GRC & Information Security Strategy Director

Blackboard

United States

Remote

USD 154,000 - 209,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Blackboard, a leading EdTech company, seeks a Director for Governance, Risk and Compliance to lead ISMS program development, risk assessment, and external audit coordination in a remote US-based role.

You will translate complex regulations (NIST, ISO, SOC, PCI-DSS) into practical security controls, report risk posture to senior management, and mentor security teams across global stakeholders.

Qualifications

  • US Citizenship
  • 10+ years of hands-on experience in IT audit and/or compliance
  • Strong documentation and communication skills
  • Strong understanding of security standards and frameworks including ISO27000 series, NIST SP 800 series, SOC audits, and security requirements of Data Privacy laws
  • Previous experience gaining an ATO or P-ATO for a cloud implementation under the FedRAMP, GovRAMP or IL-4 programs
  • Understanding of software development lifecycle methodologies, cloud and server infrastructure, network technologies
  • Experience managing security staff, collaboration and relationship building with global teams
  • Fluency in written and spoken English

Responsibilities

  • Developing and maintaining the organization's ISMS documentation, including policies, standards, and procedures for risk management, compliance, and information security.
  • Responsible for recommendations to the CISO, Product Management, Legal and Finance leadership teams that provide security program alignment with compliance requirements.
  • Responsible for information risk management, collaborative design of information security controls, assessment of effective implementation of applicable controls, including identity and access management.
  • Staying current on evolving regulatory environments, security threats, and compliance best practices, and updating policies and procedures accordingly.
  • Responsible for maintaining and improving information security awareness in the organization.
  • Translating business and information security needs and integrating these with the ISMS.
  • Coordinating external audit engagements with 3PAO, ISO/SOC auditors, PCI DSS QSA firms and other security assessors, including coordinating responses and remediation efforts.
  • Conducting vendor risk assessments and ensuring third-party compliance with security and privacy standards.
  • Reviewing and monitoring the activities of the Security Incident Response and Business Continuity Management teams to ensure that the information security controls are used effectively during the complete life cycle of business continuity and disaster recovery response.
  • Managing the recurring measurement of the effectiveness of ISMS controls implemented and communicate findings with senior management.
  • Enforcing document control management processes for the Information Security Management System.
  • Assisting with forecasting, planning and risk assessment relevant to evolving security control coverage in alignment with the company's technology strategy.
  • Maintaining and applying current industry knowledge and best practices. Researching and recommending use of new technologies.
  • Project management including analysis of business requirements, creating and updating project plans, and tracking projects to successful completion.
  • Assisting with vendor management, forecasting and program budget management.
  • Managing personnel including mentoring and cross-training of team members to achieve business objectives.

Skills

IT audit & compliance
Documentation & communication
English fluency
Vendor risk management
Security standards knowledge
Cloud/FedRAMP/IL-4 understanding
Team leadership
Project management

Education

Bachelor's degree in CS or related
CISA/CISM/CISSP certification (preferred)

Job description

Blackboard, a leading EdTech company, seeks a Director for Governance, Risk and Compliance to lead ISMS program development, risk assessment, and external audit coordination in a remote US-based role.

You will translate complex regulations (NIST, ISO, SOC, PCI-DSS) into practical security controls, report risk posture to senior management, and mentor security teams across global stakeholders.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Governance Risk and Compliance
Director, Governance Risk and Compliance

Blackboard • United States

Remote
USD 154,000 - 209,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Strategy Lead, AI & Cyber Governance
GRC Strategy Lead, AI & Cyber Governance

TransUnion LLC • Reston (VA)

Hybrid
USD 143,000 - 238,000
Health insurance
401(k) match
Employee stock purchase plan
+1
Director, GRC & Federal Compliance Leadership
Director, GRC & Federal Compliance Leadership

Unknown • United States

Remote
USD 110,000 - 180,000
Competitive salary
401(k) match
Employer-paid health vision dental
+1
Senior GRC & ISMS Security Strategist
Senior GRC & ISMS Security Strategist

Dorsey & Whitney LLP • Palo Alto (CA)

Hybrid
USD 140,000 - 190,000
GRC Lead: Security Risk & Compliance
GRC Lead: Security Risk & Compliance

MSIG USA • Warren Township (IA)

On-site
USD 120,000 - 180,000
Cybersecurity Director - Strategic GRC Leader (Remote)
Cybersecurity Director - Strategic GRC Leader (Remote)

Remote Genie • San Francisco (CA), Northern (KY)

Hybrid
USD 230,000 - 245,000
Remote work possible
Health benefits
Fitness stipend
+3
Senior GRC & Information Security Lead
Senior GRC & Information Security Lead

Dorsey & Whitney LLP • Phoenix (AZ)

On-site
USD 140,000 - 180,000
Health benefits
Paid time off
Parental leave
Director, Information Security & GRC
Director, Information Security & GRC

C&S Wholesale Grocers, LLC • Keene (NH)

Hybrid
USD 140,000 - 200,000
Remote GRC Lead: Cybersecurity Governance & Risk
Remote GRC Lead: Cybersecurity Governance & Risk

ERP International, LLC • Laurel (MD)

On-site
USD 165,000 - 210,000
Health Benefits
Retirement Plan
Training & Development
+2