1

Director It Governance Risk Compliance Jobs (NOW HIRING)

... Compliance, and Audit stakeholders to identify risks, strengthen controls, and support regulatory and governance requirements. ESSENTIAL RESPONSIBILITIES MAY INCLUDE * Leads the enterprise IT risk ...

... Compliance, and Audit stakeholders to identify risks, strengthen controls, and support regulatory and governance requirements. ESSENTIAL RESPONSIBILITIES MAY INCLUDE * Leads the enterprise IT risk ...

next page

Showing results 1-20

Director It Governance Risk Compliance information

See salary details

$42.5K

$128.3K

$199.5K

How much do director it governance risk compliance jobs pay per year?

As of Aug 22, 2026, the average yearly pay for director it governance risk compliance in the United States is $128,297.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,000.00 and $145,000.00 per year, depending on experience, location, and employer.

What does a director of IT governance, risk, and compliance do?

A Director of IT Governance, Risk, and Compliance (GRC) is responsible for overseeing an organization's IT policies, risk management strategies, and compliance with internal and external regulations. They ensure that the company's information systems are secure, compliant with relevant laws and standards, and aligned with business objectives. Their duties include developing frameworks for IT governance, managing risk assessments, and coordinating audits. They also lead teams to implement best practices and mitigate potential threats to information security.

What are the key skills and qualifications needed to thrive as a director of IT governance, risk, and compliance?

To thrive as a Director of IT Governance, Risk, and Compliance, you need deep expertise in risk management, regulatory frameworks (such as SOX, GDPR, or HIPAA), and IT governance principles, typically supported by a bachelor's or master's degree in information security or a related field. Familiarity with GRC platforms (like RSA Archer or ServiceNow), cybersecurity tools, and certifications such as CISA, CISM, or CISSP is highly valued. Outstanding leadership, strategic thinking, and communication skills are essential for collaborating with stakeholders and leading cross-functional initiatives. These competencies are crucial to ensure organizational compliance, minimize risk exposure, and align IT strategies with business objectives.

What are the most common challenges faced by a director of IT governance, risk, and compliance when aligning IT policies with business goals?

A Director of IT Governance, Risk, and Compliance often faces challenges in ensuring IT policies and procedures are not only regulatory-compliant but also flexible enough to support the company's strategic business objectives. Balancing risk mitigation with the need for technological innovation can be complex, especially when different departments have varying priorities. Building strong cross-functional relationships and maintaining clear communication with business leaders are key to successfully aligning IT governance frameworks with organizational goals. Additionally, staying updated with rapidly evolving regulations and emerging threats requires continuous learning and adaptation.

What is the difference between Director It Governance Risk Compliance vs IT Risk Manager?

AspectDirector It Governance Risk ComplianceIT Risk Manager
CertificationsCISA, CISSP, CRISCCISA, CISSP, CRISC
Work EnvironmentStrategic, leadership-focused, cross-departmentalOperational, technical, risk assessment tasks
Employer & Industry UsageFinancial, healthcare, large enterprisesFinancial, tech, consulting firms

The main difference is that the Director It Governance Risk Compliance oversees overall governance strategies and compliance at a senior level, while the IT Risk Manager focuses on identifying and mitigating specific IT risks. Both roles require similar certifications and work in related environments, but the director has broader strategic responsibilities.

More about Director It Governance Risk Compliance jobs

What cities are hiring for Director It Governance Risk Compliance jobs?

Cities with the most Director It Governance Risk Compliance job openings:

What are the most commonly searched types of It Governance Risk Compliance jobs?

The most popular types of It Governance Risk Compliance jobs are:

What states have the most Director It Governance Risk Compliance jobs?

States with the most job openings for Director It Governance Risk Compliance jobs include:

Infographic showing various Director It Governance Risk Compliance job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $128,297 per year, or $61.7 per hour.

Director, IT Governance, Risk, Compliance & AI

General Dynamics Mission Systems, Inc

Scottsdale, AZ • On-site

Full-time

Posted 4 days ago


General Dynamics Mission Systems rating

8.1

Company rating: 8.1 out of 10

Based on 31 frontline employees who took The Breakroom Quiz

114th of 246 rated software companies


Job description

Master's degree + minimum 13 years of demonstrated leadership experience; or Bachelor's degree in a related specialized area or equivalent combination of education and relevant work experience + minimum 15 years of demonstrated leadership experience.

CLEARANCE REQUIREMENTS:
Department of Defense Secret security clearance is preferred at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.


General Dynamics Mission Systems is seeking a Director, IT Governance, Risk, Compliance & AI to lead the enterprise governance function across information technology, cybersecurity, privacy, data, financial systems, and artificial intelligence. Reporting to the Chief Data & AI Officer (CDAIO), who has assumed the broader enterprise technology, data, AI, and governance portfolio, this director will establish and operate an integrated, risk-based governance model that protects the company, enables disciplined innovation, and improves the speed and quality of decision-making.

The director will partner across Business Operations, Cybersecurity, Finance, Legal, Privacy, Internal Audit, Contracts, Engineering, Supply Chain, programs, and business leadership. The successful candidate will translate complex regulatory, contractual, technical, and business requirements into clear policies, practical controls, measurable accountability, and sustainable operating practices. They will bring bold ideas and deep expertise while building upon and advancing an established vision. Success in this role requires both strong individual contribution and the ability to collaborate across CDAIO teams and enterprise partners, harness collective capabilities, and strengthen the organization’s overall effectiveness.

Key Responsibilities

  • Lead the enterprise IT governance, risk, and compliance strategy and operating model, ensuring alignment with business objectives, mission needs, regulatory obligations, and the enterprise technology, data, and AI strategy.
  • Direct and develop a multidisciplinary governance organization; establish priorities, performance expectations, succession capability, and a culture of accountability, continuous improvement, and customer focus.
  • Own the development, maintenance, communication, and enforcement of IT governance policies, standards, procedures, control frameworks, exception processes, and accountability mechanisms.
  • Lead governance and assurance for IT general controls, application controls, access management, change management, configuration management, vulnerability management, secure development, third-party services, and other technology risks.
  • Oversee SOX-related IT controls and partner with Finance, Internal Audit, external auditors, and system owners on control design, testing, evidence, deficiencies, remediation, and closure.
  • Partner with the CISO and cybersecurity organization to govern security risk, policy, exceptions, risk acceptance, compliance assessments, remediation, and executive reporting without duplicating operational security ownership.
  • Drive compliance readiness for applicable frameworks and contractual requirements, including NIST, CMMC, DFARS, privacy, controlled unclassified information, export-controlled information, and customer obligations.
  • Establish AI governance within the enterprise GRC model, including risk tiering, acceptable use, use-case intake, data and privacy safeguards, third-party AI risk, human oversight, documentation, monitoring, and lifecycle controls.
  • Partner with AI strategy, delivery, data, engineering, and cybersecurity leaders to make the responsible path for AI adoption clear, efficient, and proportionate to risk; identify opportunities to use AI to improve governance operations and control monitoring.
  • Lead internal and external audit coordination across IT, cybersecurity, privacy, data, and AI; ensure evidence is audit-ready, findings have accountable owners and due dates, and corrective actions are validated to closure.
  • Develop executive-level governance, risk, compliance, and AI reporting, including meaningful metrics, risk trends, control health, audit posture, remediation progress, and investment priorities.
  • Govern IT programs and projects at defined decision points to assess strategic alignment, risk, controls, compliance, resource use, and expected business value.
  • Plan and manage the department budget; identify opportunities to simplify, standardize, automate, and continuously improve governance processes and service delivery.
  • Build trusted relationships across geographically dispersed teams and influence senior stakeholders through clear communication, sound judgment, and practical risk recommendations.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Risk Management, Business, or a related field, or an equivalent combination of education and relevant experience, plus at least 15 years of demonstrated leadership experience; or a master's degree plus at least 13 years of demonstrated leadership experience.
  • Substantial leadership experience in IT governance, risk, compliance, information security, audit, or related enterprise technology functions within a highly regulated environment.
  • Demonstrated experience leading complex, geographically dispersed technical organizations and developing leaders and technical professionals.
  • Strong knowledge of IT control frameworks and risk methodologies, including relevant NIST frameworks, COBIT, ITIL, ISO 27001, and/or comparable standards.
  • Demonstrated experience with IT SOX controls, audit coordination, control testing, remediation management, and executive reporting.
  • Working knowledge of defense-industry and government-contracting requirements relevant to technology governance, including CMMC, NIST SP 800-171/172, DFARS, CUI, and supplier or third-party risk, as applicable.
  • Knowledge of AI governance principles, including responsible AI, model and data risk, privacy, security, human oversight, third-party AI services, AI lifecycle controls, and the NIST AI Risk Management Framework or comparable practices.
  • Ability to assess risk pragmatically and translate legal, regulatory, contractual, and technical requirements into clear, executable business actions.
  • Excellent executive communication, presentation, relationship-building, organizational-change, and influence skills.

Preferred Qualifications

  • Professional certifications such as CISSP, CISM, CISA, CRISC, CIPP, PMP, CGEIT, or comparable credentials.
  • Experience implementing scalable governance workflows, continuous control monitoring, automated evidence collection, or governance tooling.
  • Experience governing AI-enabled business processes, generative AI, or agentic AI use cases in a regulated or mission-focused environment.
  • Experience with privacy-by-design, enterprise data governance, cloud governance, and third-party technology or supply-chain risk management.
  • Active security clearance or ability to obtain and maintain a clearance, as required by position access.

This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled.
USD $201,481.00 - USD $218,009.00 /Yr.

General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!


Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans


What General Dynamics Mission Systems employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom