Senior Director, GRC
Leads Okta’s security GRC organization, overseeing enterprise cyber risk, AI governance, global compliance, audits, vendor risk, and engineering-driven remediation. The role requires 10+ years of progressive Security GRC leadership, cloud technology experience, AI governance expertise, and a bachelor’s degree or equivalent experience.
About the job
Responsibilities
- Lead and scale the Governance, Risk and Compliance (GRC) Security organization.
- Integrate AI and agentic tools into GRC operations, including automated evidence collection, risk scoring, policy mapping, and continuous audit readiness.
- Operationalize AI risk and governance frameworks covering training data protection, model risk management, responsible AI, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
- Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification.
- Maintain and expand global compliance across SOC 1/2/3, ISO 27001, ENS High, MS DPR, PCI-DSS, CSA STAR, and HDS.
- Evolve corporate information security policies and control standards.
- Direct vendor risk assessment programs for third-party SaaS tools and supply chains.
- Lead internal and external audits, customer assurances, and regulatory reviews.
- Drive engineering-led remediation of audit findings and control gaps.
- Partner with Product Management, Legal, Privacy, Infrastructure, and Business Technology teams.
- Recruit, mentor, and retain high-performing GRC engineering and risk management professionals.
Requirements
- 10+ years of progressive leadership in Security GRC within a high-growth SaaS, cloud-first, or enterprise technology environment.
- Demonstrated understanding of generative and agentic AI security, data lineage, and global AI regulations.
- Extensive experience managing compliance for enterprise cloud environments.
- Deep knowledge of risk management methodologies and risk quantification.
- Proven experience building and leading technical GRC engineering and risk management teams.
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience.
Compensation and Benefits
- San Francisco Bay Area annual base salary: $264,000–$363,000 USD.
- California excluding the San Francisco Bay Area, Colorado, Illinois, New York, and Washington annual base salary: $236,000–$325,000 USD.
- Equity where applicable, bonus, health, dental and vision insurance, 401(k), flexible spending account, and paid leave including PTO and parental leave.
Skills
Ai Governance, Generative AI, Agentic AI, Nist Ai Rmf, Iso/Iec 42001, Eu Ai Act, Risk Management, Risk Quantification, Soc 1/2/3, ISO 27001, Pci-Dss, Vendor Risk Management, Cloud Security, Continuous Control Monitoring, Compliance-As-Code
Similar jobs
Engineering Management jobsLeads the entire engineering organization, owning technical vision, architecture, execution standards, security, budget, and organizational scaling. The role requires extensive software engineering and engineering management experience, cloud-native architecture expertise, and a record of building high-performing teams.
Leads a multi-team organization responsible for AI-assisted development, cloud agentic infrastructure, developer experience, CI/CD, testing, and engineering velocity. Requires extensive software engineering and engineering leadership experience, deep infrastructure expertise, and hands-on knowledge of AI developer tooling and LLM evaluation.
Leads multiple engineering teams responsible for insurance product configuration, enrollment workflows, and core domain services. The role requires deep distributed-systems expertise, backend development experience, strong operational leadership, and a track record of managing managers in a regulated or enterprise environment.
Leads the organization responsible for deploying, sustaining, supporting, and improving integrated Hivemind software and hardware products in customer environments. Requires 15 years of technical operations or lifecycle leadership experience, systems engineering expertise, and experience building operational organizations.
Leads a 12-person application security practice, combining hands-on code auditing and vulnerability research with client delivery, staffing, profitability, and engineer development. Requires 10+ years in security and proficiency in at least four relevant programming languages.