Senior Director, GRC
$264,000–$363,000 year
On-siteSan Francisco, California, United States
Job Summary
Execute AI-first transformation by integrating agentic tools into daily GRC operations, including automated evidence collection, risk scoring, and intelligent policy mapping. Operationalize the enterprise AI risk and governance framework to address training data protection, model risk management, and alignment with NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification while maintaining global compliance posture across SOC 1/2/3, ISO 27001, PCI-DSS, and CSA STAR. Direct high-impact vendor risk assessments and serve as the primary executive lead for internal/external audits, driving engineering-led remediation of control gaps. Collaborate with Product Management, Legal, Privacy, and Infrastructure teams to align security policies with commercial objectives.
Required Qualifications
- 10+ years of progressive leadership in Security GRC within a high-growth SaaS, cloud-first, or enterprise technology environment
- Demonstrated understanding of AI/ML governance challenges, including generative and agentic AI security, data lineage and global AI regulatory landscapes
- Extensive track record managing compliance for enterprise cloud environments
- Deep knowledge of risk management methodologies and the ability to translate complex technical risks into operational context for executives
- Track record of recruiting, mentoring, and retaining high-performing, technical GRC engineering and risk management professionals
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.