Director, Enterprise Risk
Listed on 2026-08-22
-
IT/Tech
App Folio is more than a company. We’re a community of dreamers, big thinkers, problem solvers, active listeners, and multipliers. At every opportunity, we set the pace while delivering innovation built to carry real estate into the future. One in which every experience feels effortless, yet meaningful. Where customers are empowered to take on any opportunity. We show up as one team, connected by our values to be a force for good.
Because together, we have the power to create extraordinary outcomes for our customers, our communities, and ourselves.
App Folio is more than a company. We’re a community of dreamers, big thinkers, problem solvers, active listeners, and multipliers. At every opportunity, we set the pace while delivering innovation built to carry real estate into the future. One in which every experience feels effortless, yet meaningful. Where customers are empowered to take on any opportunity. We show up as one team, connected by our values to be a force for good.
Because together, we have the power to create extraordinary outcomes for our customers, our communities, and ourselves.
- Mature and integrate App Folio’s ERM framework and program in partnership with senior leaders and cross-functional stakeholders, and support the Enterprise Risk Committee (ERC) that administers the program.
- Build a new Risk Analysis capability for coordinating risk identification, assessment, and monitoring activities across the business.
- Lead the Technology Compliance team — owning compliance policies, ongoing monitoring, and audit readiness across SOX and SOC reviews, and supporting a Common Controls Framework (CCF).
- Stand up a continuous, rolling risk-identification cadence that surfaces and escalates emerging risks in real time, complementing the annual enterprise risk assessment and the quarterly ERC and RCOC cycles.
- Partner with and enable first-line functions — including R&D (Product and Engineering) — embedding risk-informed decision-making into their workflows so risk is a natural, owned part of moving quickly.
- Assist management with risk-related reporting to the Board, and communicate ERM program updates to the Risk & Compliance Oversight Committee (RCOC).
- Advance the three-lines-of-defense model and the broader GRC strategy, aligning ERM activity, cadence, and Top Risks with the company’s operating model and OKRs.
- Extensive experience in enterprise risk management, GRC, internal audit, or a closely related second-line function, including maturing or scaling an ERM program.
- A track record of building and leading teams, developing talent through individual development plans (IDPs), and planning succession for key roles.
- Strong command of enterprise risk frameworks and the three-lines-of-defense model (e.g., COSO ERM), plus working knowledge of technology compliance domains such as SOX ITGCs and SOC 1 / SOC 2.
- Demonstrated ability to influence senior leaders and to communicate risk clearly to executive and Board-level audiences, including audit or risk committees.
- Experience partnering with first-line functions — ideally R&D, Product, or Engineering — to embed risk-informed decision-making without slowing the business.
- A data-driven approach to risk monitoring, including defining risk metrics and enhancing monitoring and reporting capabilities.
- Relevant professional certifications are a plus (e.g., CRISC, CRMA, CISA, CPA, or CISSP).
- 5+ years of progressive experience in enterprise risk management, internal audit, GRC, or technology compliance, including direct people-leadership experience.
- Deep, hands-on understanding of enterprise risk frameworks and the three-lines-of-defense model, with experience operating or maturing an ERM program.
- Proven ownership of technology compliance and audit readiness (SOX and/or SOC), including serving as a primary liaison to internal and external auditors.
- Excellent executive communication and stakeholder-management skills, with experience reporting to senior leadership and/or a Board committee.
This position is based in our San Diego, CA, or our Santa Barbara office. Find out more about our locations by visiting our site.
All late-stage…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).