Director, Information Security Governance, Risk, and Compliance (GRC)

PenFed Credit Union

Tacoma (WA)

Hybrid

USD 122,000 - 284,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health, dental, vision plans
401(k) matching
Life and disability coverage
Education assistance

Job summary

PenFed Credit Union is seeking a Hybrid Director of Information Security Governance, Risk, and Compliance (GRC) to operationalize enterprise strategy and coordinate with regulators, auditors, and internal teams. The role balances leadership with hands-on risk and compliance activities to strengthen security posture.

The position emphasizes managing DRLs, findings, risk assessments, and remediation efforts across Information Security, IT, Internal Audit, Legal, and business units.

Qualifications

  • 10+ years of information security risk management experience.
  • Proven experience leading, coaching, and developing teams.
  • Experience managing security controls in large financial services organizations.
  • Strong knowledge of NIST, ISO 27001/2 frameworks.

Responsibilities

  • Lead and execute the Information Security risk management program.
  • Oversee detailed risk assessments including RCSAs.
  • Operationalize risk management strategies and mature risk frameworks.
  • Oversee third-party information security risk management activities.
  • Lead and develop the Information Security GRC team and set priorities.
  • Develop, maintain, and report risk and compliance metrics to executives.

Skills

Risk management
Leadership
Stakeholder communication
Regulatory frameworks
GRC frameworks

Education

Master's or Bachelor's in CS or related

Tools

Archer
ServiceNow GRC

Job description

Job Overview

PenFed is hiring a (Hybrid) Director, Information Security Governance, Risk, and Compliance (GRC) at our Tysons, Virginia location. The primary purpose of this role is to operationalize and execute the enterprise Information Security Governance, Risk, and Compliance (GRC) strategy established by the VP, Information Security Risk and Governance. The Director translates strategic direction into priorities, work plans, team guidance, and hands-on risk and compliance activities to ensure high-quality, timely outcomes. This role serves as the primary Information Security point of contact for NCUA examinations and audits; coordinates work across Information Security, Technology, Enterprise Risk, Internal Audit, Legal, and business teams; and is accountable for the quality and timely completion of Document Request List (DRL) responses, findings, exceptions, risk assessments, control activities, and remediation commitments. The Director balances leadership with direct operational involvement to strengthen the organization’s security posture and enable consistent, risk-based decision-making.

Responsibilities

Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. This is not intended to be an all-inclusive list of job duties, and the position will perform other duties as assigned.

  • Lead and actively execute the Information Security risk management program, including identifying, assessing, analyzing, monitoring, and reporting risks and working directly with stakeholders to define appropriate treatment and remediation actions.
  • Perform and oversee detailed Information Security risk assessments, including Risk and Control Self-Assessments (RCSAs); review work completed by team members; and clearly document risk conclusions.
  • Execute and operationalize security risk management strategies and frameworks established by Enterprise Risk Management. Maintain and mature security risk frameworks, policies, and standards that guide consistent, enterprise-wide information security risk management practices.
  • Oversee third-party Information Security risk management activities, including the vendor security risk assessments, risk analysis, issue escalation, risk acceptance, remediation follow-up, and ongoing monitoring.
  • Lead and actively support Information Security control management, including maintaining the control inventory, mapping controls to risks, confirming ownership, improving control documentation, coordinating assessments and testing, evaluating gaps, and monitoring remediation to strengthen control design and operating effectiveness.
  • Lead, coach, and develop the Information Security GRC team, including providing hands-on guidance, reviewing and improving work products, clarifying expectations, removing barriers, and directly contributing to complex or time-sensitive work. Establish clear priorities and accountability while building the capabilities of team members with varying levels of experience.
  • Develop, maintain, validate, and report risk and compliance metrics, dashboards, and key performance and risk indicators. Ensure supporting information is complete and accurate, identify overdue commitments, and provide execution status, risk insights, and escalation recommendations to the VP, Information Security Risk and Governance and other stakeholders as appropriate.
  • Prepare, review, and deliver clear, accurate, and timely risk and compliance reporting for senior leadership, regulators, the Cyber Risk Management Council, and the Board of Directors.
  • Serve as the primary Information Security point of contact for NCUA examinations and audits and support other internal and external reviews. Lead the collection, review, organization, submission, and tracking of materials responsive to Document Request Lists (DRLs); coordinate contributors and dependencies across teams; ensure responses are complete, accurate, consistent, and delivered on time; and manage Information Security findings, exceptions, remediation plans, commitments, and closure evidence.
  • Manage the execution, review, communication, and modernization of Information Security policies, standards, and procedures in alignment with VP direction, enterprise objectives, regulatory expectations, risk appetite, and the broader governance framework.
  • Maintain deep awareness of emerging technologies, industry trends, and evolving threats, proactively adapting compliance and risk practices to strengthen the security posture.
  • Coordinate closely through Information Security, Technology, Enterprise Risk, Internal Audit, Legal, Privacy, Procurement, business functions, and third parties to resolve dependencies, drive decisions, and ensure deliverables are completed on time and meet quality expectations.

*This is not intended to be an all-inclusive list of job duties.*

Qualifications

Equivalent combination of education and experience is considered.

  • Master's Degree and/or bachelor's degree in computer science or equivalent in related field preferred.
  • Minimum of ten (10) years of relevant Information Security risk management experience.
  • Proven experience leading, coaching, and developing teams while establishing priorities, driving accountability, and delivering high-quality outcomes in a complex Information Security, risk, or compliance environment.
  • Experience in the management of security control capabilities within large, complex financial services organization.
  • Solid working knowledge of understanding key security controls (Access Control, Encryptions, etc.)
  • Ability to communicate effectively and influence Business and IT leadership, staff, and other stakeholders, company-wide, to implement security recommendations.
  • Ability to establish and develop effective, trusting relationships with internal business units, together with a proven knowledge of the methods necessary to assess information security within a large organization.
  • Experience with risk management tracking tools (e.g., Archer, ServiceNow GRC, or similar platforms) to document risks, monitor remediation progress, maintain control inventories, and deliver accurate, data-driven risk reporting.
  • Experience in formal risk assessment and risk management practice.
  • Strong familiarity with information security, risk management, and IT government standards and frameworks (e.g. NIST 800-53, NIST Cyber Security Framework, ISO 27001/2, etc.)
  • Experience using AI tools preferred.

*Experience using AI tools preferred.*

Supervisory Responsibility

This position will supervise employees.

Licenses and Certifications

CISSP, CISA, CISM, CRISC, etc.

Work Environment

While performing the duties of this job, the employee is regularly exposed to an indoor office setting with moderate noise.

*Most roles require working in an office setting with moderate noise and the ability to lift 25 pounds.*

Travel

Ability to travel to various worksites and be on call is required.

Pay Transparency

The anticipated starting salary range for this role is $ 121,800 .00 - $ 283,648.00

This position is eligible for an organizational performance based annual bonus, subject to board discretion and approval.

This position is eligible for an individual performance based annual bonus.

Benefits

At PenFed, we offer a robust benefits package designed to support you both personally and professionally. You'll have access to comprehensive health, dental, and vision plans; paid time off; and family-friendly benefits like paid parental leave, care support, and fitness center access. Financial wellness is encouraged through features like a 401(k) match, employee loan discounts, and fully paid life and disability coverage. We also support growth via education assistance, community involvement, and volunteer opportunities.

Our Purpose

Helping members achieve their dreams since 1935. Pentagon Federal Credit Union (PenFed) is one of America's largest federal credit unions, serving 2.8 million members worldwide with $29 billion in assets. PenFed offers market-leading certificates, checking and savings, credit cards, personal loans, mortgages, auto loans, and a wide range of other financial services, always with members' interests in mind. PenFed is federally insured by the NCUA and is an Equal Housing Lender.

Equal Employment Opportunity

PenFed management will maintain and observe personnel policies which will not discriminate or permit harassment or retaliation against a person because of race, color, creed, age, sex, gender, gender identity, gender expression, religion, national origin, ancestry, marital status, military or veteran status or obligation, the presence of a physical and/or mental disability or medical condition, genetic information, sexual orientation, and all statuses protected by applicable state or local law in all recruiting, hiring, training, compensation, overtime, position classifications, work assignments, facilities, promotions, transfers, employee treatment, and in all other terms and conditions of employment. PenFed will also prohibit retaliation against individuals for raising a complaint of discrimination or harassment or participating in an investigation of same. PenFed will also reasonably accommodate qualified individuals with a disability so that they can apply for a job or perform the essential functions of a job unless doing so causes a direct threat to these individuals or others in the workplace and the threat cannot be eliminated by reasonable accommodation or if the accommodation creates an undue hardship to PenFed. Contact human resources (HR) with any questions or requests for accommodation at Careers@PenFed.org .

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Information Security Governance, Risk, and Compliance (GRC)
Director, Information Security Governance, Risk, and Compliance (GRC)

PenFed Credit Union • McLean (VA)

Hybrid
USD 122,000 - 284,000
VP, Intelligent Banking Platform
VP, Intelligent Banking Platform

PenFed Credit Union • Washington

Hybrid
USD 152,000 - 310,000
Health, dental, and vision plans
401(k) match
Life and disability coverage
+1
Director, Compensation
Director, Compensation

PenFed Credit Union • Washington, Baltimore (MD)

On-site
USD 97,000 - 224,000
401(k) match
Paid parental leave
Fitness center access
+5
Operations Change Delivery Lead
Operations Change Delivery Lead

PenFed Credit Union • Washington

On-site
USD 69,000 - 131,000
Health, dental, and vision plans
Paid time off
Parental leave and family benefits
+4
FP&A Manager, Home Lending & CRE
FP&A Manager, Home Lending & CRE

PenFed Credit Union • McLean (VA)

On-site
USD 85,000 - 192,000
401(k) match
Fully paid life and disability
Education assistance
+1
Manager, Decision Science
Manager, Decision Science

PenFed Credit Union • McLean (VA)

On-site
USD 97,000 - 191,000
Health insurance
Dental insurance
Vision plan
+7
Operations Change Delivery Lead - San Antonio, Texas
Operations Change Delivery Lead - San Antonio, Texas

PenFed Credit Union • San Antonio (TX)

On-site
USD 69,000 - 131,000
Health plan
Paid time off
Parental leave
+6
Senior Accountant
Senior Accountant

PenFed Credit Union • Washington, Baltimore (MD)

Hybrid
USD 60,000 - 133,000
Health insurance
Dental insurance
Vision insurance
+8
Director, Dealer Partner Product Strategy
Director, Dealer Partner Product Strategy

PenFed Credit Union • McLean (VA)

On-site
USD 97,000 - 190,000
Health insurance
Dental plan
Vision plan
+5
Risk Analyst, Enterprise Risk Management & Internal Controls
Risk Analyst, Enterprise Risk Management & Internal Controls

PenFed Credit Union • McLean (VA)

Hybrid
USD 45,000 - 89,000