Director, Governance, Risk and Compliance (GRC)
Core
Lead and operate enterprise cybersecurity governance, cyber risk management, compliance, and data governance functions to strengthen frameworks and drive risk-informed decision-making.
Role type
Senior individual contributor Director, GRC
Builds
Enterprise cyber risk management frameworks, governance policies, compliance programs, and data governance controls
Domain
Financial services (banking/fintech) + Cybersecurity/Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Enterprise cyber risk management, GRC leadership, regulatory compliance, data governance, third-party risk management, executive reporting, policy development, audit coordination, risk register management, remediation tracking
Preferred skills
Canadian financial sector regulatory knowledge, GRC platform implementation, workflow automation, control mapping across frameworks
Technologies
NIST, ISO 27001, GRC platforms, cloud security frameworks
Responsibilities
Own and operate the enterprise cyber risk management framework; Support internal and external audits and regulatory reviews; Develop and mature cybersecurity governance programs and policies; Prepare executive-level cyber risk reporting; Partner with data governance and privacy teams to manage information risk; Personally execute critical deliverables in a hands-on leadership capacity
Seniority
Director, hands-on senior IC
