AppFolio logo
AppFolioPosted 2 weeks ago

Director, Enterprise Risk

$184,000–$230,000 year

On-siteColorado, United States

Part TimeSenior LevelLarge

Job Summary

Mature and integrate the Enterprise Risk Management (ERM) framework while leading the Technology Compliance function and building a new Risk Analysis capability. Partner with first-line teams to embed risk-informed decision-making and stand up a continuous risk-identification cadence that surfaces emerging risks in real time. Own compliance policies, audit readiness for SOX and SOC reviews, and support the Common Controls Framework. Assist management with risk reporting to the Board and communicate updates to executive committees. Advance the three-lines-of-defense model and align ERM activity with company OKRs. This role involves reporting to senior leadership and requires extensive experience in enterprise risk, GRC, and technology compliance.

Required Qualifications

  • Extensive experience in enterprise risk management, GRC, internal audit, or a closely related second-line function, including maturing or scaling an ERM program.
  • A track record of building and leading teams, developing talent through individual development plans (IDPs), and planning succession for key roles.
  • Strong command of enterprise risk frameworks and the three-lines-of-defense model (e.g., COSO ERM), plus working knowledge of technology compliance domains such as SOX ITGCs and SOC 1 / SOC 2.
  • Demonstrated ability to influence senior leaders and to communicate risk clearly to executive and Board-level audiences, including audit or risk committees.
  • Experience partnering with first-line functions — ideally R&D, Product, or Engineering — to embed risk-informed decision-making without slowing the business.
  • A data-driven approach to risk monitoring, including defining risk metrics and enhancing monitoring and reporting capabilities.
  • 5+ years of progressive experience in enterprise risk management, internal audit, GRC, or technology compliance, including direct people-leadership experience.
  • Deep, hands-on understanding of enterprise risk frameworks and the three-lines-of-defense model, with experience operating or maturing an ERM program.
  • Proven ownership of technology compliance and audit readiness (SOX and/or SOC), including serving as a primary liaison to internal and external auditors.
  • Excellent executive communication and stakeholder-management skills, with experience reporting to senior leadership and/or a Board committee.
  • Must have a valid driver's license

Desired Qualifications

  • Relevant professional certifications are a plus (e.g., CRISC, CRMA, CISA, CPA, or CISSP).
  • Experience partnering with first-line functions — ideally R&D, Product, or Engineering — to embed risk-informed decision-making without slowing the business.

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce