Director of Governance Risk and Compliance
Salary undisclosed
Apply on
Availability Status
This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.
Original
Simplified
- JOB-7098
- Director of Governance Risk and Compliance
- Permanent
- Link Technologies (LinkTechConsulting.com), a Las Vegas-based IT consulting firm, is currently seeking a Director of Governance of Risk and Compliance to join our team.
JOB DESCRIPTION
This role leads the company's GRC initiatives, overseeing the IT and security GRC program and ensuring technology compliance. Key responsibilities include implementing policies, maintaining a controls framework, and managing global third-party risk. This position protects the company's technical systems and information assets, identifies and reports on significant security risks, and collaborates with cybersecurity, legal, and compliance teams to align technologies with compliance and security objectives. Success requires the ability to influence GRC strategy across both new and legacy systems. The position reports to executive leadership in security or risk management.
QUALIFICATIONS
- Bachelor's degree in Computer Science, Information Assurance, MIS, or a related field, or equivalent experience; an advanced degree is not required, but an MBA or Master's in Information Assurance/Technology is preferred.
- Minimum of 10 years of experience in cybersecurity, including roles such as security analyst, compliance, risk management, or audit.
- Minimum of five (5) years of experience managing a distributed team.
- Proven leadership skills with a strong understanding of regulatory requirements and laws such as PCI, SOX, HIPAA, GDPR, and GLBA.
- Demonstrated experience in leading projects involving both legacy and emerging technologies to assess and manage business risk while enforcing security controls.
- Preferably a minimum of two (2) years of experience with cloud security in AWS, Google Cloud Platform (Google Cloud Platform), and/or Microsoft Azure.
- Solid understanding of business operations and the ability to integrate cybersecurity into business processes through influence and teamwork.
- Strong organizational and team management skills, with a proven track record of delivering GRC projects on tight deadlines.
- High integrity, professionalism, and the confidence to represent the company and security leadership with credibility.
- Experience conducting tabletop exercises for business continuity planning.
- Ability to work effectively with diverse teams and promote a positive, enterprise-wide security culture.
- Exceptional project management, multitasking, and organizational abilities.
- Ability to build and maintain credibility with internal and external stakeholders through ongoing industry expertise.
- Proven ability to motivate and mentor team members to achieve excellence and share knowledge willingly.
- Act as a key point of contact when GRC team members identify risk to raise awareness with security management and business unit leads on a risk reduction plan.
- Play a key role in the vendor risk assessment process and ensure all business units follow and uphold process rigor.
- Create, prioritize, and manage the yearly scope of technology compliance obligations.
- Identify, document, and monitor to closure any gaps when compliance responsibilities are not met.
- Oversee findings brought forward through team analysis, requiring thorough documentation and recommendations to report to security leadership where gaps exist.
- Engage in continuous professional development with team management, honing direction as well as strategic plans.
- Maintain a high degree of knowledge with current and proposed security changes impacting regulatory, privacy and security industry best practice guidance.
- Effectively communicate knowledge of GRC controls across business units with a focus on, but not limited to, company practices, procedures, third-party integrations, product development and financials.
- Influence and validate metrics used in assessment of security program success and report them regularly to security and business leadership.
- Focus on principles aligning with enterprise risk management fundamentals within security and technology teams to maintain up-to-date configuration documentation for systems and processes.
- Lead a team to provide rigorous oversight of security systems and security configuration administration that reduces risk to enterprise systems and accounts.
- Appoint team members to stay abreast in incident response cases and track occurrence and resolution, with strict documentation and reporting.
- Guide team members to align with security, audit, and risk management leadership for ongoing security program assessments, as well as annual strategic technology and budgetary directives.
- Liaison with auditors, both internal and external, to maintain and implement controls for compliance and privacy laws.
- Provide leadership for disaster recovery and business continuity as they relate to security frameworks, compliance, and privacy laws.
- Inspire business units to adopt cybersecurity security controls to reduce the attack surface.
- Openly support the CISO, management team and executive leadership, even during tumultuous times. Perform other duties as assigned.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job Similar Jobs