Director, Governance, Risk & Compliance
$180k - $230kAnomali
Job Description
Job Description
Company Description:
Anomali, headquartered in Silicon Valley, delivers the first Intelligence-Native Agentic SOC Platform — unifying a security data lake, the world's largest IOC repository, threat intelligence, and agentic AI into a single modern experience. The platform accelerates detection, investigation, and response, delivering earlier insights, faster action, and scalable modernization across any environment.
Whether augmenting existing tools or delivering complete SOC capabilities end-to-end, Anomali empowers security teams to operate faster, smarter, and with confidence.
Beyond Detecting. Start Deciding. Start Acting.
Learn more at
Position Overview:
Anomali is scaling its compliance program to support an AI-native cybersecurity platform used by governments and enterprises worldwide. We're looking for a hands-on GRC leader who can own and drive our multi-jurisdiction certification portfolio — spanning U.S. federal (FedRAMP), global (ISO 27001, SOC 2), and regional cloud security frameworks (UAE DESC, Saudi Arabia NCA/CCC, Australia IRAP) — while building the scalable compliance infrastructure to support continued international expansion.
This is a builder role, not a maintainer role. You'll be the single point of accountability for keeping our certifications current, audit-ready, and strategically sequenced to unlock new markets and revenue.
Key Responsibilities:
Program Ownership & Strategy
- Own the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arise
- Prioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadership
- Serve as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)
FedRAMP
- Manage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agency
- Own documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall short
ISO 27001
- Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworks
SOC 2
- Own SOC 2 Type II audit readiness and execution (Security, Availability, and Confidentiality trust services criteria) in partnership with the external audit firm
- Manage evidence collection, control testing, and remediation of exceptions across annual audit cycles
- Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort
Regional Cloud/Government Certifications
- Drive DESC CSP certification for UAE market access. The CSP Security Standard is based on the following international standards, which the candidate should be conversant in:
- ISO/IEC 27001:2013
- ISO/IEC 27002:2013
- ISO/IEC 27017:2015
- ISR:2017 v.02
- CSA Cloud Controls Matrix 3.0.1
- Manage Saudi NCA compliance (ECC/CCC) in coordination with local partners
- Own Australia IRAP assessment process and coordination with registered assessors
- Monitor emerging regional requirements (e.g., additional Gulf, APAC, or EU frameworks) and advise on prioritization
Risk & Controls
- Build and maintain a unified controls framework that maps overlapping requirements across all frameworks to avoid duplicated effort
- Own enterprise risk register, vendor/third-party risk management, and remediation tracking
- Partner with engineering and product teams to ensure security controls are designed in, not bolted on
Cross-Functional Leadership
- Partner with internal cross-functional teams — IT, Security, Cloud Infrastructure, Engineering, and Product — to own and drive compliance outcomes end-to-end
- Support customer/prospect due diligence (security questionnaires, audit requests, trust portal)
- Partner with legal on regulatory obligations, data residency, and contractual compliance commitments
- Report compliance posture and risk to executive leadership and board as needed
Qualifications
Required Skills/Experience:
- 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
- Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
- Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
- Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
- Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
- Familiarity with Australia IRAP assessment process
- Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
- Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
- Exceptional written communication skills (SSPs, policies, board-level reporting)
- For candidates residing within commutable distance of Redwood City, CA, this position will be hybrid. Remote candidates based in the US, will also be considered.
- This position is not eligible for employment visa sponsorship. The successful candidate must not now, or in the future, require visa sponsorship to work in the US.
Preferred Qualifications
- Certifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer
- Experience in a high-growth, venture-backed SaaS or cybersecurity company
- Prior experience managing multiple concurrent certifications across regions
- Experience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)
What Success Looks Like
- FedRAMP ATO maintained with zero material findings; audit cycles run predictably
- ISO 27001 recertification and surveillance audits pass without major nonconformities
- SOC 2 Type II report delivered annually with no material exceptions
- DESC, Saudi CCC, and IRAP certifications achieved on committed timelines, unlocking regional deals
- A documented, reusable controls framework that reduces redundant audit effort across all certifications
- Compliance treated as a competitive differentiator in sales cycles, not a bottleneck
Equal Opportunities Monitoring
It is our policy to ensure that all eligible persons have equal opportunity for employment and advancement on the basis of their ability, qualifications and aptitude. We select those suitable for appointment solely on the basis of merit without regard to an individual's disability, race, color, religion, sex, sexual orientation, gender identity, national origin, age, or status as a protected veteran. Monitoring is carried out to ensure that our equal opportunity policy is effectively implemented.
If you are interested in applying for employment with Anomali and need special assistance or accommodation to apply for a posted position, contact our Recruiting team at View email address on us.fitly.work.
Compensation Transparency
$180,000 - $230,000 USD
Please note that the annual base salary range is a guideline and, for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as, knowledge, skills and experience of the candidate. In addition to base pay, this position is eligible for benefits, and may be el igible for a bonus and/or equity.
$174k - $203k
...communications and decision making.Summary:The Associate Director, Process Validation and Risk Management will lead and facilitate commercial process... ...to support commercial readiness, regulatory compliance, and lifecycle management.The incumbent will provide leadership...Suggested$175k - $210k
Job Title:Director, Sourcing and Operational Risk ManagementLocation:Charlotte, NC, Dallas, TX, Knoxville, TN, Palo Alto, CA, Washington, D.C.Job Summary... ...cost of ownership’, supplier diversity, and vendor compliance monitoring.Implements a rigorous and disciplined...SuggestedFull timeContract workLocal areaFlexible hours$210k - $240k
...innovation and teamwork come together to support the most exciting missions in the world!Job Description: Director/Sr Director of Product Management - RBVM, ASM, CTEM - Risk Operation Center (ROC)Date posted: April 2026About the jobCome work at a place where innovation and...SuggestedFull timeTemporary work- ...personal goals, and other priorities. We can hire people in any country where we have a legal entity. Responsibilities The Risk and Compliance Senior Manager at Atlassian will play a key role in driving the company's risk and compliance strategy across cloud and...SuggestedWork at officeLocal area
$195k - $215k
...on both external and internal platforms and tools when it comes to KYC, KYB, identity, and fraudDefine the strategy and roadmap for risk infrastructure and technologies used at MudflapPartner with Engineering and Data Science to develop and execute a test-driven Machine...SuggestedWork at officeRemote work$237.5k - $321.5k
...seeking a Group Product Manager to lead the Emerging Products Risk team. This role is the launch engine of our Fintech Risk strategy... ..., Engineering, Risk Policy, Ops, AI Scientists, and Legal/Compliance, plus external partners and vendors, to ensure new products launch...Work at officeWorldwide$91k - $169k
...Seller Engagement partner for the Seller Risk organization, translating business... ...online marketplaces, trust & safety, risk, compliance, or seller ecosystems. Experience building... ...mapping, communication strategy, content governance, and change management. MBA or advanced...Full timeTemporary workPart timeImmediate start- Walmart Connect is seeking a Manager, MRC Compliance & Technology Risk to lead the Media Rating Council compliance program and strengthen control environments across product, engineering, legal, and operations. The role focuses on audits, documentation, remediation, and...
- ...TurboTax. Overview When we protect customers from fraud and financial risk, sometimes good customers get caught in the crossfire — a held... ...across design, engineering, research, risk policy, compliance, and operations; ruthlessly prioritize; set timelines; and communicate...Self employmentLive in
- Intuit is seeking a Product Manager to own customer‑facing risk experiences and front‑end flows across QuickBooks, Mailchimp, and TurboTax ecosystems. You will partner with design, UX research, and engineering to craft clear, fast, and reassuring interactions that help...
- Pinterest is seeking a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security areas of our information security program. This leadership role runs a broad, multi-domain...
- Walmart is seeking a Manager of Operations for MRC Compliance & Technology Risk in the United States, with multi-location placement and a salary range reflecting senior IT risk and audit responsibilities. The role partners across product, engineering, legal, and operations...
$80k - $94k
...direct cash flow forecast, and to support daily operations. Reporting to our Director of Treasury Operations & Investments, you will work cross-functionally with teams such as Treasury Risk, Finance, Accounting, Engineering, Procurement, Engineering, Legal, and Tax to...Work at officeFlexible hoursShift work3 days per week$323k
...classes. The OpportunityThis Director, Investments Counsel role reports... ...on fund structuring, legal risk, and transaction execution... ...frameworks, and help strengthen governance and best practices across CZI... ...closely with Tax, Finance, Compliance, and other cross-functional teams...Remote workRelocation package$200k - $300k
Senior Vice President, Portfolio Manager Whittier Trust is the oldest privately owned multi-family office headquartered on the West Coast, providing exceptional client service and highly customized investment solutions for high-net-worth individuals and their families...Work at office$172k - $210k
Investor Relations ManagerOrganizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can ...Flexible hours- Chan Zuckerberg Initiative in Redwood City, CA, seeks a Director, Investments Counsel to serve as the primary legal partner to the Investments... ...leaders, and collaborate with Legal, Investments, Finance, Compliance, and outside counsel to ensure rigorous yet practical...
$216k - $252k
VC Stack is looking for an Assistant Controller to join our Fund Finance team in Menlo Park, California. This position involves managing cash flows, preparing financial reports, and working closely with various teams to ensure effective fund operations. Ideal candidates...$106.9k - $253.4k
Business UnitTencent Games was established in 2003. We are a leading global platform for game development, operations and publishing, and the largest online game community in China.Tencent Games has developed and operated over 140 games. We provide cross-platform interactive...Full timeWork experience placementWorldwideRelocation package$77k - $214k
...business practices and with the states applicable tax laws and rules. Our team helps our Financial Services clients transform risk and compliance related to state and local taxes into a business advantage by aligning their state tax plan with the business strategy. You’...H1bLocal area$65k - $125k
Executive Assistant The Executive Assistant will be responsible for performing an array of administrative functions requiring confidentiality, initiative and sound decision making for the executive and his/her team. You will provide high-level administrative support...Temporary workWork experience placementWork at officeFlexible hours- PsiQuantum seeks an experienced Investor Relations leader to drive strategic planning and ongoing development of IR activities. You will work with the CFO, CEO, and finance teams to increase shareholder value and strengthen PsiQuantum’s investor perception, bridging technical...
$250k
...brokerage activity and execute trades seamlessly. Appropriately assess risk when business decisions are made, demonstrating particular... ...and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy...Full timeLocal area$25 - $30 per hour
...Excel, PowerPoint, Word, Outlook) Knowledge of payment system transaction flows; understanding of operational, liquidity and credit risk, bank account management and general ledger is desirable The typical base pay for this role across the U.S. is: $25.00 - $30.00...Hourly payFull timeWork experience placementWork at officeLocal areaMonday to FridayFlexible hours$200k - $240k
...headquartered in Miami, Florida, and has additional offices in California, New Jersey, the UK, and Ireland. Overview of Role The Director, Portfolio Strategy position reports to the Executive Director, Portfolio Strategy and Competitive Intelligence to support strategic...$56.48k - $125.7k
...and international cash management, banking operations, treasury compliance, financial controls, and foreign exchange activities. In... ...investment portfolio, ensuring alignment with corporate objectives and risk tolerance. Maintain complete and accurate bank account...Work at office$175k - $225k
...Retirement Solutions team combines expertise in strategic and dynamic asset allocation, glide path design, portfolio construction, risk management, and underlying investment selection, leveraging Franklin Templeton’s global investment platform across public and private...Full timeWork at officeLocal area- Reach out to Michelle Espejo via email or LinkedIn for additional information or questions regarding this listing. Financial Planner | Thriving RIA | Mountain View | Hybrid | Base + Bonus + Profit SharingThey're dedicated to empowering clients, community, associates, and...
- ...third party administrator and reviewing fund transactions including the monthly loan servicing process and LP reporting to ensure compliance with fund agreements. The consultant will lead the month end close process for the assigned funds and related GP entities,...Remote work2 days per week1 day per week
- ...escalation point for Treasury mailbox, triaging and responding to complex inquiries within established SLAs.Assist in treasury audits and compliance reviews, ensuring adherence to internal controls and regulatory requirements.Support continuous improvement of treasury processes...Worldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Governance, Risk & Compliance. Be the first to apply!
- regulatory & compliance manager Redwood City, CA
- director global regulatory affairs Redwood City, CA
- head compliance Redwood City, CA
- senior director regulatory affairs Redwood City, CA
- compliance manager Redwood City, CA
- regulatory affairs director Redwood City, CA
- regulatory cmc manager Redwood City, CA
- regulatory affairs manager pharmaceutical Redwood City, CA
- compliance director Redwood City, CA
- senior regulatory manager Redwood City, CA

