×
Register Here to Apply for Jobs or Post Jobs. X

Director, Information Security Governance, Risk, and Compliance; GRC)

Job in McLean, Fairfax County, Virginia, USA
Listing for: PenFed Credit Union
Full Time position
Listed on 2026-09-27
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Consultant
Salary/Wage Range or Industry Benchmark: 122000 - 284000 USD Yearly USD 122000.00 284000.00 YEAR
Job Description & How to Apply Below
Position: Director, Information Security Governance, Risk, and Compliance (GRC)

Director, Information Security Governance, Risk, and Compliance (GRC)

Pen Fed is hiring a (Hybrid) Director, Information Security Governance, Risk, and Compliance (GRC) at our Tysons, Virginia location. The primary purpose of this role is to operationalize and execute the enterprise Information Security Governance, Risk, and Compliance (GRC) strategy established by the VP, Information Security Risk and Governance. The Director translates strategic direction into priorities, work plans, team guidance, and hands‑on risk and compliance activities to ensure high-quality, timely outcomes.

This role serves as the primary Information Security point of contact for NCUA examinations and audits; coordinates work across Information Security, Technology, Enterprise Risk, Internal Audit, Legal, and business teams; and is accountable for the quality and timely completion of Document Request List (DRL) responses, findings, exceptions, risk assessments, control activities, and remediation commitments. The Director balances leadership with direct operational involvement to strengthen the organization’s security posture and enable consistent, risk‑based decision‑making.

Equivalent combination of education and experience is considered.

  • Master’s Degree and/or bachelor’s degree in computer science or equivalent in related field preferred.
  • Minimum of ten (10) years of relevant Information Security risk management experience.
  • Proven experience leading, coaching, and developing teams while establishing priorities, driving accountability, and delivering high-quality outcomes in a complex Information Security, risk, or compliance environment.
  • Experience in the management of security control capabilities within large, complex financial services organization.
  • Solid working knowledge of understanding key security controls (Access Control, Encrypt ions, etc.)
  • Ability to communicate effectively and influence Business and IT leadership, staff, and other stakeholders, company-wide, to implement security recommendations.
  • Ability to establish and develop effective, trusting relationships with internal business units, together with a proven knowledge of the methods necessary to assess information security within a large organization.
  • Experience with risk management tracking tools (e.g., Archer, Service Now GRC, or similar platforms) to document risks, monitor remediation progress, maintain control inventories, and deliver accurate, data‑driven risk reporting.
  • Experience in formal risk assessment and risk management practice.
  • Strong familiarity with information security, risk management, and IT government standards and frameworks (e.g. NIST 800-53, NIST Cyber Security Framework, ISO 27001/2, etc.)
  • Experience using AI tools preferred.
Supervisory Responsibility

This position will supervise employees.

Licenses and Certifications

CISSP, CISA, CISM, CRISC, etc.

Work Environment

While performing the duties of this job, the employee is regularly exposed to an indoor office setting with moderate noise.

Most roles require working in an office setting with moderate noise and the ability to lift 25 pounds.

Travel

Ability to travel to various worksites and be on call is required.

Pay Transparency

The anticipated starting salary range for this role is $ - $

This position is eligible for an organizational performance based annual bonus, subject to board discretion and approval.

This position is eligible for an individual performance based annual bonus.

Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. This is not intended to be an all-inclusive list of job duties, and the position will perform other duties as assigned.

  • Lead and actively execute the Information Security risk management program,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary