Director, Governance, Risk Compliance; GRC
Listed on 2026-05-24
-
IT/Tech
Cybersecurity, Data Security, Information Security
Director of Governance, Risk & Compliance (GRC)
The director is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that transforms governance from a compliance-focused function into a fast, intelligent, and risk‑based engine for the business. Reporting directly to the CISO, the role serves as the architect of a scalable GRC capability that modernizes how cyber risk is identified, measured, prioritized, reported, and acted upon across the enterprise and product portfolio.
The director will leverage data, automation, analytics, and the responsible application of AI to create a single authoritative view of cyber risk, reduce operational friction, accelerate decision‑making, and ensure governance operates at the speed and scale of the business. This role partners closely with Security, IT, Product Engineering, Legal, Privacy, Finance, Internal Audit, and executive leadership to embed risk‑based governance into how the organization plans, builds, and operates.
- Define and maintain the enterprise cybersecurity governance framework, including decision rights, escalation paths, and exception handling.
- Own the cybersecurity policy, standards, and exception lifecycle across enterprise and product environments.
- Ensure clear ownership and accountability for security controls, compliance obligations, and accepted risks.
- Serve as a senior advisor to the CISO and executive leadership on governance decisions and material risk trade‑offs.
- Own the cybersecurity risk management framework, including risk taxonomy, scoring methodology, appetite, and acceptance thresholds.
- Maintain the enterprise risk register and an integrated portfolio view of cyber risk across enterprise, product, and third‑party domains.
- Provide leadership with an aggregate, decision‑ready risk posture to support prioritization, investment planning, and risk acceptance.
- Lead risk assessments for enterprise IT, cloud platforms, connected products, and critical suppliers.
- Ensure risk acceptance decisions are well‑documented, time‑bound, reviewed, and auditable.
- Lead preparation of cybersecurity risk materials for executive leadership, board committees, and full board briefings.
- Translate technical and operational cyber risk into business impact, financial exposure, and strategic implications.
- Support the CISO in board‑level discussions related to cyber risk posture, trends, and material risk decisions.
- Lead enterprise and product cybersecurity compliance programs aligned to regulatory, statutory, and customer requirements.
- Translate regulatory obligations into pragmatic, enforceable control expectations embedded into business and engineering workflows.
- Partner with Product Security and Engineering to integrate security‑by‑design and compliance into product development life cycles.
- Monitor emerging regulations and contractual obligations and define readiness roadmaps that minimize disruption to delivery.
- Own security audit, customer assurance, and certification readiness across enterprise and product environments.
- Establish an always‑audit‑ready operating model with defined control ownership, evidence standards, and testing cadence.
- Oversee remediation of audit findings and control gaps using durable, sustainable solutions.
- Provide executive visibility into audit status, findings, trends, and remediation progress.
- Lead third‑party and supply‑chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight.
- Define risk‑based tiering, minimum security requirements, and escalation thresholds for suppliers.
- Partner with Finance, Legal, and Risk Management to support cyber insurance underwriting, renewals, and claims.
- Provide risk data, metrics, and control evidence required to support cyber insurance placement and renewal activities.
- Define and maintain key risk indicators (KRIs),…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).