Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Anomali

Director, Governance, Risk & Compliance

Anomali

Compliance leader managing end-to-end GRC roadmap for an AI-native cybersecurity platform. Overseeing certifications and engaging with regulatory bodies for market expansion.

Posted 7/24/2026full-timeRedwood City • California • 🇺🇸 United StatesLead💰 $180,000 - $230,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in Governance, Risk, and Compliance (GRC) with a focus on FedRAMP, ISO 27001, and SOC 2 certifications. Proven ability to manage compliance frameworks, stakeholder relationships, and documentation quality while driving continuous improvement in security controls and risk assessments.

Highest-signal resume keywords
FedRAMP Authorization ManagementISO 27001 Certification OwnershipSOC 2 Type II Audit ManagementCloud Security Architecture KnowledgeStakeholder Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
GRC ManagementInformation Security ComplianceAudit ManagementRisk AssessmentContinuous MonitoringDocumentation Quality ControlCloud Security FrameworksISMS ManagementRegulatory ComplianceTechnical Implementation Mapping
Soft Skills
Stakeholder ManagementWritten Communication
Tools & Technologies
AWSAzureGCP
Certifications & Qualifications
FedRAMPISO 27001SOC 2 Type IIDESC CSP CertificationAustralia IRAP
Industry Keywords
Cloud SecurityData ResidencyRegulatory BodiesAudit CyclesCompliance Posture Reporting

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud Platform

About the role

Key responsibilities & impact
  • Own the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, DESC (Dubai Electronic Security Center), Saudi NCA Cloud Cybersecurity Controls (CCC), Australia IRAP, and other regional cloud security/data residency frameworks as they arise
  • Prioritize and sequence certification efforts against GTM and revenue targets, in partnership with sales, product, and executive leadership
  • Serve as the primary liaison with assessors, auditors, and regulatory bodies (3PAOs, sponsoring agencies, in-country assessors)
  • Manage ongoing FedRAMP authorization activities (ATO maintenance, continuous monitoring, SAR/POA&M remediation) in partnership with the 3PAO and sponsoring agency
  • Own documentation quality (SSP, SAR, POA&M) and escalation management when assessor deliverables fall short
  • Maintain and evolve the ISMS, manage internal/external audit cycles, and drive continuous improvement of controls, risk assessments, and policy frameworks
  • Drive DESC CSP certification for UAE market access. The CSP Security Standard is based on the following international standards, which the candidate should be conversant in: ISO/IEC 27001:2013 ISO/IEC 27002:2013 ISO/IEC 27017:2015 ISR:2017 v.02 CSA Cloud Controls Matrix 3.0.1
  • Manage Saudi NCA compliance (ECC/CCC) in coordination with local partners
  • Own Australia IRAP assessment process and coordination with registered assessors
  • Partner with legal on regulatory obligations, data residency, and contractual compliance commitments
  • Report compliance posture and risk to executive leadership and board as needed

Requirements

What you’ll need
  • 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
  • Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
  • Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
  • Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
  • Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
  • Familiarity with Australia IRAP assessment process
  • Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
  • Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
  • Exceptional written communication skills (SSPs, policies, board-level reporting)

Benefits

Comp & perks
  • In addition to base pay, this position is eligible for benefits
  • May be eligible for a bonus and/or equity