×
Register Here to Apply for Jobs or Post Jobs. X

IT Sr Director, Compliance and Risk Governance

Job in Sunnyvale, Santa Clara County, California, 94087, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 190000 - 270000 USD Yearly USD 190000.00 270000.00 YEAR
Job Description & How to Apply Below

Primary Function of Position:

Responsible for providing strategic leadership and oversight of the enterprise Cybersecurity Governance, Risk, and Compliance (GRC) program. This role establishes the vision, operating model, and governance framework necessary to effectively identify, assess, manage, and communicate cybersecurity and technology risks across the organization. Serves as a trusted advisor to senior leadership, business stakeholders, and technology teams, ensuring that cybersecurity risk management practices align with organizational objectives, regulatory requirements, and industry best practices.

This leader drives a risk-informed culture and enables the business to innovate securely while maintaining compliance and operational resilience.

Cybersecurity Governance

Define, implement, and continuously mature the enterprise cybersecurity governance framework, including policies, standards, procedures, and oversight mechanisms. Establish strategic direction for cybersecurity governance, ensuring alignment with corporate objectives, risk appetite, and business priorities. Lead governance forums, steering committees, and executive reviews to drive accountability and informed decision-making. Develop and monitor key performance indicators (KPIs), key risk indicators (KRIs), and executive dashboards that measure program effectiveness and organizational risk posture.

Drive governance modernization initiatives through automation, process optimization, and data-driven decision support.

Enterprise Risk Management

Lead the enterprise cybersecurity risk management program, ensuring risks are identified, assessed, prioritized, mitigated, and monitored effectively. Develop risk assessment methodologies and reporting frameworks that provide actionable insights to executive leadership. Partner with business and technology leaders to implement risk mitigation strategies that balance security, operational efficiency, and business objectives.

Compliance Oversight

Establish and maintain programs to ensure compliance with applicable regulations, standards, and industry frameworks, including ISO 27001, ISO 27036, NIST Cybersecurity Framework (CSF), as well as other relevant frameworks such as AI risk management. Lead internal and external audits, assessments, and regulatory reviews. Ensure remediation activities are effectively managed and tracked through closure. Monitor emerging regulatory requirements and industry developments, advising leadership on compliance obligations and risk implications.

Third-Party

Risk Management

Establish and oversee governance processes for evaluating and monitoring third-party cybersecurity and technology risks. Collaborate with Procurement, Legal, Privacy, and business stakeholders to assess vendor security posture and contractual risk requirements. Drive continuous improvement of supplier risk management practices to support organizational resilience and compliance objectives.

Engagement & Business Partnership

Serve as key advisor to senior leadership on cybersecurity risk, governance, and compliance matters. Provide clear, concise, and impactful reporting to executive leadership and governance bodies. Influence strategic business initiatives by integrating security, risk, and compliance considerations into planning and execution activities. Foster strong partnerships across business functions to promote risk-aware decision-making and regulatory readiness.

Leadership & Organizational Development

Build, lead, and develop a high-performing team of cybersecurity governance, risk, and compliance professionals. Establish organizational goals, resource strategies, and performance expectations aligned with enterprise priorities. Manage departmental budgets, strategic planning activities, and program investments. Champion a culture of accountability, transparency, continuous improvement, and risk awareness throughout the organization.

Skills, Experience, Education, & Training:

Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Administration, or a related discipline.

12+ years of progressive leadership experience in cybersecurity, information security, governance, risk management, compliance, or related disciplines. 7+ years of experience leading enterprise-scale cybersecurity GRC programs and teams. Demonstrated success developing and executing enterprise governance and risk management strategies within complex, highly regulated environments. Experience presenting cybersecurity risk, compliance, and governance topics to executive leadership, senior management, and governance committees. Proven track record of leading external audits, regulatory assessments, and compliance initiatives.

Deep expertise in cybersecurity governance, enterprise risk management, regulatory compliance, and industry frameworks. Strong understanding of cybersecurity standards and frameworks, including ISO 27001, ISO 27036, ISO 42001, NIST CSF, NIST AI RMF, CSA AISMM, and…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary