IT Sr Director, Compliance and Risk Governance

Intuitive

Sunnyvale (CA)

On-site

USD 180,000 - 300,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Intuitive in Sunnyvale is seeking a senior leader to provide strategic oversight of the enterprise Cybersecurity Governance, Risk, and Compliance (GRC) program. This role establishes the vision, operating model, and governance framework to identify, assess, manage, and communicate cybersecurity and technology risks across the organization.

You will lead governance forums, develop KPIs/KRIs, drive automation, and partner with executives to balance risk with business objectives, ensuring

Responsibilities

  • Define, implement, and mature the enterprise cybersecurity governance framework with policies, standards, and procedures.
  • Lead governance forums, steering committees, and executive reviews for accountable decision-making.
  • Develop KPIs, KRIs, and dashboards to measure program effectiveness and risk posture.
  • Drive governance modernization through automation, process optimization, and data-driven support.
  • Lead enterprise cybersecurity risk management, including risk assessment methodologies and reporting.
  • Partner with business and technology leaders to balance security with operational efficiency.
  • Oversee compliance programs for ISO 27001, ISO 27036, NIST CSF, and AI risk management.
  • Manage third-party risk governance with Procurement, Legal, Privacy, and stakeholders.
  • Advise senior leadership on cybersecurity risk, governance, and compliance matters.
  • Build and develop a high-performing team, set goals, budgets, and program investments.

Job description

Job Description

Primary Function of Position:
Responsible for providing strategic leadership and oversight of the enterprise
Cybersecurity Governance, Risk, and Compliance (GRC) program. This role
establishes the vision, operating model, and governance framework necessary to
effectively identify, assess, manage, and communicate cybersecurity and
technology risks across the organization. Serves as a trusted advisor to senior
leadership, business stakeholders, and technology teams, ensuring that
cybersecurity risk management practices align with organizational objectives,
regulatory requirements, and industry best practices. This leader drives a risk-
informed culture and enables the business to innovate securely while maintaining
compliance and operational resilience.

Roles & Responsibilities
Cybersecurity Governance
  • Define, implement, and continuously mature the enterprise cybersecurity governance framework, including policies, standards, procedures, and oversight mechanisms.
  • Establish strategic direction for cybersecurity governance, ensuring alignment with corporate objectives, risk appetite, and business priorities.
  • Lead governance forums, steering committees, and executive reviews to drive accountability and informed decision-making.
  • Develop and monitor key performance indicators (KPIs), key risk indicators (KRIs), and executive dashboards that measure program effectiveness and organizational risk posture.
  • Drive governance modernization initiatives through automation, process optimization, and data-driven decision support.
Enterprise Risk Management
  • Lead the enterprise cybersecurity risk management program, ensuring risks are identified, assessed, prioritized, mitigated, and monitored effectively.
  • Develop risk assessment methodologies and reporting frameworks that provide actionable insights to executive leadership.
  • Partner with business and technology leaders to implement risk mitigation strategies that balance security, operational efficiency, and business objectives.
  • Facilitate enterprise-level risk discussions and support strategic decision-making by translating technical and cyber risks into business-relevant impacts.
Compliance Oversight
  • Establish and maintain programs to ensure compliance with applicable regulations, standards, and industry frameworks, including ISO 27001, ISO 27036, NIST Cybersecurity Framework (CSF), as well as other relevant frameworks such as AI risk management.
  • Lead internal and external audits, assessments, and regulatory reviews.
  • Ensure remediation activities are effectively managed and tracked through closure.
  • Monitor emerging regulatory requirements and industry developments, advising leadership on compliance obligations and risk implications.
Third-Party Risk Management
  • Establish and oversee governance processes for evaluating and monitoring third-party cybersecurity and technology risks.
  • Collaborate with Procurement, Legal, Privacy, and business stakeholders to assess vendor security posture and contractual risk requirements.
  • Drive continuous improvement of supplier risk management practices to support organizational resilience and compliance objectives.
Engagement & Business Partnership
  • Serve as key advisor to senior leadership on cybersecurity risk, governance, and compliance matters.
  • Provide clear, concise, and impactful reporting to executive leadership and governance bodies.
  • Influence strategic business initiatives by integrating security, risk, and compliance considerations into planning and execution activities.
  • Foster strong partnerships across business functions to promote risk-aware decision-making and regulatory readiness.
Leadership & Organizational Development
  • Build, lead, and develop a high-performing team of cybersecurity governance, risk, and compliance professionals.
  • Establish organizational goals, resource strategies, and performance expectations aligned with enterprise priorities.
  • Manage departmental budgets, strategic planning activities, and program investments.
  • Champion a culture of accountability, transparency, continuous improvement, and risk awareness throughout the organization.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Director, Governance, Risk, and Compliance (GRC)
Sr. Director, Governance, Risk, and Compliance (GRC)

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Director, Cyber Risk
Director, Cyber Risk

Asurion • Sterling (IL)

On-site
USD 190,000 - 270,000