Director of the Trust Office (Cyber Governance, Risk & Compliance)
About the Role
As the Director of the Trust Office (Cyber Governance, Risk & Compliance), you will lead the evolution of IDEXX’s Trust Office and help shape how cybersecurity governance, risk management, controls assurance, and customer trust enable business success across a global organization. This role goes beyond traditional Governance, Risk & Compliance leadership to transform the organization into a modern, AI-enabled Trust Office that helps the business understand cyber risk, strengthen customer confidence, accelerate decision-making, and continuously improve cybersecurity maturity.
You’ll partner closely with technology, legal, privacy, internal audit, product, sales, and business leaders to modernize governance, strengthen trust, and help define the future of cybersecurity at IDEXX.
Responsibilities
- Lead the transformation of the Trust Office by expanding an established Governance, Risk & Compliance organization into a modern, business-focused security function, developing the long-term strategy, operating model, and roadmap.
- Build a culture where Governance, Risk & Compliance is viewed as a trusted business partner rather than a traditional audit function.
- Modernize cyber risk management by building and maturing an enterprise cyber risk management program that enables leaders to understand, communicate, and make informed business decisions regarding cyber risk.
- Develop scalable governance processes, enterprise policies, standards, and risk management frameworks aligned with industry best practices including NIST CSF and CIS Controls.
- Oversee enterprise risk registers, risk acceptance processes, executive reporting, and ongoing governance activities.
- Advance controls assurance and automation by leading the development of an enterprise Controls Assurance program focused on validating that security controls are operating effectively.
- Expand continuous controls monitoring, automated evidence collection, and scalable assurance capabilities.
- Transform governance operations through AI-enabled workflows, automation, analytics, and continuous monitoring.
- Develop executive dashboards and meaningful risk metrics that provide leaders with actionable visibility into IDEXX’s security posture.
- Strengthen customer trust and compliance by leading customer security assessments, security questionnaires, trust center content, external assurance activities, and customer-facing security documentation.
- Partner with Sales, Product, Legal, Privacy, and Information Security teams to ensure cybersecurity enables customer confidence and business growth.
- Oversee compliance activities supporting SOC 2, SOX IT General Controls, GDPR, SEC cybersecurity disclosure requirements, and emerging regulatory obligations.
- Guide external audits, certifications, regulatory readiness activities, and third-party assessments.
- Build trusted relationships across Information Security, Technology, Product, Legal, Privacy, Internal Audit, Finance, Procurement, and business leadership.
- Translate complex cybersecurity concepts into practical business discussions that influence strategic decision-making.
- Lead, coach, and develop an experienced team of Governance, Risk & Compliance professionals while fostering a culture of accountability, collaboration, and continuous improvement.
Requirements
- 10-12+ years of progressive leadership experience in cybersecurity, governance, risk management, compliance, assurance, or related disciplines.
- Experience building, transforming, or significantly maturing enterprise Governance, Risk & Compliance or Trust organizations.
- Demonstrated success leading organizational change within complex global enterprises.
- Experience partnering with executive leadership to improve cybersecurity maturity across the organization.
- Exceptional executive communication skills with the ability to translate technical concepts into meaningful business discussions.
- Experience influencing across organizations through partnership rather than authority.
- Collaborative leadership style focused on coaching, relationship-building, and business enablement.
- Experience developing cyber risk management programs, governance frameworks, policy programs, controls assurance, or continuous monitoring capabilities.
- Experience supporting regulatory and compliance frameworks such as NIST CSF, CIS Controls, SOC 2, SOX IT General Controls, GDPR, SEC cybersecurity disclosure requirements, or similar frameworks.
- Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or similar technologies.
- Familiarity with automation, AI-enabled governance, continuous controls monitoring, or risk telemetry is highly desirable.
- BISO (Business Information Security Officer) or similar business-facing cybersecurity leadership experience is a strong plus.
- CISSP, CISM, CRISC, CISA, CGRC, or similar certifications are preferred.
Location: Ideally within driving distance of Westbrook, Maine corporate HQ, with a flexible hybrid requirement of 8 days per month on-site. Open to candidates in NH and MA if they can meet the on-site requirement.
Benefits
- Base annual salary target: $190,000 - $210,000 (flexible if needed).
- Opportunity for annual cash bonus and yearly equity award.
- Health, dental, and vision benefits.
- Day-one 5% matching 401k.
- Additional benefits including financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, and foundation donation matching.
- Relocation support if applicable.