Director IT Risk and Compliance
Core
Lead enterprise IT risk management and regulatory compliance programs, modernizing processes with AI and automation to shift from reactive to predictive.
Role type
Director, IT Risk and Compliance
Builds
Enterprise risk registers, compliance dashboards, automated testing workflows, and GRC platform capabilities
Domain
Retail / IT Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOX ITGC expertise, PCI DSS compliance, IT risk assessment, vendor risk management, incident response planning, executive communication, team leadership, regulatory interpretation
Preferred skills
CISA/CISSP/CISM/CRISC certifications, GRC platform deployment (AuditBoard/ServiceNow/Archer), AI/automation piloting, third-party risk platforms, state data privacy regulations
Technologies
AuditBoard, ServiceNow GRC, Archer, UpGuard, BitSight, Security Scorecard
Responsibilities
Own and mature the SOX ITGC program end-to-end; Direct PCI DSS assessment activities and annual penetration testing; Lead enterprise IT and cybersecurity risk assessments; Build and lead a high-performing team of IT risk and compliance professionals; Champion the use of AI and automation to modernize compliance testing; Present risk and compliance status to the ELT, Audit Committee, and Board-level stakeholders
Seniority
Director, strategic leadership with hands-on program ownership