Senior Director, GRC
About the Role
We are seeking a visionary Senior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta’s workforce, taking direct responsibility for cyber risk, data governance, security compliance, and product certifications to enable Okta to ship world-class, secure products. You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset—pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures. This is a builder’s role.
Responsibilities
- Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness).
- Enterprise Risk & Governance: Operationalize Okta’s AI risk and governance framework—addressing training data protection, model risk management, responsible AI principles, and alignment with emerging frameworks (NIST AI RMF, ISO/IEC 42001, and the EU AI Act).
- Enterprise Cyber Risk Management: Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification.
- Regulatory & Compliance Assurance: Maintain and expand Okta’s global compliance posture across major security and privacy frameworks, including SOC 1/2/3, ISO 27001/ENS High/MS DPR/PCI-DSS/CSA STAR/HDSP.
- Policy & Governance Lifecycle: Ensure our corporate information security policies and control standards reflect evolving business priorities and emerging threats.
- Third-Party & SaaS Risk Governance: Direct high-impact vendor risk assessment programs, ensuring third-party SaaS tools and supply chain risks meet Okta’s stringent security controls program.
- Audit Management & Remediation: Serve as the primary executive lead for internal/external audits, customer assurances, and regulatory reviews. Drive rapid, engineering-led remediation of audit findings and control gaps.
- Cross-Functional Partnership: Collaborate closely with Product Management, Legal, Privacy, Infrastructure, and Business Technology teams to align compliance requirements with product roadmaps and commercial objectives.
Requirements
- Proven Executive Leadership: 10+ years of progressive leadership in Security GRC within a high-growth SaaS, cloud-first, or enterprise technology environment.
- AI Governance Expertise: Demonstrated understanding of AI/ML governance challenges, including generative and agentic AI security, data lineage, and global AI regulatory landscapes.
- Mastery of Security Frameworks: Extensive track record managing compliance for enterprise cloud environments.
- Risk Quantification Skills: Deep knowledge of risk management methodologies and the ability to translate complex technical risks into operational context for executives.
- Team Scale & Mentorship: Track record of recruiting, mentoring, and retaining high-performing, technical GRC engineering and risk management professionals.
- Education & Certifications: Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience.
Pay
The annual base salary range for this position for candidates located in the San Francisco Bay area is $264,000 USD - $363,000 USD.
The annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is $236,000 USD - $325,000 USD. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location.
Benefits
- Health, dental, and vision insurance
- 401(k) retirement plan
- Flexible spending account
- Paid leave (including PTO and parental leave)
- Equity (where applicable)
- Bonus opportunities
To learn more about our Total Rewards program, please visit: https://rewards.okta.com/us.
About Okta
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.