Technology Director
lululemonUSA4d ago
ComplianceDirectorremotecurated-jd
Job description
Technology Director at lululemon.
About the role
This leadership position oversees the Governance, Risk, and Compliance domain, managing security strategy and engineering at a global scale. You will guide multiple teams to balance operational resilience with business growth while ensuring adherence to international regulatory standards.
Key facts
What you'll do
- Direct the GRC function, focusing on control effectiveness, risk management, and overall maturity.
- Develop and implement security strategies aligned with global frameworks like NIST and ISO.
- Convert regulatory requirements and threat intelligence into multi-quarter roadmaps.
- Act as the second line of defense for SOX compliance while supporting first-line control owners.
- Manage departmental budgets, resource allocation, and investment planning.
- Lead and mentor multiple teams to create a scalable operating model and a strong leadership bench.
- Conduct cybersecurity risk assessments and oversee mitigation efforts across the organization.
- Provide executive-level reporting on security posture to influence business and technology stakeholders.
- Serve as a leader during major security events and critical incidents.
Requirements
- 12 to 15+ years of experience in technology risk or cybersecurity.
- 4+ years of experience in senior leadership roles.
- Bachelor degree in a STEM field or a related discipline.
- Deep expertise in regulatory requirements and security frameworks, including NIST, ISO 27001, CCPA/CPPA, SOX, PCI, and GDPR.
- Demonstrated ability to manage large-scale cybersecurity program delivery and risk assessments.
- Must possess an entrepreneurial mindset, prioritize people, and communicate with honesty.
- Ability to take personal responsibility and lead with courage.
Nice to have
- Advanced degree.
- Relevant professional certifications.
Skills & tools
- Governance, Risk, and Compliance (GRC) engineering
- Cybersecurity strategy and program management
- Risk assessment and mitigation
- Executive stakeholder management
- Regulatory compliance (NIST, ISO, SOX, GDPR, PCI, CCPA)
Practical notes
- Applicants must be authorized to work for any employer in the U.S. without sponsorship.
- Compensation includes potential annual bonus and equity offerings subject to eligibility.
- Benefits include health, dental, and mental health plans, retirement matching, parenthood top-up, fitness classes, and an employee discount.
- The company provides access to mentorship programs, leadership series, and professional development courses.