83 director grc jobs at 71 companies in United States
4w
Save
Mark Applied
Hide
4w
Director, Cybersecurity & GRC
Berkeley or Somerville or Weirton
$200k-$294k/yrHybridFull Time
Form Energy: Developing multi-day batteries for grid-scale energy storage.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT GRC with 5+ years leadership; deep ITGC, IAM, EDR/MDR, vulnerability management, incident response, and audit liaison experience; ISO 27001/SOC 2/NIST familiarity; strong executive communication.
Live Nation EntertainmentNYSE: LYV: Sells tickets and produces concerts for live entertainment events.
6+ YOELead and mature a third-party risk management program within a GRC framework; manage a team of risk analysts; collaborate across security, privacy, legal, and technology.
WorkivaNYSE: WK: Cloud platform for connected reporting and compliance.
10+ YOE10+ years in B2B product marketing (SaaS), undergraduate degree, experience marketing GRC or risk/compliance solutions preferred, GTM and competitive strategy expertise, strong communication and cross-functional influence.
Clover HealthNasdaq: CLOV: Provide Medicare Advantage plans and AI-powered clinical decision tools.
8+ YOE8+ years in information security, GRC or risk management; experience leading governance and compliance in regulated environments; strong HIPAA knowledge; public company experience; manages third-party GRC vendors; incident response governance.
Inkit: Software platform for secure document generation and digital signatures.
Proven GRC leadership in B2B SaaS, hands-on Vanta experience, knowledge of SOC 2/ISO/FedRAMP/NIST/DoD IL frameworks, strong cross-functional communication, and ability to build scalable risk and compliance processes.
Sr Director Analyst, Cyber GRC Tools and Technology (Remote US)
United States or Texas
$172k-$203k/yrRemoteFull Time
GartnerNYSE: IT: Provides research and advisory services for business leaders.
12+ YOE5+ Mgmt12+ years in Cyber GRC/InfoSec/ERM with 5+ years leadership, expertise in Cyber GRC tools, strong research, writing, presentation and client engagement skills; willingness to travel up to 25%.
Technetics GroupNYSE: NPO: Designs and manufactures high-performance industrial seals and components.
10+ YOE5+ Mgmt10+ years in information security; 5+ years in security program leadership; experience with GRC, IAM, security operations; ISO 27001, SOC; OT security; cloud; risk management.
AWS, Microsoft Entra, Windows, Linux, SIEM, GRC tooling, IAM
EY: Global firm providing audit, tax, and professional consulting services.
15+ YOE10+ Mgmt15+ years technology risk/internal audit experience, 10+ years leading teams; bachelor’s degree or equivalent; experience in cybersecurity, AI governance, ERP/SAP, GRC/IRM and resilience; CISSP/CISM/CCSP/CISA desired.
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.
Sawdey Solution Services: Provides engineering and technical services to government and defense agencies.
10+ YOE5+ Mgmt10+ years program/project management, 5+ years leading service transitions, experience with security services (SIEM, SOC, vulnerability management, GRC, forensics), CJIS-compliant background check, U.S. citizenship, travel 25–50%, Microsoft Office proficiency; bachelor’s degree preferred.
Microsoft Word, Microsoft PowerPoint, Microsoft Excel, Microsoft Outlook, SIEM, SOC, GRC
Airwallex: Global financial platform for business payments and money management.
10+ YOE3+ Mgmt10+ years in corporate governance/compliance/internal audit or operational risk; 3+ years managing a compliance inventory or GRC program; experience mapping controls to laws and overseeing audit registers.
Q4: Provides digital platforms and software for corporate investor relations.
7+ YOE7+ Mgmt7+ years in IT operations, information security, technology risk or GRC with people management; strong knowledge of security frameworks and privacy regulations; hands-on experience with IdP/IAM, MDM/EDR, logging/monitoring and GRC platforms; program and audit experience.
South Jordan or Woodbury or Horsham or Pittsburgh or Orlando
$151k-$168k/yrHybridFull Time
CardWorks: Offers consumer lending, credit card servicing, and merchant solutions.
8+ YOE3+ Mgmt8+ years in information security/compliance with leadership; expertise in risk management, CRI Profile, NIST CSF, PCI DSS; vendor risk, GRC tools; Bachelor's or Master's preferred; CRISC/CISM/CISSP/CISA.
Asurion: Provides insurance and repair services for consumer electronics.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT risk or GRC with 5+ years leading managers; bachelor’s or equivalent; deep knowledge of NIST CSF 2.0 and ISO 27001/27005; GRC platform and risk-quantification experience; strong executive communication.
SMBC GroupNew York Stock Exchange: SMFG: Provides global banking, investment, securities, and consumer finance services.
10+ YOELead AI risk governance; 10+ years risk/tech risk/AI governance in financial services; experience with AI governance, GRC tooling; strong communication; bachelor’s degree, master’s preferred.
AI governance tools, GRC tooling, model management
10+ YOE4+ Mgmt10+ years product management with 4+ years leadership, expertise in sovereign cloud/data sovereignty, experience with GRC and cybersecurity products, strong communication and cross-functional influence, ability to partner with Legal and Privacy.
Infoblox: Secures and automates core network services and cloud identity.
15+ YOE15+ years in GRC or information security with ownership of controls, audits, SOX ITGC, and enterprise compliance; CISSP preferred; experience with ISO/NIST frameworks, SOC 2/ISO certifications, ServiceNow GRC or AuditBoard, automation/AI-driven GRC, and a bachelor’s degree or equivalent.
WPS Health Solutions: Provides health insurance plans and administers government benefit programs.
10+ YOE5+ MgmtU.S. citizenship required. Bachelor's (or equivalent) and 10+ years cybersecurity/risk experience with 5+ years leadership. Experience with cyber risk frameworks, GRC tools, AI cyber risk, audit/assurance, and executive-level communication.
NIST CSF, NIST SP 800-53, NIST SP 800-171, HIPAA, CMS, CMMC, SOC 1, SOC 2, ISO 27001, GRC, POA&M, AI