Promutuel Assurance, expert en audit et conformité des risques d’assurance des particuliers. Soutien aux analystes, formation et amélioration continue des processus.
Principal Risk Engineer guiding energy and renewable portfolio risk for Liberty Mutual Canada, a commercial insurer. Leading assessments, loss prevention, underwriting advisory, and client risk strategy.
Chargé de livraison applicative chez Desjardins, coordonnant les livrables technologiques de projets de risque et de gestion de la fraude. Mobilisation des équipes TI, gestion des dépendances et résolution des obstacles en mode Agile.
Chef(fe) de pratique dirigeant le secrétariat corporatif et la gouvernance des filiales chez iA Financial Group. Soutien aux conseils d’administration et amélioration des pratiques juridiques.
Conseiller principal en gouvernance des données chez BRP, manufacturier canadien de véhicules récréatifs. Opérationnalisation d’un modèle fédéré et adoption des pratiques de Data Stewardship.
Senior risk manager overseeing controls, assessments, and governance for RBC’s global technology functions. Advising executives and leading risk remediation, testing, and process improvement.
Data governance advisor helping Desjardins secure and manage member and client data. Developing governance processes, controls, dashboards, and compliance practices in a hybrid role.
Senior Data Governance Advisor at Desjardins, a financial services cooperative. Leading data governance standards, controls, compliance, and strategic initiatives for members and clients.