Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
Governance, Risk, and Compliance and Data Privacy Office Director
Midland, MI · On-site
$180 - $260/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Midland, MI · On-site
$180 - $260/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Essexville, MI · On-site
$150 - $230/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Essexville, MI · On-site
$150 - $230/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Mount Pleasant, MI · On-site
$180 - $240/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Mount Pleasant, MI · On-site
$180 - $240/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Alma, MI · On-site
$180 - $280/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Alma, MI · On-site
$180 - $280/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
Governance, Risk, and Compliance and Data Privacy Office Director
Clare, MI · On-site
$180 - $240/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Governance, Risk, and Compliance and Data Privacy Office Director
Clare, MI · On-site
$180 - $240/hr
Own cyber security governance effectiveness - establish clear, enforceable policies, standards and ... Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes ...
New
Vice President of Cybersecurity
Detroit, MI · On-site
$160 - $210/hr
Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and regulated environments, including NIST 800‑53, NIST 800‑171, CMMC, and related federal frameworks
New
Vice President of Cybersecurity
Detroit, MI · On-site
$160 - $210/hr
Governance, Risk & Compliance (GRC) * Lead cybersecurity compliance efforts for government and regulated environments, including NIST 800‑53, NIST 800‑171, CMMC, and related federal frameworks
New
Cyber Security Architecture Manager
Detroit, MI · On-site
$109K - $148K/yr
... ensure compliance with security frameworks. Responsibilities : • Lead the design and ... governance, risk management, and secure AI adoption strategies. • Drive cloud security ...
Cyber Security Architecture Manager
Detroit, MI · On-site
$109K - $148K/yr
... ensure compliance with security frameworks. Responsibilities : • Lead the design and ... governance, risk management, and secure AI adoption strategies. • Drive cloud security ...
Governance, Risk & Compliance (GRC) * Establish & maintain company cybersecurity policies and procedures. * Oversee regional cybersecurity governance processes and ensure adherence to enterprise ...
Governance, Risk & Compliance (GRC) * Establish & maintain company cybersecurity policies and procedures. * Oversee regional cybersecurity governance processes and ensure adherence to enterprise ...
Governance, Risk & Compliance (GRC) * Establish & maintain company cybersecurity policies and procedures. * Oversee regional cybersecurity governance processes and ensure adherence to enterprise ...
Governance, Risk & Compliance (GRC) * Establish & maintain company cybersecurity policies and procedures. * Oversee regional cybersecurity governance processes and ensure adherence to enterprise ...
IT Security Analyst 2
Lansing, MI · On-site
Contract / Requirement: * 1-3 years of experience in IT Security, Cyber Security, Compliance, or a related field. * Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC ...
New
IT Security Analyst 2
Lansing, MI · On-site
Contract / Requirement: * 1-3 years of experience in IT Security, Cyber Security, Compliance, or a related field. * Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC ...
New
IT Security Analyst
Lansing, MI · Hybrid
Contract / Requirement: * 1-3 years of experience in IT Security, Cyber Security, Compliance, or a related field. * Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC ...
New
IT Security Analyst
Lansing, MI · Hybrid
Contract / Requirement: * 1-3 years of experience in IT Security, Cyber Security, Compliance, or a related field. * Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC ...
New
Minimum of seven (7) years of progressive experience in information services including three (3) years working in cybersecurity governance, risk, and compliance (GRC). * Minimum of three (3) years of ...
Minimum of seven (7) years of progressive experience in information services including three (3) years working in cybersecurity governance, risk, and compliance (GRC). * Minimum of three (3) years of ...
IT Security Analyst
Lansing, MI · On-site
Maintain security documentation within Governance, Risk, and Compliance (GRC) tools. Required Qualifications * 1-3 years of experience in Information Security, Cybersecurity, IT Compliance, Risk ...
IT Security Analyst
Lansing, MI · On-site
Maintain security documentation within Governance, Risk, and Compliance (GRC) tools. Required Qualifications * 1-3 years of experience in Information Security, Cybersecurity, IT Compliance, Risk ...
Minimum of seven (7) years of progressive experience in information services including three (3) years working in cybersecurity governance, risk, and compliance (GRC). * Minimum of three (3) years of ...
Minimum of seven (7) years of progressive experience in information services including three (3) years working in cybersecurity governance, risk, and compliance (GRC). * Minimum of three (3) years of ...
Minimum of seven (7) years of progressive experience in information services including three (3) years working in cybersecurity governance, risk, and compliance (GRC). * Minimum of three (3) years of ...
Minimum of seven (7) years of progressive experience in information services including three (3) years working in cybersecurity governance, risk, and compliance (GRC). * Minimum of three (3) years of ...
The system security plans are documented in the Governance, Risk, Compliance tool. This requires ... Michigan Cyber Security (MCS) in order to support security requirements to Go Live.
New
The system security plans are documented in the Governance, Risk, Compliance tool. This requires ... Michigan Cyber Security (MCS) in order to support security requirements to Go Live.
New
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Cybersecurity Governance Risk Compliance information
What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?
| Aspect | Cybersecurity Governance Risk Compliance | Cybersecurity Analyst |
|---|---|---|
| Certifications | CISA, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Policy development, audits, compliance frameworks | Monitoring security systems, incident response |
| Employer & Industry Usage | Organizations with compliance needs, regulatory bodies | IT security teams, cybersecurity firms |
While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.
What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?
What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?
Is cybersecurity governance risk compliance a good career?
Is cybersecurity governance risk compliance a good job?
What is cybersecurity governance, risk, and compliance (GRC)?

Governance, Risk, and Compliance and Data Privacy Office Director
Midland, MI
Full-time
Medical, Life, Retirement, PTO
Posted 9 days ago
Job description
At Dow, we believe in putting people first and we're passionate about delivering integrity, respect and safety to our customers, our employees and the planet.
Our people are at the heart of our solutions. They reflect the communities we live in and the world where we do business. Their diversity is our strength. We're a community of relentless problem solvers that offers the daily opportunity to contribute with your perspective, transform industries and shape the future. Our purpose is simple - to deliver a sustainable future for the world through science and collaboration.If you're looking for a challenge and meaningful role, you're in the right place.
About this role
Dow has an exciting opportunity for a Governance, Risk, and Compliance and Data Privacy Director located in Midland, MI or Houston, TX.
In this role, you will lead and direct multiple teams (typically through other people leaders) and apply in-depth knowledge of your area of responsibility. You will lead cyber governance, risk, compliance, data privacy, and develop and implement an evergreen enterprise-wide cyber awareness program to ensure effective risk oversight, regulatory adherence, and develop a strong cybersecurity culture.
Responsibilities - Duties, projects, tasks, and activities you would be responsible for in this role
- Own cyber security governance effectiveness - establish clear, enforceable policies, standards and control frameworks with unambiguous ownership and consistent application
- Own cyber and data privacy risk identification and visibility - ensure internal and external risks are clearly defined in central risk register, quantified and reported. Actively challenge and escalate unacceptable risk
- Own regulatory compliance and audit outcomes - ensure compliance is sustainable and audit-ready by design, with no reliance on reactive audit preparation and no recurring findings
- Own external cyber assessments and certification to enable the business (e.g. customer cyber assessment, ISO 270001, NIST CSF, etc)
- Own security culture and behavior change outcomes - drive measurable improvements in workforce cyber and data privacy behaviors
Key requirements
Risk-first mindset (non-negotiable) - uses compliance frameworks as tools, not goals; prioritizes exposure, control effectiveness and business impact
Ability to challenge the business with credibility - pushes back on weak controls and unclear risk acceptance; forces clarity on ownership and impact
Translates risks into business language - converts regulatory and control concepts into exposure, financial risk and operational impact
Governance builder (not just operator) - designs governance forums, decision rights and escalation paths that enforce accountability and consistency
Culture shaper - drives measurable shifts in how the organization thinks about and manages risk
Skills
Leadership: Demonstrates the ability to lead global teams, influence stakeholders, establish accountability, and drive enterprise-wide cybersecurity, risk, compliance, and data privacy initiatives.
Strategic Planning: Develops and implements long-term governance, risk management, compliance, and cybersecurity strategies that align with business objectives and regulatory requirements.
Decision Making: Evaluates complex cyber and privacy risks, prioritizes actions based on business impact, challenges inadequate controls, and drives informed risk acceptance decisions.
Communication: Effectively translates technical cybersecurity, regulatory, and data privacy concepts into clear business language for executives, stakeholders, and non-technical audiences.
Business Management: Oversees governance programs, compliance processes, audit readiness, risk reporting, external assessments, and organizational initiatives to ensure sustainable business outcomes.
Qualifications
A minimum of a bachelor's degree or relevant military experience at or above a U.S. E5 ranking or Canadian Petty Officer 2nd Class or Sergeant.
Minimum 10 years of progressive experience in IT and/or Cybersecurity
Demonstrated leadership experience leading diverse global teams
Deep understanding of regulatory compliance, audit readiness, and risk management in regulated industries
Strong interpersonal, communication and stakeholder engagement skills across technical and non-technical audiences.
A minimum requirement for this U.S. based position is the ability to work legally in the United States. No visa sponsorship/support is available for this position, including for any type of U.S. permanent residency (green card) process.
Note: Domestic relocation may be provided for this role. Details to be discussed at the time of offer.
Benefits - What Dow offers you
We invest in you.
Dow invests in total rewards programs to help you manage all aspects of you: your pay, your health, your life, your future, and your career.You bring your background, talent, and perspective to work every day. Dow rewards that commitment by investing in your total wellbeing.
Here are just a few highlights of what you would be offered as a Dow employee:
- Equitable and market-competitive base pay and bonus opportunity across our global markets, along with locally relevant incentives.
- Benefits and programs to support your physical, mental, financial, and social well-being, to help you get the care you need...when you need it.
- Competitive retirement program that may include company-provided benefits, savings opportunities, financial planning, and educational resources to help you achieve your long term financial-goals.
- Employee stock purchase programs (availability varies depending on location).
- Student Debt Retirement Savings Match Program (U.S. only).
- Dow will take the value of monthly student debt payments and apply them as if they are contributions to the Employees' Savings Plan (401(k)), helping employees reach the Company match.
- Robust medical and life insurance packages that offer a variety of coverage options to meet your individual needs. Travel insurance is also available in certain countries/locations.
- Opportunities to learn and grow through training and mentoring, work experiences, community involvement and team building.
- Workplace culture empowering role-based flexibility to maximize personal productivity and balance personal needs.
- Competitive yearly vacation allowance.
- Paid time off for new parents (birthing and non-birthing, including adoptive and foster parents).
- Paid time off to care for family members who are sick or injured.
- Paid time off to support volunteering and Employee Resource Group's (ERG) participation.
- Wellbeing Portal for all Dow employees, our one-stop shop to promote wellbeing, empowering employees to take ownership of their entire wellbeing journey.
- On-site fitness facilities to help stay healthy and active (availability varies depending on location).
- Employee discounts for online shopping, cinema tickets, gym memberships and more.
- Additionally, some of our locations might offer:
- Transportation allowance (availability varies depending on location)
- Meal subsidiaries/vouchers (availability varies depending on location)
- Carbon-neutral transportation incentives e.g. bike to work (availability varies depending on location)
Join our team, we can make a difference together.
About Dow
Dow (NYSE: DOW) is one of the world's leading materials science companies, serving customers in high-growth markets such as packaging, infrastructure, mobility and consumer applications.Our global breadth, asset integration and scale, focused innovation, leading business positions and commitment to sustainability enable us to achieve profitable growth and help deliver a sustainable future. We operate manufacturing sites in 30countries and employ approximately36,000 people. Dow delivered sales of approximately$43 billionin 2024. References to Dow or the Company mean Dow Inc. and its subsidiaries. Learn more about us and our ambition to be the most innovative, customer-centric, inclusive and sustainable materials science company in the world by visitingwww.dow.com.
As part of our dedication to inclusion, Dow is committed to equal opportunities in employment. We encourage every employee to bring their whole self to work each day to not only deliver more value, but also have a more fulfilling career. Further information regarding Dow's equal opportunities is available on www.dow.com.
Dow is an Equal Employment Opportunity employer and is committed to providing opportunities without regard for race, color, religion, sex, including pregnancy, sexual orientation, or gender identity, national origin, age, disability and genetic information, including family medical history. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may call us at 1-833-My Dow HR (833-693-6947) and select option 8.