1

Director Security Governance Risk Compliance Jobs

Showing results 21-40

Director Security Governance Risk Compliance information

See salary details

$42.5K

$128.3K

$199.5K

How much do director security governance risk compliance jobs pay per year?

As of Sep 10, 2026, the average yearly pay for director security governance risk compliance in the United States is $128,297.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,000.00 and $145,000.00 per year, depending on experience, location, and employer.

What does a director of security governance, risk, and compliance do?

A Director of Security Governance, Risk, and Compliance (GRC) is responsible for overseeing an organization’s information security policies, risk management processes, and compliance with relevant regulations and standards. They develop and implement strategies to identify, assess, and mitigate security risks, ensuring that the organization meets legal and industry requirements. The role also involves coordinating audits, managing security frameworks, and fostering a culture of security awareness across the company. Directors of GRC often work closely with executive leadership and IT teams to align security initiatives with business objectives.

How does a director of security governance, risk, and compliance typically collaborate with other departments to ensure effective risk management?

A Director of Security Governance, Risk, and Compliance (GRC) works closely with IT, legal, audit, and business operations teams to identify, assess, and address security risks across the organization. This collaboration often involves regular cross-functional meetings, policy development workshops, and coordinated risk assessments to ensure alignment with industry regulations and company objectives. Effective communication and relationship-building are key, as the role requires translating complex compliance requirements into actionable guidance for non-technical stakeholders. By fostering a culture of security awareness and accountability, the Director helps ensure that security and compliance are integrated into daily business processes.

What are the key skills and qualifications needed to thrive as a director of security governance, risk, and compliance, and why are they important?

To thrive as a Director of Security Governance, Risk, and Compliance, you need deep knowledge of risk management, information security frameworks (such as ISO 27001, NIST), and a relevant degree or certification like CISSP or CISM. Familiarity with GRC tools, security auditing platforms, and regulatory compliance systems is essential in this role. Strong leadership, strategic thinking, and effective communication skills help you drive organizational change and align security practices with business objectives. These skills and qualities are crucial for ensuring regulatory compliance, minimizing security risks, and safeguarding organizational assets.

What is the difference between Director Security Governance Risk Compliance vs Security Manager?

AspectDirector Security Governance Risk ComplianceSecurity Manager
CertificationsCISSP, CISM, CRISCCISSP, Security+
Work EnvironmentStrategic, executive-level, policy developmentOperational, team management, security operations
ResponsibilitiesOversees security governance, risk management, compliance programsManages security teams, implements security measures
Industry UsageCommon in large organizations, corporate security departmentsFound across various industries, including corporate and government

The main difference is that the Director Security Governance Risk Compliance focuses on strategic oversight, policy, and compliance at an executive level, while the Security Manager handles day-to-day security operations and team management. Both roles require relevant certifications, but their scope and responsibilities differ significantly.

What cities are hiring for Director Security Governance Risk Compliance jobs?

Cities with the most Director Security Governance Risk Compliance job openings:

What states have the most Director Security Governance Risk Compliance jobs?

States with the most job openings for Director Security Governance Risk Compliance jobs include:

What are popular job titles related to Director Security Governance Risk Compliance jobs?

For Director Security Governance Risk Compliance jobs, the most frequently searched job titles are:

Principal Security Governance, Risk & Compliance Analyst

Boston, MA • On-site

CarGurus
Internet and IT • 1 - 5K employees

$135K - $168K/yr

Full-time

Posted 19 days ago


Job description

Who we are
At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we're the largest and fastest-growing automotive marketplace, and we've been profitable for over 15 years.
What we do
The market is evolving, and we are too, moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing, purchase, and delivery of a new one. Today, tens of millions of consumers visit CarGurus.com each month, and ~30,000 dealerships use our products. But they're not the only ones who love CarGurus-our employees do, too. We have a people-first culture that fosters kindness, collaboration, and innovation, and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride!
Role overview
The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus' cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.
The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus' continued growth.
What you'll do
  • Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program.
  • Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
  • Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
  • Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
  • Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
  • Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
  • Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
  • Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
  • Lead third-party security risk management activities and vendor security assessments.
  • Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
  • Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
  • Develop executive reporting on cyber risk, compliance posture, and key security metrics.
  • Drive automation and continuous improvement across GRC processes and controls.

What you'll bring
  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance programs.
  • Experience supporting SOX ITGCs in partnership with Internal Audit.
  • Experience building AI governance frameworks and conducting AI security and risk assessments.
  • Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
  • Excellent executive communication skills with the ability to influence technical and business stakeholders.

The displayed range represents the expected annual base salary / On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings, which applies exclusively to sales roles.
Individual pay within this range is determined by work location and other factors such as job-related skills, experience, and relevant education or training.
This annual base salary forms part of a comprehensive Total Rewards Package. In addition to benefits, this role may qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs).
Position Pay Range
$135,000-$168,000 USD
Working at CarGurus
We reward our Gurus' curiosity and passion with best-in-class benefits and compensation, including equity for all employees, both when they start and as they continue to grow with us. Our career development and corporate giving programs, as well as our employee resource groups (ERGs) and communities, help people build connections while making an impact in personally meaningful ways. A flexible hybrid model and robust time off policies encourage work-life balance and individual well-being. Thoughtful perks like daily free lunch, a new car discount, meditation and fitness apps, commuting cost coverage, and more help our people create space for what matters most in their personal and professional lives.
CarGurus may require in-person interviews as part of our hiring process, particularly for positions based in our Boston and Dublin offices. Candidates selected for an in-person interview will be notified in advance. Please be aware that travel expenses are the responsibility of the candidate.
We welcome all
CarGurus strives to be a place to which people can bring the ultimate expression of themselves and their potential-starting with our hiring process. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. We foster an inclusive environment that values people for their skills, experiences, and unique perspectives. That's why we hope you'll apply even if you don't check every box listed in the job description. We also encourage you to tell your recruiter if you require accommodations to participate in our hiring process due to a disability so we can provide the appropriate support. We want to know what only you can bring to CarGurus. #LI-Hybrid