Director of Governance, Risk, and Compliance / TPRM
Director of Governance, Risk, and Compliance / TPRM
Posted 2 days ago
SENIORITY
Manager
About the role
- Own and maintain the enterprise-wide information security compliance posture across alloperating entities, ensuring alignment with regulatory expectations and internal risk appetite.
- Establish a defensible, evidence-driven control environment capable of withstanding regulatoryscrutiny across multiple jurisdictions.
- Serve as the authoritative leader for compliance strategy across MGAs and carrier entities with differingregulatory obligations. Enterprise GRC Strategy & Architecture
- Design and implement a unified GRC operating model across multiple insurance entities with varyinglevels of maturity.
- Establish a control-centric framework leveraging NIST 800-53, ISO 27001, SOC 2, and PCI DSS.
- Transition the organization from periodic, interview-based assessments to continuous, evidence-drivencompliance measurement.
- Define and operationalize KRIs, control effectiveness metrics, and executive reporting. Regulatory & Audit Leadership
- Serve as the central point of accountability for regulatory readiness, including NYDFS, state insuranceregulators, and international frameworks where applicable.
- Lead enterprise-wide audit strategy (SOC 2 Type II, ISO 27001, internal audits).
- Interface directly with regulators and external auditors to ensure consistent narratives, defensiblecontrols, and successful audit outcomes.
- Drive enterprise remediation strategies with measurable timelines and executive accountability. Third-Party Risk Management (TPRM)
- Build and scale a comprehensive TPRM program across the full vendor lifecycle.
- Establish risk tiering, due diligence, and continuous monitoring aligned with enterprise risk tolerance.
- Integrate TPRM into procurement, legal, and business operations to ensure consistent enforcement.
- Oversee risk acceptance and exception governance frameworks. Operational Integration & Transformation
- Harmonize fragmented GRC practices across acquired entities into a centralized and scalable function.
- Drive automation strategy leveraging GRC platforms (auditboard, Drata, or equivalent) to enablereal-time compliance visibility and evidence collection.
- Embed security, privacy, and identity governance into enterprise-wide control frameworks.
- Advance organizational maturity toward a “Security First” operating model. Executive Engagement & Cross-Functional Collaboration
- Provide regular reporting to executive leadership and board-level stakeholders (e.g., Audit Committee, Risk Committee).
- Collaborate daily with the Chief Privacy Officer (CPO) and Chief Risk Officer (CRO) organizationsto ensure alignment across privacy, enterprise risk management, and information security compliance.
- Translate complex regulatory and technical requirements into business-aligned decision frameworks.
- Influence enterprise investment decisions through quantified risk exposure and control effectiveness. Leadership & Organizational Complexity
- Lead a multi-layered global GRC and TPRM organization, including:o 4 senior GRC functional leaderso A transversal offshore operations teamo A dedicated outsourced delivery pod (India-based) supporting scaled compliance andassessment activities
- Establish governance models, performance management, and operational rigor across distributedteams.
- Drive talent strategy, succession planning, and capability development aligned to enterprise scale.
- 12–15+ years of progressive experience in cybersecurity, risk management, compliance, or audit.
- 5–7+ years in senior leadership roles within insurance or highly regulated financial servicesenvironments (required).
- Proven success leading enterprise GRC and TPRM programs across complex, multi-entity organizations. Professional Background
- Licensed attorney (JD) or Certified Public Accountant (CPA) strongly preferred, particularly withexperience in regulatory interpretation, audit, or assurance.
- Background in external audit, internal audit, or regulatory advisory highly desirable.
- MBA or equivalent advanced business degree preferred.
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- CGRC (Certified in Governance, Risk and Compliance)
- CIA (Certified Internal Auditor)
- CIPP / CIPM (privacy certifications)
- ISO 27001 Lead Implementer or Lead Auditor Expertise
- Deep knowledge of NIST 800-53, ISO 27001, SOC 2, PCI DSS, and regulatory regimes such as NYDFS.
- Strong command of third-party risk methodologies and vendor lifecycle governance.
- Experience implementing and scaling GRC tooling platforms.
- Ability to design and operationalize scalable, evidence-based control frameworks. Leadership & Influence
- Executive presence with the ability to influence across Legal, Audit, Technology, Privacy, and Riskdomains.
- Strong strategic and analytical thinking with the ability to translate risk into financial and operationalimpact.
- Exceptional communication skills, including board-level engagement.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
