Director, Governance, Risk & Compliance
Core
Lead and scale the Governance, Risk & Compliance (GRC) function, setting strategy for security, compliance, privacy, and customer trust in a high-growth cybersecurity platform.
Role type
Director, Governance, Risk & Compliance (Strategic IC)
Builds
Enterprise risk management frameworks, compliance certification programs (SOC 2, ISO), control assurance systems, and third-party risk governance.
Domain
Cybersecurity, Risk Management, Compliance, Privacy
Required skills
GRC strategy & roadmap planning, team building & scaling, SOC 2 Type II & ISO 27001/27701/42001 certification ownership, enterprise risk management (ERM), third-party risk governance, control assurance & automation, executive advisory, privacy & AI governance, organizational resilience planning.
Preferred skills
ISO 27701/42001 experience, CISA/CISSP/CISM/CRISC certifications, experience in high-growth SaaS/cybersecurity environments.
Technologies
SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST, Trust Services Criteria, GRC tooling platforms.
Responsibilities
Define and execute multi-year GRC strategy and operating model; lead and develop the GRC organization; maintain executive accountability for compliance certifications; establish enterprise risk governance frameworks; scale control assurance and security governance; own third-party and emerging risk strategy; lead customer trust and security assurance programs; shape privacy and AI governance; strengthen organizational resilience; advise executives and the board on risk posture.
Seniority
Director, strategic leadership & team building
