IT Security Director, GRC Strategy, Platforms & Architecture Lead
Listed on 2026-01-10
-
IT/Tech
Cybersecurity, Data Security, IT Consultant, IT Project Manager
IT Security Director, GRC Strategy, Platforms & Architecture Lead
1 day ago – Be among the first 25 applicants
As the IT Security Director and GRC Strategy, Platforms & Architecture Lead
, you will serve as a senior leader responsible for the strategic direction, governance, and operational oversight of the organization’s Governance, Risk, and Compliance (GRC) platforms. This role drives the overall GRC strategy, ensuring that all aspects of cyber governance, controls, compliance, and risk operations are seamlessly integrated through people, processes, and technology. You will ensure that security, risk, compliance, and audit functions are effectively supported by scalable technology solutions aligned with organizational policies and evolving regulatory requirements.
Partnering closely with security leadership, IT, product development, legal, compliance, and business stakeholders, you will enable a consistent, automated, and efficient control environment across the enterprise.
This position offers a flexible hybrid work schedule from our local office (2 days in office, 3 days remote).
Essential Duties and Responsibilities- GRC Strategy:
Understand and drive strategy across security governance, controls, compliance and risk operations to build scalable, functional, and timely solutions that enable scalable processes, high quality outcomes, and enhanced risk management across the Company. - Executive Communication and Leadership:
Accountable for executive-level reporting, communications, and influence to ensure that security Governance and IT risk operations platforms, architecture, and processes are enabled, integrated, leveraged, and decisions/outcomes are in line with Cybersecurity & Technology Controls (CTC) principles. Manage a small team of contractors and employees across engineering and platform roles. - Controls, IT Risk Operations, and Policies/Standards Support:
Act as a seasoned expert and advisor to other CTC leaders in Controls, Risk Operations, and Policy Management domains through collaboration, risk finding reviews, and policy/standard review and release management to support cross-team outcomes and book of work. - Compliance and Controls:
Support control testing and compliance initiatives spanning Policy‑Regulation analysis/crosswalks and gap identification, as well as potential evidence and control design reviews to enable unified compliance at scale with common controls programs. - Platform Strategy &
Roadmap:
Define and execute the enterprise GRC technology and platform strategy, ensuring alignment with security frameworks (e.g., NIST CSF, NIST 800‑53, DORA, etc.). - Platform Ownership:
Serve as the primary owner of the GRC platform(s), overseeing configuration, integration, upgrades, managing platform changes, roadmap and optimization to meet enterprise needs. - Process Enablement:
Translate governance, risk, and compliance processes into platform workflows, dashboards, and reporting that support issue management, risk assessments, policy governance, evidence collection, risk register generation and alignment with organizational units. - Stakeholder Engagement:
Collaborate with information security, IT, compliance, operations, and legal partners in the development, integration, and operation of the platform and intertwined product strategies and roadmaps. - Automation & Efficiency:
Drive automation of risk and compliance processes to reduce manual effort, improve audit readiness, and increase sustainability of controls. - Data & Reporting:
Develop dashboards, analytics, and reporting to provide actionable insights to executives, regulators, auditors, and business leadership. - Platform Governance:
Establish platform governance standards, change control processes, and ongoing lifecycle management and own/drive cross‑functional sessions and demand‑management mechanisms. - Vendor Management:
Manage relationships with platform vendors and system integrators, including licensing, renewals, escalations, and roadmap discussions.
- Deep understanding of IT risk, security, compliance, and audit frameworks (e.g., NIST CSF, NIST 800‑53, ISO 27001, COBIT, SOX, HIPAA, PCI DSS).
- Strong background…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).