1

Director Security Governance Risk Compliance Jobs

$112K - $236K/yr

Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: Position Overview The primary purpose ...

next page

Showing results 1-20

Director Security Governance Risk Compliance information

See salary details

$42.5K

$128.3K

$199.5K

How much do director security governance risk compliance jobs pay per year?

As of Sep 10, 2026, the average yearly pay for director security governance risk compliance in the United States is $128,297.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,000.00 and $145,000.00 per year, depending on experience, location, and employer.

What does a director of security governance, risk, and compliance do?

A Director of Security Governance, Risk, and Compliance (GRC) is responsible for overseeing an organization’s information security policies, risk management processes, and compliance with relevant regulations and standards. They develop and implement strategies to identify, assess, and mitigate security risks, ensuring that the organization meets legal and industry requirements. The role also involves coordinating audits, managing security frameworks, and fostering a culture of security awareness across the company. Directors of GRC often work closely with executive leadership and IT teams to align security initiatives with business objectives.

How does a director of security governance, risk, and compliance typically collaborate with other departments to ensure effective risk management?

A Director of Security Governance, Risk, and Compliance (GRC) works closely with IT, legal, audit, and business operations teams to identify, assess, and address security risks across the organization. This collaboration often involves regular cross-functional meetings, policy development workshops, and coordinated risk assessments to ensure alignment with industry regulations and company objectives. Effective communication and relationship-building are key, as the role requires translating complex compliance requirements into actionable guidance for non-technical stakeholders. By fostering a culture of security awareness and accountability, the Director helps ensure that security and compliance are integrated into daily business processes.

What are the key skills and qualifications needed to thrive as a director of security governance, risk, and compliance, and why are they important?

To thrive as a Director of Security Governance, Risk, and Compliance, you need deep knowledge of risk management, information security frameworks (such as ISO 27001, NIST), and a relevant degree or certification like CISSP or CISM. Familiarity with GRC tools, security auditing platforms, and regulatory compliance systems is essential in this role. Strong leadership, strategic thinking, and effective communication skills help you drive organizational change and align security practices with business objectives. These skills and qualities are crucial for ensuring regulatory compliance, minimizing security risks, and safeguarding organizational assets.

What is the difference between Director Security Governance Risk Compliance vs Security Manager?

AspectDirector Security Governance Risk ComplianceSecurity Manager
CertificationsCISSP, CISM, CRISCCISSP, Security+
Work EnvironmentStrategic, executive-level, policy developmentOperational, team management, security operations
ResponsibilitiesOversees security governance, risk management, compliance programsManages security teams, implements security measures
Industry UsageCommon in large organizations, corporate security departmentsFound across various industries, including corporate and government

The main difference is that the Director Security Governance Risk Compliance focuses on strategic oversight, policy, and compliance at an executive level, while the Security Manager handles day-to-day security operations and team management. Both roles require relevant certifications, but their scope and responsibilities differ significantly.

What cities are hiring for Director Security Governance Risk Compliance jobs?

Cities with the most Director Security Governance Risk Compliance job openings:

What states have the most Director Security Governance Risk Compliance jobs?

States with the most job openings for Director Security Governance Risk Compliance jobs include:

What are popular job titles related to Director Security Governance Risk Compliance jobs?

For Director Security Governance Risk Compliance jobs, the most frequently searched job titles are:

Director, Governance, Risk & Compliance

Lehi, UT • On-site

MX Technologies, Inc.
501 - 1,000 employees

Full-time

Re-posted 10 days ago


Job description

As we continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across Security, Engineering, Legal, Product, Sales, Customer Success, and Operations to ensure MX maintains industry-leading security and privacy standards while enabling the business to move quickly and responsibly.

Reporting directly to the VP & Chief Information Security Officer (CISO), you will lead the Compliance team and own the strategy, execution, and continuous improvement of MX's security governance, privacy, and regulatory compliance programs.

 What You'll DoLead Governance, Risk & Compliance
  • Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy.
  • Build, mature, and continuously improve security, privacy, and risk management programs that align with business objectives and regulatory requirements.
  • Develop, maintain, and operationalize enterprise-wide security policies, standards, controls, and governance processes.
  • Establish scalable compliance frameworks that support continued company growth while reducing organizational risk.
Own Privacy & Regulatory Compliance
  • Lead the company's global privacy program across multiple jurisdictions.
  • Ensure compliance with applicable privacy regulations, including GDPR, CCPA, HIPAA, PIPEDA, UK Data Protection Act, and other emerging regulations.
  • Partner with Legal, Engineering, Product, and business stakeholders to perform Privacy Impact Assessments (PIAs) and advise on privacy requirements throughout the product lifecycle.
  • Develop governance frameworks for responsible data collection, storage, processing, retention, and sharing.
  • Oversee data mapping initiatives, vendor privacy reviews, and data governance practices.
Manage Audits & Customer Assurance
  • Own all internal and external security, privacy, and compliance audits.
  • Lead certification efforts including SOC 2, ISO 27001, PCI DSS, and other applicable frameworks.
  • Serve as the executive owner for customer security and privacy questionnaires.
  • Partner with Sales and Customer Success to support enterprise customer due diligence and security reviews.
Drive Risk Management
  • Continuously assess organizational security, compliance, and privacy risks.
  • Monitor effectiveness of security controls and recommend improvements where necessary.
  • Build reporting and metrics that provide executive leadership visibility into organizational risk posture.
  • Develop mitigation strategies and partner across engineering and operations to reduce risk.
Lead & Develop the Team
  • Lead, mentor, and grow a high-performing Compliance and Privacy team.
  • Foster a culture of accountability, operational excellence, and continuous improvement.
  • Develop scalable processes that improve efficiency while maintaining regulatory compliance.
Build Cross-Functional Partnerships
  • Partner closely with Security, Engineering, Legal, Product, Sales, Support, and Operations to embed security and privacy into business processes.
  • Influence stakeholders across the organization to balance business objectives with regulatory obligations.
  • Lead company-wide privacy and compliance awareness initiatives and employee training programs.
Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Business, Legal Studies, or a related field.
  • 10+ years of experience leading Information Security Governance, Risk, Compliance, Privacy, or Security Operations programs.
  • Deep expertise with compliance frameworks
  • Experience implementing Governance, Risk & Compliance (GRC) platforms and common control frameworks.
Preferred Qualifications
  • Professional certifications such as: CIPP, CIPM, CIPT, CISM, CISA
  • Experience working within fintech or highly regulated industries.
  • Knowledge of Business Continuity Planning and Disaster Recovery.
  • Experience supporting multinational organizations with global regulatory requirements.
  • Familiarity with Web Application Firewalls (WAFs), Content Delivery Networks (CDNs), and modern cloud infrastructure.
Â