IT Sr Director, Compliance and Risk Governance

Socket.dev

Sunnyvale (CA)

On-site

USD 190,000 - 270,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Intuitive Surgical seeks a strategic leader to head the cybersecurity governance, risk, and compliance (GRC) program in Sunnyvale, CA. This role shapes the governance framework, risk management, and compliance posture across the organization, guiding executive reporting and stakeholder engagement.

The ideal candidate has 12+ years in cybersecurity leadership, 7+ years in enterprise GRC, and deep expertise in ISO/NIST standards, with a proven record in audits and regulatory programs.

Qualifications

  • 12+ years of leadership experience in cybersecurity, information security, governance, risk management, or compliance.
  • 7+ years leading enterprise-scale GRC programs and teams.
  • Deep expertise in ISO 27001, ISO 27036, ISO 42001, NIST CSF, NIST AI RMF, CSA AISMM, and related control frameworks.
  • Experience presenting cybersecurity risk, compliance, and governance topics to executives and governance committees.
  • Proven track record of leading audits and regulatory assessments.

Responsibilities

  • Define, implement, and mature the enterprise cybersecurity governance framework with policies, standards, procedures, and oversight.
  • Lead enterprise cybersecurity risk management, including risk assessment methodologies and reporting.
  • Oversee compliance programs with ISO/NIST frameworks and regulatory requirements; manage audits and remediation.
  • Oversee third-party risk management with procurement, legal, privacy and business stakeholders.
  • Partner with senior leadership to integrate security, risk, and compliance into planning and execution.
  • Build and lead a high-performing GRC team; manage budgets and strategic investments.

Skills

Strategic leadership
Executive communication
Security governance
Risk management
Regulatory compliance

Education

Bachelor's degree in Cybersecurity or related field

Job description

Primary Function of Position:

Responsible for providing strategic leadership and oversight of the enterprise Cybersecurity Governance, Risk, and Compliance (GRC) program. This role establishes the vision, operating model, and governance framework necessary to effectively identify, assess, manage, and communicate cybersecurity and technology risks across the organization. Serves as a trusted advisor to senior leadership, business stakeholders, and technology teams, ensuring that cybersecurity risk management practices align with organizational objectives, regulatory requirements, and industry best practices. This leader drives a risk-informed culture and enables the business to innovate securely while maintaining compliance and operational resilience.

Cybersecurity Governance

Define, implement, and continuously mature the enterprise cybersecurity governance framework, including policies, standards, procedures, and oversight mechanisms. Establish strategic direction for cybersecurity governance, ensuring alignment with corporate objectives, risk appetite, and business priorities. Lead governance forums, steering committees, and executive reviews to drive accountability and informed decision-making. Develop and monitor key performance indicators (KPIs), key risk indicators (KRIs), and executive dashboards that measure program effectiveness and organizational risk posture. Drive governance modernization initiatives through automation, process optimization, and data-driven decision support.

Enterprise Risk Management

Lead the enterprise cybersecurity risk management program, ensuring risks are identified, assessed, prioritized, mitigated, and monitored effectively. Develop risk assessment methodologies and reporting frameworks that provide actionable insights to executive leadership. Partner with business and technology leaders to implement risk mitigation strategies that balance security, operational efficiency, and business objectives.

Compliance Oversight

Establish and maintain programs to ensure compliance with applicable regulations, standards, and industry frameworks, including ISO 27001, ISO 27036, NIST Cybersecurity Framework (CSF), as well as other relevant frameworks such as AI risk management. Lead internal and external audits, assessments, and regulatory reviews. Ensure remediation activities are effectively managed and tracked through closure. Monitor emerging regulatory requirements and industry developments, advising leadership on compliance obligations and risk implications.

Third-Party Risk Management

Establish and oversee governance processes for evaluating and monitoring third-party cybersecurity and technology risks. Collaborate with Procurement, Legal, Privacy, and business stakeholders to assess vendor security posture and contractual risk requirements. Drive continuous improvement of supplier risk management practices to support organizational resilience and compliance objectives.

Engagement & Business Partnership

Serve as key advisor to senior leadership on cybersecurity risk, governance, and compliance matters. Provide clear, concise, and impactful reporting to executive leadership and governance bodies. Influence strategic business initiatives by integrating security, risk, and compliance considerations into planning and execution activities. Foster strong partnerships across business functions to promote risk-aware decision-making and regulatory readiness.

Leadership & Organizational Development

Build, lead, and develop a high-performing team of cybersecurity governance, risk, and compliance professionals. Establish organizational goals, resource strategies, and performance expectations aligned with enterprise priorities. Manage departmental budgets, strategic planning activities, and program investments. Champion a culture of accountability, transparency, continuous improvement, and risk awareness throughout the organization.

Skills, Experience, Education, & Training:

Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Administration, or a related discipline.

12+ years of progressive leadership experience in cybersecurity, information security, governance, risk management, compliance, or related disciplines. 7+ years of experience leading enterprise-scale cybersecurity GRC programs and teams. Demonstrated success developing and executing enterprise governance and risk management strategies within complex, highly regulated environments. Experience presenting cybersecurity risk, compliance, and governance topics to executive leadership, senior management, and governance committees. Proven track record of leading external audits, regulatory assessments, and compliance initiatives. Deep expertise in cybersecurity governance, enterprise risk management, regulatory compliance, and industry frameworks. Strong understanding of cybersecurity standards and frameworks, including ISO 27001, ISO 27036, ISO 42001, NIST CSF, NIST AI RMF, CSA AISMM, and related control frameworks. Exceptional executive communication, stakeholder management, and influencing skills. Ability to translate complex technical concepts into clear business-focused recommendations.

Strong strategic thinking, analytical, problem-solving, and organizational leadership capabilities. Experience driving organizational transformation, process modernization, and program maturity initiatives.

Preferred certifications:
  • CISSP
  • CISM
  • CRISC
  • CISA

Due to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19. Details can vary by role.

Intuitive is an Equal Opportunity Employer.We provide equal employment opportunities to all qualified applicants and employees, and prohibit discrimination and harassment of any type, without regard to race, sex, pregnancy, sexual orientation, gender identity, national origin, color, age, religion, protected veteran or disability status, genetic information or any other status protected under federal, state, or local applicable laws.

Mandatory Notices

U.S. Export Controls Disclaimer:In accordance with the U.S. Export Administration Regulations (15 CFR §743.13(b)), some roles at Intuitive Surgical may be subject to U.S. export controls for prospective employeeswho are nationals from countries currently on embargo or sanctions status.

Certain information you provide as part of the application will be used for purposes of determining whether Intuitive Surgical will need to (i) obtain an export license from the U.S. Government on your behalf (note: the government’s licensing process can take 3 to 6+ months) or (ii) implement a Technology Control Plan (“TCP”) (note: typically adds 2 weeks to the hiring process).

For any Intuitive role subject to export controls, final offers are contingent upon obtaining an approved export license and/or an executed TCP prior to the prospective employee’sstart date, which may or may not be flexible, and within a timeframe that does not unreasonably impede the hiring need. If applicable, candidates will be notified and instructed on any requirements for these purposes.

We will consider for employment qualified applicants with arrest and conviction records in accordance with fair chance laws.

Preference will be given to qualified candidates who do not reside, or plan to reside, in Alabama, Arkansas, Delaware, Florida, Indiana, Iowa, Louisiana, Maryland, Mississippi, Missouri, Oklahoma, Pennsylvania, South Carolina, or Tennessee.

This position may be filled at a different job level than listed here depending onbusiness need and/or on the selected candidate’s experience, knowledge and skills. Compensation will be based primarily on the job level at which the role is filled and thecandidate’s qualifications, consistent with applicable law.

We provide market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity. It would not be typical for someone to be hired at the top end of range for the role, as actual pay will be determined based on several factors, including experience, skills, and qualifications. The target compensation ranges are listed.

It started with a simple idea: what if surgery could be less invasive and recovery less painful? Nearly 30 years later, that question still fuels everything we do at Intuitive. As a global leader in robotic-assisted surgery and minimally invasive care, our technologies—like the da Vinci surgical system and Ion—have transformed how care is delivered for millions of patients worldwide.

We’re a team of engineers, clinicians, and innovators united by one purpose: to make surgery smarter, safer, and more human. Every day, our work helps care teams perform with greater precision and patients recover faster, improving outcomes around the world.

The problems we solve demand creativity, rigor, and collaboration. The work is challenging, but deeply meaningful—because every improvement we make has the potential to change a life.

If you’re ready to contribute to something bigger than yourself and help transform the future of healthcare, you’ll find your purpose here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vision Systems Engineer
Senior Vision Systems Engineer

Socket.dev • Sunnyvale (CA)

On-site
USD 140,000 - 210,000
Staff Business Systems & Process Analyst - Engineering Business Systems
Staff Business Systems & Process Analyst - Engineering Business Systems

Socket.dev • Sunnyvale (CA)

Hybrid
USD 170,000 - 210,000
Hybrid work arrangement
Senior Strategy Manager, Global Services AI and Automation
Senior Strategy Manager, Global Services AI and Automation

Socket.dev • Sunnyvale (CA)

On-site
USD 180,000 - 260,000
Market-competitive compensation
Equity benefits
Systems Analyst (Robotic Algorithms and Controls)
Systems Analyst (Robotic Algorithms and Controls)

Socket.dev • Sunnyvale (CA)

On-site
USD 180,000 - 240,000
Service Operations Technician 2
Service Operations Technician 2

Socket.dev • Peachtree Corners (GA)

On-site
USD 55,000 - 75,000
Manager, Embedded Software Engineering - Future Forward
Manager, Embedded Software Engineering - Future Forward

Socket.dev • Sunnyvale (CA)

On-site
USD 260,000 - 350,000
Staff Embedded Software Engineer
Staff Embedded Software Engineer

Socket.dev • Sunnyvale (CA)

On-site
USD 180,000 - 240,000
Senior Quality Engineer - Endoluminal Systems
Senior Quality Engineer - Endoluminal Systems

Socket.dev • Sunnyvale (CA)

On-site
USD 140,000 - 190,000
Manager, Industrial Engineering
Manager, Industrial Engineering

Socket.dev • Sunnyvale (CA)

On-site
USD 140,000 - 190,000
Equipment Engineering - Software
Equipment Engineering - Software

Socket.dev • Sunnyvale (CA)

On-site
USD 120,000 - 180,000