Senior Director, Security Governance
Job description
About the role
The Senior Director of Security Governance leads the design and execution of the enterprise governance, risk, and compliance (GRC) program. This role owns the strategic vision for AI-driven risk management and ensures alignment with business objectives. The position requires a hands-on leader who partners across Security, Legal, Product, and executive teams to build a resilient security posture. The role balances the acceleration of innovation with the discipline of risk control, establishing security as a driver of business trust and momentum. This position is based remotely from Ireland and is a full-time role. The base salary for this role is $220,000.00 per year.
What you'll do
Lead the development of a comprehensive GRC roadmap that integrates governance, risk management, and compliance initiatives to establish a cohesive strategic direction.
Design and maintain the enterprise risk register in partnership with business leaders to identify, quantify, and prioritize emerging threats across the organization.
Drive continuous compliance for a wide set of standards, moving beyond point-in-time audits to ensure sustained adherence and operational integrity.
Implement and manage a right-sized third-party risk (TPRM) program, assessing vendor maturity and reviewing security contracts to ensure resilience and accountability.
Enable transaction velocity and customer trust within security sales processes by rapidly responding to security inquiries and building confidence through transparent communication.
Leverage automation and Agentic AI to streamline workflows, utilizing platforms such as ServiceNow GRC and Vanta to generate metrics and deliver executive dashboards.
Serve as the central point of collaboration between Security, Legal, Product, and executive leadership, translating complex technical risks into clear business language to align risk posture with strategic goals.
Charter security by design programs that embed measured risk tolerance into the innovation lifecycle, ensuring security considerations are integrated from the outset.
Establish metrics and reporting frameworks to measure the effectiveness of governance initiatives and drive data-informed decision-making at all levels.
Champion a culture of security awareness and accountability, ensuring that policies and procedures are understood and adopted across the enterprise.
Identify gaps and opportunities for improvement within the GRC ecosystem, recommending actionable initiatives to enhance control effectiveness and efficiency.
Collaborate with external auditors and regulators to ensure timely responses to inquiries and maintain strong, trust-based relationships.
Guide the organization through complex regulatory landscapes by interpreting requirements and implementing controls that mitigate potential risks.
Support the development of training and awareness programs to ensure that security governance principles are embedded in everyday operations.
Requirements
Bring 10+ years of experience in information security or GRC, with at least 5 years in a senior leadership capacity to ensure depth of knowledge and practical application.
Demonstrate deep knowledge of risk frameworks, including NIST AI RMF, and security compliance standards such as ISO and SOC 2 to navigate complex regulatory requirements.
Show a proven ability to scale security teams, mature GRC programs, and foster a "security by design" culture that embeds security into every initiative.
Excel at translating complex technical risks into clear, business-relevant context for both executive leadership and customers to drive understanding and informed decision-making.
Hold a Bachelor's degree in a relevant field as a foundational requirement for the role.
Preferably hold a Master's or PhD to bring advanced analytical and strategic thinking to the governance function.
Possess industry certifications such as CISSP, CISM, CRISC, or CISA, which are strongly preferred to validate expertise and commitment to the profession.
Demonstrate a history of building and influencing cross-functional partnerships to drive security outcomes across the organization.
Show strong proficiency in risk assessment methodologies, policy development, and compliance management to ensure robust governance practices.
Nice to have
Preferred knowledge of AI-driven risk management concepts and methodologies to leverage emerging technologies effectively.
Experience with Security Sales processes and supporting customer-facing security inquiries to enable trust and transaction velocity.
Familiarity with modern GRC and security tooling ecosystems to optimize workflows and enhance program effectiveness.
Practical notes
This is a full-time position based remotely from Ireland.
The base salary for this role is $220,000.00 per year.