Director, Governance, Risk & Compliance
$180k - $230kAnomali
Redwood City, CAG&A – CEO/Legal /Full-time /HybridCompany Description:Anomali, headquartered in Silicon Valley, delivers the first Intelligence-Native Agentic SOC Platform — unifying a security data lake, the world's largest IOC repository, threat intelligence, and agentic AI into a single modern experience. The platform accelerates detection, investigation, and response, delivering earlier insights, faster action, and scalable modernization across any environment.Whether augmenting existing tools or delivering complete SOC capabilities end-to-end, Anomali empowers security teams to operate faster, smarter, and with confidence.Beyond Detecting. Start Deciding. Start Acting.Learn more at Position Overview:Anomali is scaling its compliance program to support an AI-native cybersecurity platform used by governments and enterprises worldwide. We're looking for a hands-on GRC leader who can own and drive our multi-jurisdiction certification portfolio — spanning U.S. federal (FedRAMP), global (ISO 27001, SOC 2), and regional cloud security frameworks (UAE DESC, Saudi Arabia NCA/CCC, Australia IRAP) — while building the scalable compliance infrastructure to support continued international expansion.This is a builder role, not a maintainer role. You'll be the single point of accountability for keeping our certifications current, audit-ready, and strategically sequenced to unlock new markets and revenue.Key Responsibilities:Program Ownership & StrategyOwn the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arisePrioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadershipServe as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)FedRAMPManage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agencyOwn documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall shortISO 27001Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworksSOC 2Own SOC 2 Type II audit readiness and execution (Security, Availability, and Confidentiality trust services criteria) in partnership with the external audit firmManage evidence collection, control testing, and remediation of exceptions across annual audit cyclesEnsure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effortRegional Cloud/Government CertificationsDrive DESC CSP certification for UAE market access. The CSP Security Standard is based on the following international standards, which the candidate should be conversant in: ISO/IEC 27001:2013ISO/IEC 27002:2013ISO/IEC 27017:2015ISR:2017 v.02CSA Cloud Controls Matrix 3.0.1Manage Saudi NCA compliance (ECC/CCC) in coordination with local partnersOwn Australia IRAP assessment process and coordination with registered assessorsMonitor emerging regional requirements (e.g., additional Gulf, APAC, or EU frameworks) and advise on prioritizationRisk & ControlsBuild and maintain a unified controls framework that maps overlapping requirements across all frameworks to avoid duplicated effortOwn enterprise risk register, vendor/third-party risk management, and remediation trackingPartner with engineering and product teams to ensure security controls are designed in, not bolted onCross-Functional LeadershipPartner with internal cross-functional teams — IT, Security, Cloud Infrastructure, Engineering, and Product — to own and drive compliance outcomes end-to-endSupport customer/prospect due diligence (security questionnaires, audit requests, trust portal)Partner with legal on regulatory obligations, data residency, and contractual compliance commitmentsReport compliance posture and risk to executive leadership and board as needed Qualifications Required Skills/Experience: 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacityDirect, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisoryDemonstrated ownership of ISO 27001 certification and ongoing ISMS managementDemonstrated ownership of SOC 2 Type II audits, from readiness through report deliveryExperience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)Familiarity with Australia IRAP assessment processStrong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementationExcellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsorsExceptional written communication skills (SSPs, policies, board-level reporting)For candidates residing within commutable distance of Redwood City, CA, this position will be hybrid. Remote candidates based in the US, will also be considered.This position is not eligible for employment visa sponsorship. The successful candidate must not now, or in the future, require visa sponsorship to work in the US.Preferred QualificationsCertifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/ImplementerExperience in a high-growth, venture-backed SaaS or cybersecurity companyPrior experience managing multiple concurrent certifications across regionsExperience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)What Success Looks LikeFedRAMP ATO maintained with zero material findings; audit cycles run predictablyISO 27001 recertification and surveillance audits pass without major nonconformitiesSOC 2 Type II report delivered annually with no material exceptionsDESC, Saudi CCC, and IRAP certifications achieved on committed timelines, unlocking regional dealsA documented, reusable controls framework that reduces redundant audit effort across all certificationsCompliance treated as a competitive differentiator in sales cycles, not a bottleneckEqual Opportunities MonitoringIt is our policy to ensure that all eligible persons have equal opportunity for employment and advancement on the basis of their ability, qualifications and aptitude. We select those suitable for appointment solely on the basis of merit without regard to an individual's disability, race, color, religion, sex, sexual orientation, gender identity, national origin, age, or status as a protected veteran. Monitoring is carried out to ensure that our equal opportunity policy is effectively implemented. If you are interested in applying for employment with Anomali and need special assistance or accommodation to apply for a posted position, contact our Recruiting team at [email protected].Compensation Transparency$180,000 - $230,000 USD Please note that the annual base salary range is a guideline and, for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as, knowledge, skills and experience of the candidate. In addition to base pay, this position is eligible for benefits, and may be eligible for a bonus and/or equity.We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$174k - $203k
...communications and decision making.Summary:The Associate Director, Process Validation and Risk Management will lead and facilitate commercial process... ...to support commercial readiness, regulatory compliance, and lifecycle management.The incumbent will provide leadership...Suggested$147.05k - $220.8k
...every stage of development, from entrepreneurial start-ups to multibillion‑dollar global corporations. Job Summary The Governance, Risk & Compliance Manager will lead the firm’s IT risk, security, and operational governance. The role is highly collaborative, working closely...SuggestedWork at officeRemote workWorldwide- Wilson Sonsini Goodrich & Rosati, Professional Corporation is seeking a Governance, Risk & Compliance Manager to lead IT risk, security, and operational governance. This role offers remote or hybrid working options and emphasizes collaboration across IT and firm leadership...SuggestedRemote job
$175k - $210k
Job Title:Director, Sourcing and Operational Risk ManagementLocation:Charlotte, NC, Dallas, TX, Knoxville, TN, Palo Alto, CA, Washington, D.C.Job Summary... ...cost of ownership’, supplier diversity, and vendor compliance monitoring.Implements a rigorous and disciplined...SuggestedFull timeContract workLocal areaFlexible hours$210k - $240k
...innovation and teamwork come together to support the most exciting missions in the world!Job Description: Director/Sr Director of Product Management - RBVM, ASM, CTEM - Risk Operation Center (ROC)Date posted: April 2026About the jobCome work at a place where innovation and...SuggestedFull timeTemporary work$134.4k - $201.6k
...information. Job Responsibilities Program & Governance Leadership Coordinate, partner, and... ...status reporting, issue tracking, and risk visibility to leadership. Track and report... ...risk indicators (KRIs), metrics, and compliance status to support decision-making and continuous...WorldwideFlexible hours- ...other that is the bedrock of our culture today."Charlie MonkSr. Director | Capital MarketsPhoenix, AZ"At SBE, every employee has a voice... ...Center & Power Grid Integration Denver, CO Manager, Insurance & Risk Management – Energy & Digital Infrastructure Commercialization &...InternshipRemote work
- ...Qualys in Foster City seeks a Director, Product Management – Technology Alliances & Marketplace to lead the ROC Marketplace strategy, partner integrations, and joint solution development across cloud, identity, and endpoint security. You will collaborate with internal...
$195k - $215k
...on both external and internal platforms and tools when it comes to KYC, KYB, identity, and fraudDefine the strategy and roadmap for risk infrastructure and technologies used at MudflapPartner with Engineering and Data Science to develop and execute a test-driven Machine...Work at officeRemote work$200k - $247k
...non-profit organizations. Our Safety Team also helps advise on compliance with applicable environmental, health, and safety regulations.... ...of Enterprise Resilience. You will: Lead and execute resilience risk assessments across critical business services, infrastructure,...Full timeRemote work$237.5k - $321.5k
...seeking a Group Product Manager to lead the Emerging Products Risk team. This role is the launch engine of our Fintech Risk strategy... ..., Engineering, Risk Policy, Ops, AI Scientists, and Legal/Compliance, plus external partners and vendors, to ensure new products launch...Work at officeWorldwide$188.5k - $255k
...TurboTax.OverviewWhen we protect customers from fraud and financial risk, sometimes good customers get caught in the crossfire — a held... ...across design, engineering, research, risk policy, compliance, and operations; ruthlessly prioritize; set timelines; and communicate...Self employmentLive inWorldwide- Walmart Connect is seeking a Manager, MRC Compliance & Technology Risk to lead the Media Rating Council compliance program and strengthen control environments across product, engineering, legal, and operations. The role focuses on audits, documentation, remediation, and...
$108k - $131k
...deliver the best experience and products to our customers. The Model Risk team plays a crucial role in ensuring the risks associated with... ...and help design the guardrails and platform-level controls that govern their safe use. You'll act as a credible technical peer to first...Work at officeWork from homeRelocation packageFlexible hours- Intuit is seeking a Product Manager to own customer‑facing risk experiences and front‑end flows across QuickBooks, Mailchimp, and TurboTax ecosystems. You will partner with design, UX research, and engineering to craft clear, fast, and reassuring interactions that help...
- Intuit Inc. is seeking a Group Product Manager to lead the Emerging Products Risk team, driving the launch engine for Fintech risk across SMBs and Consumers. You will guide risk design, decisioning, and controls while protecting customers and the business from day one...
- SageSure is seeking a Manager, Actuarial for the BOP Product Development unit of the Commercial Actuarial team. You will drive day‑to‑day execution, manage development and pricing analytics, and translate business requests into actuarial solutions for leadership. You will...
- Affirm is seeking an experienced professional for Bank Model Risk Management (MRM) to build and oversee risk frameworks for credit and fraud models. You will validate models, monitor performance, and collaborate cross-functionally to ensure mathematical robustness and...Remote work
- Intuit is seeking a Group Product Manager to lead the Account Risk and Decisions team within the Fintech Risk organization. This role focuses on protecting millions of customers from fraud while delivering a seamless, low-friction experience across onboarding and ongoing...
- Lucid Motors in Newark, CA seeks a Senior Manager, Global Insurance to oversee risk financing and company-wide insurance programs. The role reports to the Director, Global Risk & Insurance and ensures protective, cost-effective coverage for Lucid’s operations worldwide...Worldwide
- ...looking for a Staff Product Manager to lead the transformation in customer experience regarding money products. You will tackle fraud and risk management challenges, working closely with cross-functional teams to drive product innovation. The ideal candidate has over 4 years...
- Salesforce is seeking a seasoned Engineering Program Director to architect and lead enterprise-scale portfolio governance across the Product Engineering org. You will... ...ll partner with executives to shape roadmaps, own risk management, and implement best-in-class delivery...
$80k - $94k
...direct cash flow forecast, and to support daily operations. Reporting to our Director of Treasury Operations & Investments, you will work cross-functionally with teams such as Treasury Risk, Finance, Accounting, Engineering, Procurement, Engineering, Legal, and Tax to...Work at officeFlexible hoursShift work3 days per week$172k - $210k
Company DescriptionOrganizations everywhere struggle under the crushing costs and complexities of “solutions” that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or ...Flexible hours$323k
...classes. The OpportunityThis Director, Investments Counsel role reports... ...on fund structuring, legal risk, and transaction execution... ...frameworks, and help strengthen governance and best practices across CZI... ...closely with Tax, Finance, Compliance, and other cross-functional teams...Remote workRelocation package$132.85k - $185.98k
...they are assigned. The Senior Portfolio Manager is also responsible for ensuring their assigned loan portfolio is properly risk-graded, in compliance with loan agreements/approvals and potential risks are identified and addressed. The Senior Portfolio Manager will...Work experience placementBank staffWork at office$200k - $300k
Senior Vice President, Portfolio ManagerWhittier Trust is the oldest privately owned multi-family office headquartered on the West Coast, providing exceptional client service and highly customized investment solutions for high-net-worth individuals and their families.Our...Work at office$216k - $252k
VC Stack is looking for an Assistant Controller to join our Fund Finance team in Menlo Park, California. This position involves managing cash flows, preparing financial reports, and working closely with various teams to ensure effective fund operations. Ideal candidates...$77k - $214k
...business practices and with the states applicable tax laws and rules. Our team helps our Financial Services clients transform risk and compliance related to state and local taxes into a business advantage by aligning their state tax plan with the business strategy. You’...H1bLocal area$106.9k - $253.4k
Business UnitTencent Games was established in 2003. We are a leading global platform for game development, operations and publishing, and the largest online game community in China.Tencent Games has developed and operated over 140 games. We provide cross-platform interactive...Full timeWork experience placementWorldwideRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Governance, Risk & Compliance. Be the first to apply!
- regulatory cmc manager Redwood City, CA
- regulatory manager Redwood City, CA
- director global regulatory affairs Redwood City, CA
- manager regulatory affairs Redwood City, CA
- head compliance Redwood City, CA
- compliance manager Redwood City, CA
- compliance director Redwood City, CA
- senior director regulatory affairs Redwood City, CA
- regulatory affairs director Redwood City, CA
- regulatory affairs manager pharmaceutical Redwood City, CA

