Director of Governance, Risk, and Compliance
Job description
About the role
The Director of Governance, Risk, and Compliance owns the design and execution of the company's GRC strategy across housing and healthcare operations. This role drives the implementation of structured risk frameworks to protect data, ensure regulatory adherence, and support scalable growth. You will establish the governance backbone that aligns security, legal, and business objectives while maintaining a clear line of sight on emerging threats. The position requires direct ownership of audit readiness, third-party risk oversight, and the maturation of compliance policies into actionable workflows. You will set the standard for control environments and ensure that risk decisions are transparent and measurable. The role demands close collaboration with Security Engineering, Legal, and business leaders to embed compliance into product and process design. Ultimately, you will build the GRC function from the ground up, creating the playbook that defines how the company manages risk at scale.
Key facts
What you'll do
- Lead the development and execution of the enterprise GRC program, defining strategy and priorities across SOC 1, SOC 2, PCI, HITRUST, and HIPAA requirements.
- Serve as the main liaison with external auditors, owning the audit planning, evidence collection, and documentation processes while managing communications throughout the audit cycle.
- Create and maintain compliance roadmaps that translate regulatory expectations into concrete initiatives with clear ownership, timelines, and metrics.
- Build and scale the GRC team by defining hiring plans, setting performance expectations, and providing mentorship to ensure high-impact delivery.
- Own the vendor risk management program, including tiering third-party vendors, driving due diligence reviews, and escalating critical risk findings to leadership.
- Review and approve security questionnaires and due diligence responses for vendors and clients, ensuring consistency, accuracy, and alignment with security standards.
- Drive the creation, review, and adoption of security and compliance policies across the organization, ensuring they are practical, documented, and enforced.
- Partner with Legal and Security leadership to assess and negotiate security-related contractual terms, including addenda and service-level expectations.
- Establish metrics and reporting structures to track compliance posture, risk trends, and remediation progress for executive and board-level visibility.
- Act as the central authority on risk-based decision-making, translating complex regulatory language into clear guidance for cross-functional stakeholders.
- Coordinate with Security Engineering to implement control objectives, ensuring that technical controls support compliance requirements and business needs.
- Support the evaluation and onboarding of new clients and vendors by providing risk assessments and compliance guidance that enable faster decision-making.
Requirements
- Bring 8+ years of progressive experience in Governance, Risk, and Compliance, Information Security, or a related discipline, with at least 3 years in a leadership or program ownership role.
- Demonstrate deep expertise across multiple compliance frameworks, including SOC 1, SOC 2, PCI, HIPAA, and ISO certifications, with practical implementation experience.
- Show a proven track record of managing audit programs end-to-end, including direct relationships and communication with external auditors.
- Have experience building out a GRC function from scratch or scaling an existing function, including hands-on team hiring, development, and performance management.
- Exhibit strong understanding of vendor risk management practices, third-party due diligence, and risk-based decision-making methodologies.
- Possess the ability to translate complex compliance and risk topics into clear narratives for executive leadership and board-level audiences.
- Display excellent cross-functional influencing skills, working confidently with Legal, Engineering, and business leadership to advance shared objectives.
- Commit to working in person at the New York City office 4-5 days per week to enable close collaboration and cultural integration.
Practical notes
This is a full-time role based in New York City.
Work location and schedule
You will work in person at our office 4-5 days a week.
Application deadline
No explicit deadline is listed; candidates are encouraged to apply as soon as possible.