Director, Security Governance, Risk and Compliance
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Our Security GRC team sits within Information Security and plays a critical role in earning and maintaining our customer's trust. We ensure we meet our duty of care to our customers, employees, and partners by creating effective governance for upholding internal security policies, distributing foundational security expertise across every department to create a strong security culture, and bolstering customer and community trust by providing accessible and transparent information about our internal security program.
The team and this role partners closely with other security teams, Legal, Sales, HR, and many other teams Director reports to the Chief Information Security Officer and leads a team of professionals to oversee key programs and collaborates with business leaders to reduce business risk and support the Tricentis global growth strategy. The director will use collaborative change management tactics that builds engagement, establishes trust and effective relationships and ownership, and inspires enthusiasm across the company.
This is a strategic leadership role that has a strong hands‑on component, requiring a mix of strategic forethought, people leadership, and hands‑on execution. The Director plays a critical role in corporate M&A processes and customer and internal incident response, and will also be responsible for building and maintaining a forward leaning compliance posture, looking at the global compliance and regulatory landscape as a guide to help design and execute on a strategic roadmap.
If you hate silos, this is the company for you. This role will assist in building deeper layers of transparency and accountability while ensuring all roles have visibility to drive appropriate planning, allocation, and delivery.
- Lead and manage a global team to oversee security governance, risk, compliance, customer trust, and privacy activities, reporting directly to the CISO.
- Directly manage and own the security policies, procedures and controls with the goal of maintaining compliance to applicable regulations and beyond.
- Develop and implement a comprehensive information security risk management program, including risk strategy, self-assessment, and analysis programs.
- Foster strong relationships with internal stakeholders, external auditors, and vendors while managing M&A due diligence, training, and awareness initiatives.
- Oversee data governance, product certification, and compliance efforts to align with regulatory controls while optimizing engineering velocity.
- Configure and maintain GRC tools for compliance evidence collection, gap identification, and risk management.
- Collaborate with Privacy Counsel on ISO 27701 certification, lead security audits, and refine policies and practices to meet evolving regulatory requirements.
- Support sales and marketing teams with certification roadmaps, compliance reporting, and alignment of initiatives with executive leadership goals.
- Foster continuous partnership with the sales team to maintain trust and transparency with customers, ensuring clear communication of security and compliance efforts while addressing customer concerns and expectations
- Create and manage a security M&A due diligence plan.
- Use influence and technology to drive operational changes in a pro‑active and supportive way that builds unity across corporate divisions.
- Leverage AI and other technologies to force multiply the team and reduce the typical overhead burden of compliance activities
- Work with the Marketing team to identify Level of Effort and ROI for new certifications while also ensuring that our Compliance & Certification efforts are adequately reflected in Marketing materials.
- Partner with engineering, product management, and customer‑facing teams to create…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).