Director, Governance, Risk & Compliance
Anomali · Redwood City, CA · 1 mo ago
HybridLegal$180k–$230k/yrFull-time
Key Responsibilities
- Program Ownership & Strategy
- Own the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arise
- Prioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadership
- Serve as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)
- FedRAMP
- Manage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agency
- Own documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall short
- ISO 27001
- Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworks
- Own internal audit cycles and ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort
- SOC 2
- Own SOC 2 Type II audit readiness and execution (Security, Availability, and Confidentiality trust services criteria) in partnership with the external audit firm
- Manage evidence collection, control testing, and remediation of exceptions across annual audit cycles
- Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort
- Regional Cloud/Government Certifications
- Drive DESC CSP certification for UAE market access
- Manage Saudi NCA compliance (ECC/CCC)
- Own Australia IRAP assessment process and coordination with registered assessors
- Monitor emerging regional requirements (e.g., additional Gulf, APAC, or EU frameworks) and advise on prioritization
- Risk & Controls
- Build and maintain a unified controls framework that maps overlapping requirements across all frameworks to avoid duplicated effort
- Own enterprise risk register, vendor/third-party risk management, and remediation tracking
- Partner with engineering and product teams to ensure security controls are designed in, not bolted on
- Cross-Functional Leadership
- Partner with internal cross-functional teams — IT, Security, Cloud Infrastructure, Engineering, and Product — to own and drive compliance outcomes end-to-end
- Support customer/prospect due diligence (security questionnaires, audit requests, trust portal)
- Partner with legal on regulatory obligations, data residency, and contractual compliance commitments
- Report compliance posture and risk to executive leadership and board as needed
Qualifications
- Required Skills/Experience:
- 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
- Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
- Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
- Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
- Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
- Familiarity with Australia IRAP assessment process
- Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
- Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
- Exceptional written communication skills (SSPs, policies, board-level reporting)
- Preferred Qualifications:
- Certifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer
- Experience in a high-growth, venture-backed SaaS or cybersecurity company
- Prior experience managing multiple concurrent certifications across regions
- Experience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)