Governance, Risk, and Compliance and Data Privacy Office Director
Dow · Midland, MI · 4 wk ago
Finance$43/hrFull-time
About the role
Dow has an exciting opportunity for a Governance, Risk, and Compliance and Data Privacy Director located in Midland, MI or Houston, TX.
Responsibilities
- Own cyber security governance effectiveness – establish clear, enforceable policies, standards and control frameworks with unambiguous ownership and consistent application
- Own cyber and data privacy risk identification and visibility – ensure internal and external risks are clearly defined in central risk register, quantified and reported. Actively challenge and escalate unacceptable risk
- Own regulatory compliance and audit outcomes – ensure compliance is sustainable and audit-ready by design, with no reliance on reactive audit preparation and no recurring findings
- Own external cyber assessments and certification to enable the business (e.g. customer cyber assessment, ISO 270001, NIST CSF, etc)
- Own security culture and behavior change outcomes – drive measurable improvements in workforce cyber and data privacy behaviors
Requirements
- Risk-first mindset (non-negotiable) – uses compliance frameworks as tools, not goals; prioritizes exposure, control effectiveness and business impact
- Ability to challenge the business with credibility – pushes back on weak controls and unclear risk acceptance; forces clarity on ownership and impact
- Translates risks into business language – converts regulatory and control concepts into exposure, financial risk and operational impact
- Governance builder (not just operator) – designs governance forums, decision rights and escalation paths that enforce accountability and consistency
- Culture shaper – drives measurable shifts in how the organization thinks about and manages risk
Skills
- Leadership: Demonstrates the ability to lead global teams, influence stakeholders, establish accountability, and drive enterprise-wide cybersecurity, risk, compliance, and data privacy initiatives.
- Strategic Planning: Develops and implements long-term governance, risk management, compliance, and cybersecurity strategies that align with business objectives and regulatory requirements.
- Decision Making: Evaluates complex cyber and privacy risks, prioritizes actions based on business impact, challenges inadequate controls, and drives informed risk acceptance decisions.
- Communication: Effectively translates technical cybersecurity, regulatory, and data privacy concepts into clear business language for executives, stakeholders, and non-technical audiences.
- Business Management: Oversees governance programs, compliance processes, audit readiness, risk reporting, external assessments, and organizational initiatives to ensure sustainable business outcomes.
Qualifications
- A minimum of a bachelor’s degree or relevant military experience at or above a U.S. E5 ranking or Canadian Petty Officer 2nd Class or Sergeant.
- Minimum 10 years of progressive experience in IT and/or Cybersecurity.
- Deep understanding of regulatory compliance, audit readiness, and risk management in regulated industries.
- Strong interpersonal, communication and stakeholder engagement skills across technical and non-technical audiences.