Director, Governance, Risk & Compliance
$180,000–$230,000 year
HybridRedwood City, California, United States
Job Summary
Own the end-to-end GRC roadmap for multi-jurisdictional certifications spanning FedRAMP, ISO 27001, SOC 2, UAE DESC, Saudi NCA/CCC, and Australia IRAP. Prioritize and sequence certification efforts against GTM targets while serving as the primary liaison with assessors, auditors, and regulatory bodies. Manage FedRAMP ATO maintenance, continuous monitoring, and documentation quality alongside ISO 27001 ISMS evolution and SOC 2 Type II audit readiness. Build a unified controls framework to map overlapping requirements and partner with engineering teams to ensure security controls are designed in. Own the enterprise risk register, vendor risk management, and support customer due diligence and board reporting. This builder role drives compliance as a competitive differentiator to unlock new markets for Anomali's AI-native SOC platform.
Required Qualifications
- 8+ years in GRC, information security compliance, or related audit/assurance roles
- 3+ years in a leadership capacity
- Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner
- Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
- Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
- Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
- Familiarity with Australia IRAP assessment process
- Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
- Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
- Exceptional written communication skills (SSPs, policies, board-level reporting)
- For candidates residing within commutable distance of Redwood City, CA, this position will be hybrid
- Remote candidates based in the US, will also be considered
- This position is not eligible for employment visa sponsorship
- The successful candidate must not now, or in the future, require visa sponsorship to work in the US
Desired Qualifications
- Certifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer
- Experience in a high-growth, venture-backed SaaS or cybersecurity company
- Prior experience managing multiple concurrent certifications across regions
- Experience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.