Director of Cyber Risk & Assurance
$185,000–$225,000 year
Hybrid · Madison, Wisconsin, United States
Job Summary
Leads the enterprise-wide cyber risk and assurance function within the Enterprise IT Security team, establishing a risk-based approach to cybersecurity governance, compliance, assurance, and regulatory readiness. Defines the cyber risk framework, control ownership model, and assurance practices that support regulatory obligations, business needs, and the Enterprise Cyber Resilience operating model. Oversees issue and POA&M governance, cybersecurity awareness, automation, AI cyber enablement, and M&A-related cyber risk support; drives governance, remediation accountability, and measurable cybersecurity maturity.
Required Qualifications
- U.S. citizenship is required for this position due to Department of Defense restrictions.
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Risk Management, Business, or related field; equivalent combination of education and relevant experience may be considered.
- 10 or more years of progressive experience in cybersecurity, technology risk, information security governance, security assurance or related risk functions.
- 5 or more years in a leadership role in cybersecurity risk, GRC, assurance, technology risk, or cyber governance.
- Demonstrated experience building or maturing a risk-based cybersecurity governance, risk, compliance, or assurance program.
- Strong knowledge of cybersecurity control frameworks and regulatory expectations such as NIST CSF, NIST SP 800-53, NIST SP 800-171, HIPAA, CMS security requirements, CMMC, SOC 1/SOC 2, ISO 27001, or comparable frameworks.
- Proven experience using workflow automation, GRC tools, reporting dashboards, or process automation to improve risk, compliance, assurance, evidence collection, and remediation workflows.
- Working knowledge of AI-related cybersecurity risk, safe-use governance, AI policy considerations, or AI-enabled workflow automation.
- Demonstrated ability to translate complex technical control gaps into clear business‐risk implications and prioritized remediation strategies, paired with strong executive‐level communication, presentation, and stakeholder‐leadership skills.
Additional Requirements
- U.S. citizenship required for position due to DoD restrictions.
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.