Director of Governance, Risk, and Compliance
Core
Lead and scale the Governance, Risk, and Compliance (GRC) program to ensure regulatory and IT audit readiness, manage third-party risk, and align policies with industry standards.
Role type
Director of GRC (Leadership)
Builds
Enterprise compliance frameworks, audit readiness, and vendor risk management programs
Domain
Technology / SaaS / Healthcare & Housing
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC program ownership, audit management, vendor risk management, compliance framework expertise, team leadership, executive communication
Preferred skills
Scaling GRC functions, cross-functional influence, security policy development
Technologies
SOC 1, SOC 2, PCI, HIPAA, HITRUST, ISO
Responsibilities
Own and lead the company's GRC program setting strategic direction across compliance frameworks; Serve as primary owner of audit relationships overseeing planning and evidence collection; Define and enforce compliance roadmaps ensuring cross-functional alignment; Attract top-tier talent to scale the GRC team providing mentorship; Oversee the vendor risk management program including third-party due diligence; Lead reviews of vendor and client security questionnaires with final sign-off authority; Own the security and compliance policy framework driving creation and adoption
Seniority
Director, strategic leadership & team scaling
