Director, Governance, Risk & Compliance

MX

Lehi (UT)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Company-paid meals
Gym access
Mothers lounge

Job summary

MX, a fintech leader, seeks a Director of Governance, Risk & Compliance to own MX's security governance, privacy, and regulatory compliance programs. You will partner across Security, Legal, Product, Sales, and Operations to enable fast, responsible growth.

Reporting to the CISO, you will build scalable processes, lead the Compliance team, and drive continuous improvement across privacy and regulatory controls. Utah-based, on-site with office perks.

Qualifications

  • Experience leading information security governance, risk, and privacy programs.
  • Proven ability to implement and mature enterprise-wide GRC frameworks.
  • Strong collaboration with Legal, Product, Engineering, and Compliance teams.
  • Experience driving privacy programs across multiple jurisdictions.

Responsibilities

  • Develop and execute MX's enterprise GRC strategy.
  • Build and mature security, privacy, and risk programs aligned to regulations.
  • Maintain enterprise security policies, standards, controls, and governance.
  • Lead audits and certification efforts (SOC 2, ISO 27001, PCI DSS).
  • Partner with cross-functional stakeholders to embed security/privacy in processes.

Skills

Governance
Risk management
Privacy program
Regulatory compliance
Security audits
Data mapping
Cross-functional leadership
Stakeholder management

Education

Bachelor's degree in IT/CS/Cybersecurity

Tools

GRC platforms
Compliance frameworks

Job description

MX is a fintech company on a mission to empower the world to be financially strong. We build technology that helps banks, credit unions, and fintechs deliver smarter, more intuitive financial experiences to millions of people.

Like many startups, we’ve navigated real growth challenges — and we’ve come out stronger on the other side. Today, MX is in a phase of renewed momentum and scale, with a solid foundation and a clear vision for what’s next. This is a place where thoughtful execution matters, innovation is encouraged, and individuals have real ownership over their work.

Our culture values curiosity, accountability, and impact. We give people the space to question assumptions, design better solutions, and help shape how the company grows. If you’re looking to do meaningful work, influence outcomes, and grow alongside a company that’s ready to move fast, you’ll feel at home at MX.

As we continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across Security, Engineering, Legal, Product, Sales, Customer Success, and Operations to ensure MX maintains industry-leading security and privacy standards while enabling the business to move quickly and responsibly.

Reporting directly to the VP & Chief Information Security Officer (CISO), you will lead the Compliance team and own the strategy, execution, and continuous improvement of MX's security governance, privacy, and regulatory compliance programs.

What You'll Do
Lead Governance, Risk & Compliance
  • Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy.
  • Build, mature, and continuously improve security, privacy, and risk management programs that align with business objectives and regulatory requirements.
  • Develop, maintain, and operationalize enterprise-wide security policies, standards, controls, and governance processes.
  • Establish scalable compliance frameworks that support continued company growth while reducing organizational risk.
Own Privacy & Regulatory Compliance
  • Lead the company's global privacy program across multiple jurisdictions.
  • Ensure compliance with applicable privacy regulations, including GDPR, CCPA, HIPAA, PIPEDA, UK Data Protection Act, and other emerging regulations.
  • Partner with Legal, Engineering, Product, and business stakeholders to perform Privacy Impact Assessments (PIAs) and advise on privacy requirements throughout the product lifecycle.
  • Develop governance frameworks for responsible data collection, storage, processing, retention, and sharing.
  • Oversee data mapping initiatives, vendor privacy reviews, and data governance practices.
Manage Audits & Customer Assurance
  • Own all internal and external security, privacy, and compliance audits.
  • Lead certification efforts including SOC 2, ISO 27001, PCI DSS, and other applicable frameworks.
  • Serve as the executive owner for customer security and privacy questionnaires.
  • Partner with Sales and Customer Success to support enterprise customer due diligence and security reviews.
Drive Risk Management
  • Continuously assess organizational security, compliance, and privacy risks.
  • Monitor effectiveness of security controls and recommend improvements where necessary.
  • Build reporting and metrics that provide executive leadership visibility into organizational risk posture.
  • Develop mitigation strategies and partner across engineering and operations to reduce risk.
Lead & Develop the Team
  • Lead, mentor, and grow a high-performing Compliance and Privacy team.
  • Foster a culture of accountability, operational excellence, and continuous improvement.
  • Develop scalable processes that improve efficiency while maintaining regulatory compliance.
Build Cross-Functional Partnerships
  • Partner closely with Security, Engineering, Legal, Product, Sales, Support, and Operations to embed security and privacy into business processes.
  • Influence stakeholders across the organization to balance business objectives with regulatory obligations.
  • Lead company-wide privacy and compliance awareness initiatives and employee training programs.
Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Business, Legal Studies, or a related field.
  • 10+ years of experience leading Information Security Governance, Risk, Compliance, Privacy, or Security Operations programs.
  • Deep expertise with compliance frameworks
  • Experience implementing Governance, Risk & Compliance (GRC) platforms and common control frameworks.
Preferred Qualifications
  • Professional certifications such as: CIPP, CIPM, CIPT, CISM, CISA
  • Experience working within fintech or highly regulated industries.
  • Knowledge of Business Continuity Planning and Disaster Recovery.
  • Experience supporting multinational organizations with global regulatory requirements.
  • Familiarity with Web Application Firewalls (WAFs), Content Delivery Networks (CDNs), and modern cloud infrastructure.

At MX, we are a high-performance organization that thrives on trust and results. This role is based in Lehi, Utah. We believe in empowering our team members to deliver exceptional outcomes while taking advantage of our incredible office space when it best supports their work. Our Utah office features onsite perks such as company-paid meals, a sports simulator, gym, mother’s lounge, and meditation room and meaningful interactions with amazing people. We encourage team members to come together in the office to collaborate, kick off key projects, or strategize cross-functionally, fostering connection and innovation.

MX is proudly committed to recruiting and retaining a diverse and inclusive workforce. As an Equal Opportunity Employer, we never discriminate based on race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, military or veteran status, status as an individual with a disability, or other applicable legally protected characteristics. We particularly welcome applications from veterans and military spouses. All your information will be kept confidential according to EEO guidelines. You may request reasonable accommodations by sending an email to hr@mx.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Strategy Lead - Privacy, Security & Compliance
GRC Strategy Lead - Privacy, Security & Compliance

MX • Lehi (UT)

On-site
USD 150,000 - 230,000
Company-paid meals
Gym access
Mothers lounge
GRC Engineer
GRC Engineer

RiverPark Ventures • New York (NY)

On-site
USD 130,000 - 170,000
Medical, Dental and Vision plans
401(k) plan with match
Paid holidays
+7
Senior Manager, Engineering
Senior Manager, Engineering

MX • Lehi (UT)

On-site
USD 160,000 - 230,000
Company-paid meals
Gym access
Mother’s lounge
+1
Senior Director, GRC
Senior Director, GRC

United States Digital Space LLC • San Francisco (CA)

On-site
USD 264,000 - 363,000
Equity (where applicable)
Bonus
Health, dental and vision insurance
+3
GRC Engineer
GRC Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Vision & dental coverage
HSA & FSA
+7
Senior Compliance Analyst
Senior Compliance Analyst

Horizon3.ai • United States

Hybrid
USD 109,000 - 135,000
Hybrid & Remote Work
Health, vision & dental insurance for您
Flexible vacation policy
+1
Vice President, IT Governance, Risk & Compliance
Vice President, IT Governance, Risk & Compliance

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 220,000 - 330,000
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

United States Digital Space LLC • San Francisco (CA)

On-site
USD 120,000 - 180,000
Manager, Governance, Risk & Compliance
Manager, Governance, Risk & Compliance

mrisoftware • United States

On-site
USD 150,000 - 210,000
Senior Compliance Analyst
Senior Compliance Analyst

NightDragon Acquisition Corp. • United States

On-site
USD 109,000 - 135,000
Equity
Hybrid & Remote Work
Health, Vision & Dental
+1