FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Director, Governance, Risk & Compliance
AnomaliCompliance leader managing end-to-end GRC roadmap for an AI-native cybersecurity platform. Overseeing certifications and engaging with regulatory bodies for market expansion.
Posted 7/24/2026full-timeRedwood City • California • 🇺🇸 United StatesLead💰 $180,000 - $230,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in Governance, Risk, and Compliance (GRC) with a focus on FedRAMP, ISO 27001, and SOC 2 certifications. Proven ability to manage compliance frameworks, stakeholder relationships, and documentation quality while driving continuous improvement in security controls and risk assessments.
Highest-signal resume keywords
FedRAMP Authorization ManagementISO 27001 Certification OwnershipSOC 2 Type II Audit ManagementCloud Security Architecture KnowledgeStakeholder Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
GRC ManagementInformation Security ComplianceAudit ManagementRisk AssessmentContinuous MonitoringDocumentation Quality ControlCloud Security FrameworksISMS ManagementRegulatory ComplianceTechnical Implementation Mapping
Soft Skills
Stakeholder ManagementWritten Communication
Tools & Technologies
AWSAzureGCP
Certifications & Qualifications
FedRAMPISO 27001SOC 2 Type IIDESC CSP CertificationAustralia IRAP
Industry Keywords
Cloud SecurityData ResidencyRegulatory BodiesAudit CyclesCompliance Posture Reporting
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityGoogle Cloud Platform
About the role
Key responsibilities & impact- Own the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arise
- Prioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadership
- Serve as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)
- Manage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agency
- Own documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall short
- Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworks
- Drive DESC CSP certification for UAE market access. The CSP Security Standard is based on the following international standards, which the candidate should be conversant in: ISO/IEC 27001:2013 ISO/IEC 27002:2013 ISO/IEC 27017:2015 ISR:2017 v.02 CSA Cloud Controls Matrix 3.0.1
- Manage Saudi NCA compliance (ECC/CCC) in coordination with local partners
- Own Australia IRAP assessment process and coordination with registered assessors
- Partner with legal on regulatory obligations, data residency, and contractual compliance commitments
- Report compliance posture and risk to executive leadership and board as needed
Requirements
What you’ll need- 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
- Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
- Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
- Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
- Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
- Familiarity with Australia IRAP assessment process
- Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
- Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
- Exceptional written communication skills (SSPs, policies, board-level reporting)
Benefits
Comp & perks- In addition to base pay, this position is eligible for benefits
- May be eligible for a bonus and/or equity