Director of the Trust Office (Cyber Governance, Risk & Compliance)
About the role
Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware enterprise prepared to navigate today’s evolving threat landscape. We have complex, multi-dimensional programs across the organization that support all the technology needed to deliver products and solutions to customers - enabling them to focus on delivering high quality patient care. As the Director of the Trust Office (Cyber Governance, Risk & Compliance), you will lead the evolution of IDEXX’s Trust Office and help shape how cybersecurity governance, risk management, controls assurance, and customer trust enable business success across a global organization.
Responsibilities
In this role, you will lead the transformation of the Trust Office, modernize cyber risk management, advance controls assurance and automation, strengthen customer trust and compliance, partner across the enterprise, and lead and develop an exceptional team. Specific responsibilities include:
- Leading the evolution of IDEXX’s Trust Office, expanding an established Governance, Risk & Compliance organization into a modern, business-focused security function.
- Developing the long-term strategy, operating model, and roadmap that advances IDEXX’s cybersecurity maturity.
- Building and maturing an enterprise cyber risk management program that enables leaders to understand, communicate, and make informed business decisions regarding cyber risk.
- Leading the development of an enterprise Controls Assurance program focused on validating that security controls are operating effectively.
- Leading customer security assessments, security questionnaires, trust center content, external assurance activities, and customer-facing security documentation.
- Partnering with Sales, Product, Legal, Privacy, and Information Security teams to ensure cybersecurity enables customer confidence and business growth.
- Overseeing compliance activities supporting SOC 2, SOX IT General Controls, GDPR, SEC cybersecurity disclosure requirements, and emerging regulatory obligations.
- Building trusted relationships across Information Security, Technology, Product, Legal, Privacy, Internal Audit, Finance, Procurement, and business leadership.
- Leading, coaching, and developing an experienced team of Governance, Risk & Compliance professionals.
Requirements
We’re looking for an experienced cybersecurity leader who combines strategic vision with operational excellence and has successfully transformed Governance, Risk & Compliance organizations into trusted business partners. Ideally, you have:
- 10-12+ years of progressive leadership experience in cybersecurity, governance, risk management, compliance, assurance, or related disciplines.
- Experience building, transforming, or significantly maturing enterprise Governance, Risk & Compliance or Trust organizations.
- Demonstrated success leading organizational change within complex global enterprises.
- Exceptional executive communication skills with the ability to translate technical concepts into meaningful business discussions.
- Experience influencing across organizations through partnership rather than authority.
- A collaborative leadership style focused on coaching, relationship-building, and business enablement.
- Experience developing cyber risk management programs, governance frameworks, policy programs, controls assurance, or continuous monitoring capabilities.
- Experience supporting regulatory and compliance frameworks such as NIST CSF, CIS Controls, SOC 2, SOX IT General Controls, GDPR, SEC cybersecurity disclosure requirements, or similar frameworks.
Benefits
We offer a range of benefits, including:
- Base annual salary target: $190,000 - $210,000.
- Opportunity for annual cash bonus and yearly equity award.
- Health / Dental / Vision Benefits.
- Day-One 5% matching 401k.
- Additional benefits including financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and more.
Qualifications
Preferred qualifications include:
- BISO (Business Information Security Officer) or similar business-facing cybersecurity leadership experience.
- CISSP, CISM, CRISC, CISA, CGRC, or similar certifications.
- Familiarity with automation, AI-enabled governance, continuous controls monitoring, or risk telemetry.
- Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or similar technologies.