Director of Governance, Risk, and Compliance
Lead and scale the GRC program across SOC, PCI, HIPAA, and ISO frameworks. Own audit relationships, vendor risk management, policy development, and team building while partnering with Legal, Security, and business stakeholders.
About the job
Key Responsibilities
- Own and lead the company's GRC program, setting strategic direction across frameworks including SOC 1, SOC 2, PCI, HITRUST, and HIPAA
- Serve as the primary owner of audit relationships, overseeing planning, evidence collection, documentation, and auditor communications
- Define and enforce compliance roadmaps, ensuring cross-functional alignment and accountability on regulatory requirements
- Attract top-tier talent to scale the GRC team, providing mentorship, setting priorities, and managing team performance
- Oversee the vendor risk management program, including third-party due diligence, risk tiering, and escalation of critical findings
- Lead reviews of vendor and client security questionnaires (DDQs) in partnership with Security Engineering, with final sign-off authority
- Own the security and compliance policy framework — driving creation, review cycles, and organization-wide adoption
- Partner with Legal and Security leadership on security-related contractual obligations, including review and negotiation of security addenda
Requirements
- 8+ years of experience in Governance, Risk, and Compliance, Information Security, or a related field, with at least 3 years in a leadership or program ownership role
- Deep expertise across compliance frameworks including SOC1, SOC 2, PCI, HIPAA, and ISO certifications
- Proven track record managing audit programs end-to-end, including direct relationships with external auditors
- Experience building or scaling a GRC function, including team hiring and development
- Strong understanding of vendor risk management, third-party due diligence, and risk-based decision-making
- Ability to translate complex compliance and risk topics for executive and board-level audiences
- Excellent cross-functional influencing skills — comfortable working with Legal, Engineering, and business leadership
- Willingness to work in person at our office 4-5 days a week
Benefits
- Equity in the company
- Medical, Dental and Vision premiums covered at 100%
- Fully paid parental leave
- Commuter benefits
- 401k benefits
- Fitness & home services stipend
- Collaborative in-office environment with an open floor plan, fully stocked kitchen, and all meals covered in the office
- Unlimited vacation and paid holidays
- Relocation packages covered
Skills
Soc 1, SOC 2, PCI, HIPAA, Hitrust, Iso Certifications, Vendor Risk Management, Third-Party Due Diligence, Audit Management, Compliance Frameworks
Similar jobs
Legal jobsLeads Astra’s enterprise compliance, financial-crimes, payments, privacy, GRC, and assurance programs while advising executives, the Board, product teams, and bank partners. Requires 8+ years of financial-services compliance experience, BSA/AML leadership, sponsor-bank expertise, and a bachelor’s degree.
Leads commercial contracting and a legal team while transforming contract operations through AI and CLM platforms. Requires a JD, active bar membership, 10+ years of legal and commercial-contract experience, people management, and hands-on legal AI implementation expertise.
The Director of Compliance designs, oversees, and monitors Commure’s corporate compliance program for its AI healthcare platform. Responsibilities include risk assessments, policy development, training, auditing, and advising on healthcare laws such as HIPAA, Anti-Kickback, Stark, FDA SaMD, and information blocking. Requires 6-10 years healthcare compliance leadership experience.
Leads the full government contracting lifecycle, from capture and acquisition strategy through negotiation, performance, compliance, and closeout. Requires 8+ years of federal contracting experience, strong FAR/DFARS expertise, and the ability to manage government, subcontract, and teaming relationships.
Leads tax workstreams across acquisitions, reorganizations, investments, and infrastructure transactions, advising Corporate Development, Legal, and Finance. Requires a JD or CPA and substantial transactional tax experience, with preferred depth in M&A, REITs, joint ventures, and technology or data center transactions.