Jobs · Legal · California

Director, Governance, Risk & Compliance

Anomali · Redwood City, CA · 1 mo ago
HybridLegal$180k–$230k/yrFull-time

Key Responsibilities

  • Program Ownership & Strategy
  • Own the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arise
  • Prioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadership
  • Serve as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)
  • FedRAMP
  • Manage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agency
  • Own documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall short
  • ISO 27001
  • Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworks
  • Own internal audit cycles and ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort
  • SOC 2
  • Own SOC 2 Type II audit readiness and execution (Security, Availability, and Confidentiality trust services criteria) in partnership with the external audit firm
  • Manage evidence collection, control testing, and remediation of exceptions across annual audit cycles
  • Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort
  • Regional Cloud/Government Certifications
  • Drive DESC CSP certification for UAE market access
  • Manage Saudi NCA compliance (ECC/CCC)
  • Own Australia IRAP assessment process and coordination with registered assessors
  • Monitor emerging regional requirements (e.g., additional Gulf, APAC, or EU frameworks) and advise on prioritization
  • Risk & Controls
  • Build and maintain a unified controls framework that maps overlapping requirements across all frameworks to avoid duplicated effort
  • Own enterprise risk register, vendor/third-party risk management, and remediation tracking
  • Partner with engineering and product teams to ensure security controls are designed in, not bolted on
  • Cross-Functional Leadership
  • Partner with internal cross-functional teams — IT, Security, Cloud Infrastructure, Engineering, and Product — to own and drive compliance outcomes end-to-end
  • Support customer/prospect due diligence (security questionnaires, audit requests, trust portal)
  • Partner with legal on regulatory obligations, data residency, and contractual compliance commitments
  • Report compliance posture and risk to executive leadership and board as needed

    Qualifications

    • Required Skills/Experience:
    • 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
    • Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
    • Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
    • Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
    • Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
    • Familiarity with Australia IRAP assessment process
    • Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
    • Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
    • Exceptional written communication skills (SSPs, policies, board-level reporting)
    • Preferred Qualifications:
    • Certifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer
    • Experience in a high-growth, venture-backed SaaS or cybersecurity company
    • Prior experience managing multiple concurrent certifications across regions
    • Experience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)

Similar jobs