Director, Governance, Risk & Compliance
$180k - $230kAnomali
Redwood City, CAG&A – CEO/Legal /Full-time /HybridCompany Description:Anomali, headquartered in Silicon Valley, delivers the first Intelligence-Native Agentic SOC Platform — unifying a security data lake, the world's largest IOC repository, threat intelligence, and agentic AI into a single modern experience. The platform accelerates detection, investigation, and response, delivering earlier insights, faster action, and scalable modernization across any environment.Whether augmenting existing tools or delivering complete SOC capabilities end-to-end, Anomali empowers security teams to operate faster, smarter, and with confidence.Beyond Detecting. Start Deciding. Start Acting.Learn more at Position Overview:Anomali is scaling its compliance program to support an AI-native cybersecurity platform used by governments and enterprises worldwide. We're looking for a hands-on GRC leader who can own and drive our multi-jurisdiction certification portfolio — spanning U.S. federal (FedRAMP), global (ISO 27001, SOC 2), and regional cloud security frameworks (UAE DESC, Saudi Arabia NCA/CCC, Australia IRAP) — while building the scalable compliance infrastructure to support continued international expansion.This is a builder role, not a maintainer role. You'll be the single point of accountability for keeping our certifications current, audit-ready, and strategically sequenced to unlock new markets and revenue.Key Responsibilities:Program Ownership & StrategyOwn the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arisePrioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadershipServe as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)FedRAMPManage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agencyOwn documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall shortISO 27001Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworksSOC 2Own SOC 2 Type II audit readiness and execution (Security, Availability, and Confidentiality trust services criteria) in partnership with the external audit firmManage evidence collection, control testing, and remediation of exceptions across annual audit cyclesEnsure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effortRegional Cloud/Government CertificationsDrive DESC CSP certification for UAE market access. The CSP Security Standard is based on the following international standards, which the candidate should be conversant in: ISO/IEC 27001:2013ISO/IEC 27002:2013ISO/IEC 27017:2015ISR:2017 v.02CSA Cloud Controls Matrix 3.0.1Manage Saudi NCA compliance (ECC/CCC) in coordination with local partnersOwn Australia IRAP assessment process and coordination with registered assessorsMonitor emerging regional requirements (e.g., additional Gulf, APAC, or EU frameworks) and advise on prioritizationRisk & ControlsBuild and maintain a unified controls framework that maps overlapping requirements across all frameworks to avoid duplicated effortOwn enterprise risk register, vendor/third-party risk management, and remediation trackingPartner with engineering and product teams to ensure security controls are designed in, not bolted onCross-Functional LeadershipPartner with internal cross-functional teams — IT, Security, Cloud Infrastructure, Engineering, and Product — to own and drive compliance outcomes end-to-endSupport customer/prospect due diligence (security questionnaires, audit requests, trust portal)Partner with legal on regulatory obligations, data residency, and contractual compliance commitmentsReport compliance posture and risk to executive leadership and board as needed Qualifications Required Skills/Experience: 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacityDirect, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisoryDemonstrated ownership of ISO 27001 certification and ongoing ISMS managementDemonstrated ownership of SOC 2 Type II audits, from readiness through report deliveryExperience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)Familiarity with Australia IRAP assessment processStrong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementationExcellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsorsExceptional written communication skills (SSPs, policies, board-level reporting)For candidates residing within commutable distance of Redwood City, CA, this position will be hybrid. Remote candidates based in the US, will also be considered.This position is not eligible for employment visa sponsorship. The successful candidate must not now, or in the future, require visa sponsorship to work in the US.Preferred QualificationsCertifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/ImplementerExperience in a high-growth, venture-backed SaaS or cybersecurity companyPrior experience managing multiple concurrent certifications across regionsExperience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)What Success Looks LikeFedRAMP ATO maintained with zero material findings; audit cycles run predictablyISO 27001 recertification and surveillance audits pass without major nonconformitiesSOC 2 Type II report delivered annually with no material exceptionsDESC, Saudi CCC, and IRAP certifications achieved on committed timelines, unlocking regional dealsA documented, reusable controls framework that reduces redundant audit effort across all certificationsCompliance treated as a competitive differentiator in sales cycles, not a bottleneckEqual Opportunities MonitoringIt is our policy to ensure that all eligible persons have equal opportunity for employment and advancement on the basis of their ability, qualifications and aptitude. We select those suitable for appointment solely on the basis of merit without regard to an individual's disability, race, color, religion, sex, sexual orientation, gender identity, national origin, age, or status as a protected veteran. Monitoring is carried out to ensure that our equal opportunity policy is effectively implemented. If you are interested in applying for employment with Anomali and need special assistance or accommodation to apply for a posted position, contact our Recruiting team at [email protected].Compensation Transparency$180,000 - $230,000 USD Please note that the annual base salary range is a guideline and, for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as, knowledge, skills and experience of the candidate. In addition to base pay, this position is eligible for benefits, and may be eligible for a bonus and/or equity.We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$200k - $300k
...Senior Director, Procurement Governance, Risk & Compliance Equinix is the world's digital infrastructure company, shortening the path to connectivity to enable the innovations that enrich our work, life and planet. A place where bold ideas are welcomed, human connection...SuggestedFull timeContract workWork at office$174k - $203k
...communications and decision making.Summary:The Associate Director, Process Validation and Risk Management will lead and facilitate commercial process... ...to support commercial readiness, regulatory compliance, and lifecycle management.The incumbent will provide leadership...Suggested$175k - $210k
Job Title:Director, Sourcing and Operational Risk ManagementLocation:Charlotte, NC, Dallas, TX, Knoxville, TN, Palo Alto, CA, Washington, D.C.Job Summary... ...cost of ownership’, supplier diversity, and vendor compliance monitoring.Implements a rigorous and disciplined...SuggestedFull timeContract workLocal areaFlexible hours$210k - $240k
...innovation and teamwork come together to support the most exciting missions in the world!Job Description: Director/Sr Director of Product Management - RBVM, ASM, CTEM - Risk Operation Center (ROC)Date posted: April 2026About the jobCome work at a place where innovation and...SuggestedFull timeTemporary work$210k - $240k
...Role Overview Qualys is seeking a Director / Sr. Director of Product Management to lead its flagship Risk-Based Vulnerability Management (RBVM) product powered by Qualys VMDR and drive the evolution toward Continuous Threat Exposure Management (CTEM) via Qualys ETM....Suggested$180k - $190k
...clients’ success.This position has a HYRBID schedule in our San Mateo, Boston, or New York office.About the DepartmentOur Investment Risk team safeguards the quality and performance of the firm’s fixed income strategies by providing quantitative insights, independent...Full timeWork at officeLocal area$195k - $215k
...on both external and internal platforms and tools when it comes to KYC, KYB, identity, and fraudDefine the strategy and roadmap for risk infrastructure and technologies used at MudflapPartner with Engineering and Data Science to develop and execute a test-driven Machine...Work at officeRemote work$237.5k - $321.5k
...Trust. We are seeking a Group Product Manager to lead the Account Risk and Decisions team. This role is at the heart of our Fintech... ...to the ongoing protection of their accounts against fraud and compliance risks. You will balance a "security-first" mindset with a "customer...WorldwideShift work$188.5k - $255k
...TurboTax.OverviewWhen we protect customers from fraud and financial risk, sometimes good customers get caught in the crossfire — a held... ...across design, engineering, research, risk policy, compliance, and operations; ruthlessly prioritize; set timelines; and communicate...Self employmentLive inWorldwide$216k
...We are seeking a Head of Audit, Risk & Compliance to lead our end-to-end governance ecosystem, unifying Internal Audit, Enterprise Risk, and Regulatory Compliance and Navan, and reporting to our CFO. This high-impact role is about being the architect of a scalable, tech...$172k - $210k
Company DescriptionOrganizations everywhere struggle under the crushing costs and complexities of “solutions” that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or ...Flexible hours$80k - $94k
...direct cash flow forecast, and to support daily operations. Reporting to our Director of Treasury Operations & Investments, you will work cross-functionally with teams such as Treasury Risk, Finance, Accounting, Engineering, Procurement, Engineering, Legal, and Tax to...Work at officeFlexible hoursShift work3 days per week$132.85k - $185.98k
...they are assigned. The Senior Portfolio Manager is also responsible for ensuring their assigned loan portfolio is properly risk-graded, in compliance with loan agreements/approvals and potential risks are identified and addressed. The Senior Portfolio Manager will...Work experience placementBank staffWork at office- ...Engineering, Legal, and Tax teams. The role emphasizes in-person collaboration and strong control environment. Responsibilities include automation workflows, bank relationship management, and SOX compliance, with base pay described in regional ranges. #J-18808-Ljbffr...
$172k - $210k
Job Description We're looking for a driven, detail-oriented Investor Relations professional to join our Finance team. Reporting to the VP of Investor Relations, you'll help shape how the investment community understands our business, growth strategy, and financial performance...Flexible hours$106.9k - $253.4k
Business UnitTencent Games was established in 2003. We are a leading global platform for game development, operations and publishing, and the largest online game community in China.Tencent Games has developed and operated over 140 games. We provide cross-platform interactive...Full timeWork experience placementWorldwideRelocation package- ...business practices and with the states applicable tax laws and rules. Our team helps our Financial Services clients transform risk and compliance related to state and local taxes into a business advantage by aligning their state tax plan with the business strategy. You'...Local area
$250k
...brokerage activity and execute trades seamlessly. Appropriately assess risk when business decisions are made, demonstrating particular... ...and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy...Full timeLocal area$72k - $150k
...overseeing operational activities throughout our North American markets including cash and liquidity management, banking relationships, compliance, data management systems, FX trading, process improvement, and performance reporting. They will contribute to assessing,...Hourly payFull timeTemporary workFlexible hours$56.48k - $125.7k
...and international cash management, banking operations, treasury compliance, financial controls, and foreign exchange activities. In... ...investment portfolio, ensuring alignment with corporate objectives and risk tolerance. Maintain complete and accurate bank account records,...Work at office$165k - $220k
...as well a comprehensive understanding of tax issues and trust and fiduciary laws; consistently apply existing risk management procedures and follow compliance directives; display solid judgment in managing financial contribution of assigned relationships with periodic...16 hoursWork experience placementWork from homeFlexible hours$161.1k - $241.7k
...Strategy & Planning team connects strategy, planning, operations and governance to create clearer priorities, stronger execution and better... ...execution and measurable outcomes Monitor program performance, risks and dependencies, intervening when delivery falls behind and...- ...third party administrator and reviewing fund transactions including the monthly loan servicing process and LP reporting to ensure compliance with fund agreements. The consultant will lead the month end close process for the assigned funds and related GP entities,...Remote work2 days per week1 day per week
$150k - $200k
At Franklin Templeton, we believe success is built through powerful partnerships. As a forward thinking asset manager, we build dynamic relationships with clients, understand their goals, and navigate complex markets together. We leverage cutting edge strategies and deep...Full timeWork experience placementLocal area$252k - $275k
...with internal customers and usher projects through the entire project lifecycle. This includes managing project schedules, identifying risks and clearly communicating them to project stakeholders. You're equally at home explaining your team's analyses and recommendations...- ...escalation point for Treasury mailbox, triaging and responding to complex inquiries within established SLAs.Assist in treasury audits and compliance reviews, ensuring adherence to internal controls and regulatory requirements.Support continuous improvement of treasury processes...Worldwide
$94.4k - $293.8k
...custody, and distributed ledger technologies. Proven experience advising banks on operational resilience, including operational risk, business continuity, third-party risk management, and regulatory resilience frameworks. Experience managing and influencing senior...Live inWork at officeLocal area- A reputable Private Equity Firm in Palo Alto is hiring a Fund Accounting Manager to oversee fund reporting and accounting processes. The successful candidate will have a background in VC/PE firms, strong attention to detail, and proficiency in Excel. Responsibilities include...
$60k - $80k
...free to obtain their own housing at any time. The corporate housing option is designed to provide flexibility and reduce relocation risk while you establish yourself in the firm and the region. We will attract a new generation of legal and technical talent who understand...Full timeWork at officeImmediate startRelocationRelocation package$60k - $80k
...client files, account records, performance reports, and required compliance documentation Execute trades across client accounts in... ...and complete account applications Administer and assess client risk tolerance questionnaires Serve as a key point of contact for client...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Governance, Risk & Compliance. Be the first to apply!
- regulatory affairs manager pharmaceutical Redwood City, CA
- manager regulatory affairs Redwood City, CA
- training and compliance manager Redwood City, CA
- regulatory manager Redwood City, CA
- compliance manager Redwood City, CA
- compliance director Redwood City, CA
- director global regulatory affairs Redwood City, CA
- regulatory & compliance manager Redwood City, CA
- regulatory affairs director Redwood City, CA
- head compliance Redwood City, CA


