Director, Security Governance, Risk and Compliance

Tricentis

Austin (TX)

On-site

USD 180,000 - 250,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Tricentis, based in Austin, TX, seeks a Director of Security GRC to lead a global team within Information Security. You will oversee governance, risk, privacy, and compliance programs, reporting to the CISO, and collaborate with Legal, Sales, HR and other leaders to reduce risk and enable growth.

You will build risk management, drive audits, and shape a proactive compliance posture across regions, including M&A support.

Qualifications

  • 10+ years in Governance, Risk, and Compliance or related field with 3–5 years in leadership.
  • Experience managing security policies, procedures, and controls in regulated environments.
  • Proven track record leading audit activities and vendor management.
  • Experience building risk programs, incident response, and data governance.
  • Strong understanding of standards (GDPR, HIPAA, SOC 2, ISO 27001, ISO 27701, NIST).
  • Familiarity with Secure Controls Framework and implementing controls.

Responsibilities

  • Lead and manage a global team to oversee security governance, risk, compliance, customer trust, and privacy, reporting to the CISO.
  • Directly manage security policies, procedures, and controls to maintain compliance.
  • Develop and implement a comprehensive information security risk management program.
  • Foster relationships with auditors, vendors, and stakeholders; manage M&A due diligence and awareness initiatives.
  • Oversee data governance, product certification, and compliance to align with regulatory controls while optimizing engineering velocity.
  • Configure and maintain GRC tools for evidence collection, gap identification, and risk management.
  • Collaborate with Privacy Counsel on ISO 27701 certification; lead security audits and refine policies.
  • Support sales and marketing with certification roadmaps, compliance reporting, and leadership alignment.
  • Partner with engineering, product, and customer-facing teams to meet customer needs compliantly.

Skills

Leadership
Governance
Risk management
Compliance
Security policy
Stakeholder collaboration
Audit management
Communication

Tools

LogicGate

Job description

Our Security GRC team sits within Information Security and plays a critical role in earning and maintaining our customer's trust. We ensure we meet our duty of care to our customers, employees, and partners by creating effective governance for upholding internal security policies, distributing foundational security expertise across every department to create a strong security culture, and bolstering customer and community trust by providing accessible and transparent information about our internal security program. The team and this role partners closely with other security teams, Legal, Sales, HR, and many other teams at Tricentis. The Director reports to the Chief Information Security Officer and leads a team of professionals to oversee key programs and collaborates with business leaders to reduce business risk and support the Tricentis global growth strategy. The director will use collaborative change management tactics that builds engagement, establishes trust and effective relationships and ownership, and inspires enthusiasm across the company. This is a strategic leadership role that has a strong hands‑on component, requiring a mix of strategic forethought, people leadership, and hands‑on execution. The Director plays a critical role in corporate M&A processes and customer and internal incident response, and will also be responsible for building and maintaining a forward leaning compliance posture, looking at the global compliance and regulatory landscape as a guide to help design and execute on a strategic roadmap. If you hate silos, this is the company for you. This role will assist in building deeper layers of transparency and accountability while ensuring all roles have visibility to drive appropriate planning, allocation, and delivery.

What You’ll Do:
  • Lead and manage a global team to oversee security governance, risk, compliance, customer trust, and privacy activities, reporting directly to the CISO.
  • Directly manage and own the security policies, procedures and controls with the goal of maintaining compliance to applicable regulations and beyond.
  • Develop and implement a comprehensive information security risk management program, including risk strategy, self-assessment, and analysis programs.
  • Foster strong relationships with internal stakeholders, external auditors, and vendors while managing M&A due diligence, training, and awareness initiatives.
  • Oversee data governance, product certification, and compliance efforts to align with regulatory controls while optimizing engineering velocity.
  • Configure and maintain GRC tools for compliance evidence collection, gap identification, and risk management.
  • Collaborate with Privacy Counsel on ISO 27701 certification, lead security audits, and refine policies and practices to meet evolving regulatory requirements.
  • Support sales and marketing teams with certification roadmaps, compliance reporting, and alignment of initiatives with executive leadership goals.
  • Foster continuous partnership with the sales team to maintain trust and transparency with customers, ensuring clear communication of security and compliance efforts while addressing customer concerns and expectations
  • Create and manage a security M&A due diligence plan.
  • Use influence and technology to drive operational changes in a pro‑active and supportive way that builds unity across corporate divisions.
  • Leverage AI and other technologies to force multiply the team and reduce the typical overhead burden of compliance activities
  • Work with the Marketing team to identify Level of Effort and ROI for new certifications while also ensuring that our Compliance & Certification efforts are adequately reflected in Marketing materials.
  • Partner with engineering, product management, and customer‑facing teams to create effective processes that ensure we meet the needs of our customers in the most optimized and compliant way possible
Who You Are:
  • You are an empathetic leader that seeks to understand each project team member’s strengths and constraints.
  • You have a willingness to “jump in” and empower stakeholders to be ‘editors’ instead of ‘authors.’
  • You are comfortable at both the strategic and tactical level. You see the big picture and can create an inspirational vision, but you thrive in leading and executing strategic initiatives of your own.
  • You have the ability to work directly with Individual Contributors while also preparing & presenting reporting for Senior Leadership.
  • While you are not responsible for the Security of the product, you should have a high‑level familiarity with standard Security concepts, as well as standard development frameworks such as Security Operations, Corporate Security, DevSecOps, etc.
  • You should be comfortable interacting with external stakeholders such as CTOs, CISOs, and VPs of Procurement.
  • You will assist in streamlining our revenue pipeline by responding to and subsequently automating responses to our customer’s third-party validation activities.
Qualifications

Experience:

  • 10+ years of experience in Governance, Risk, and Compliance or a related field, with at least 3‑5 years in a leadership or managerial position.
  • Extensive experience in managing security policies, procedures, and controls in complex, highly regulated environments.
  • Proven track record of leading audit activities, including internal assessments, external compliance audits and third‑party vendor management.
  • Experience in developing and implementing risk management programs, incident response strategies, and data governance.
  • Strong understanding of industry standards and regulatory frameworks (e.g., GDPR, HIPAA, SOC 2, ISO 27001, ISO 27701, ISO 9001, ISO 42001, DORA, NIST).
  • Strong understanding of Secure Controls Framework (SCF) and experience in implementing, monitoring, and continuously improving security controls to mitigate risks and ensure compliance with industry standards and regulatory requirements.
  • Experience in working closely with executive leadership, product teams, legal counsel, and external auditors to ensure alignment with business goals and regulatory compliance.
  • Strong communication and leadership skills to influence decision‑making and drive operational change across various departments.
Preferred Certifications / Experience
  • GxP / FDA / ICH (leading certification efforts)
  • FedRamp / FISMA (leading certification efforts)
  • Sarbanes‑Oxley Act (SOX) and financial reporting audits
  • LogicGate Administration
  • Information security certification or risk management certifications preferred (CISA, CISM, CRISC, CISSP)
  • CIPP/e /us (or equivalent experience)
  • HIPAA & HITECH (leading certification efforts)

Tricentis is proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, ethnicity, gender, religious affiliation, age, sexual orientation, socioeconomic status, or physical and mental disability and other statuses protected by law.

Global Sanctions Compliance We comply with all applicable global sanctions and export control laws. Candidates must not be listed on any government restricted party lists (including OFAC SDN List and U.S. Commerce Department restricted lists) and must certify that their employment would not violate any sanctions or export control regulations. Candidates must notify us of any changes to their status during the application process or subsequent employment.

U.S. Work Authorization: This role is not eligible for employer-sponsored work visas. Applicants must be authorized to work in the U.S. without current or future sponsorship.

Tricentis is a global leader in continuous testing and quality engineering. The Tricentis AI-based, continuous testing portfolio of products provide a new and fundamentally different way to perform software testing. An approach that’s totally automated, fully codeless, and intelligently driven by AI. It addresses both agile development and complex enterprise apps, enabling enterprises to accelerate their digital transformation by dramatically increasing software release speed, reducing costs, and improving software quality. Widely credited for reinventing software testing for DevOps, cloud, and enterprise applications, Tricentis has been recognized as a leader by all major industry analysts, including Forrester, Gartner, and IDC. Tricentis has more than 3,000 customers, including the largest brands in the world, such as McKesson, Allianz, Telstra, Dolby, and Vodafone. To learn more, visit https://www.tricentis.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Security Governance, Risk and Compliance
Director, Security Governance, Risk and Compliance

Tricentis Americas, Inc. • Austin (TX)

On-site
USD 170,000 - 260,000
Lead Program Manager
Lead Program Manager

Tricentis • Austin (TX), Northern (KY)

Hybrid
USD 120,000 - 180,000
Lead Program Manager
Lead Program Manager

Ascent360 • Virginia (IL)

On-site
USD 120,000 - 180,000
Lead Program Manager
Lead Program Manager

tricentis • United States

On-site
USD 140,000 - 190,000
Director, Global Security GRC & Compliance
Director, Global Security GRC & Compliance

Tricentis • Austin (TX)

On-site
USD 180,000 - 250,000
Global Director, Security GRC & Compliance
Global Director, Security GRC & Compliance

Tricentis Americas, Inc. • Austin (TX)

On-site
USD 170,000 - 260,000
Senior Pricing & Packaging Director
Senior Pricing & Packaging Director

Tricentis Americas, Inc. • Austin (TX)

Hybrid
USD 180,000 - 260,000
Senior Field Marketing Manager
Senior Field Marketing Manager

Tricentis Americas, Inc. • Atlanta (GA)

Hybrid
USD 90,000 - 130,000
Account Director
Account Director

Ascent360 • California (MO)

On-site
USD 180,000 - 240,000
Competitive market salary + commission
401(k) / pension plan
Professional & personal development
+5
Associate Software Engineer at Tricentis
Associate Software Engineer at Tricentis

Feedinkoo • United States

Remote
USD 95,000 - 125,000
Flexible working hours
Medical coverage
Salary plus bonus
+1