Director, Governance Risk and Compliance

Anthology
United States
Workplace: RemoteFull timeUSD 154,000 - 209,000 annuallyFunction: Legal, Risk & ComplianceExperience: 10+ yearsSkills: ["Documentation","Communication","Risk management","Relationship building","Stakeholder collaboration"]

Lead governance, risk, and compliance for information security by driving the company’s ISMS framework and assessing confidentiality, integrity, and availability. Own internal and third-party risk management, translate regulations across NIST, ISO, SOC, and PCI-DSS into practical controls, and report risk posture to senior management. Coordinate audits and remediation with security assessors, manage vendor risk, oversee control effectiveness measurement, and mentor a security compliance team.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Anthology
Anthology
2 weeks ago

Director, Governance Risk and Compliance

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live
Reposted: similar role first listed 8 months ago

Job Summary

Lead governance, risk, and compliance for information security by driving the company’s ISMS framework and assessing confidentiality, integrity, and availability. Own internal and third-party risk management, translate regulations across NIST, ISO, SOC, and PCI-DSS into practical controls, and report risk posture to senior management. Coordinate audits and remediation with security assessors, manage vendor risk, oversee control effectiveness measurement, and mentor a security compliance team.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Director level

Key Responsibilities

  • •Develop and maintain ISMS documentation, including policies, standards, and procedures for risk management, compliance, and information security.
  • •Lead internal and third-party information risk management and drive collaborative design and assessment of security controls, including identity and access management.
  • •Translate business and information security needs into the ISMS and communicate findings from recurring ISMS control effectiveness measurement to senior management.
  • •Coordinate external audit engagements and support remediation with 3PAO, ISO/SOC auditors, PCI DSS QSA firms, and other security assessors.
  • •Manage personnel, mentoring and cross-training team members, and support forecasting, planning, risk assessments, and program budget management.

Pay and Benefits

Salary: USD 154,000 - 209,000 annually

Key Requirements

  • •US Citizenship
  • •10+ years of hands-on experience in IT audit and/or compliance
  • •Strong understanding of security standards and frameworks including ISO 27000, NIST SP 800 series, SOC audits, and data privacy requirements
  • •Ability to translate complex regulations in NIST, ISO, SOC, and PCI-DSS into practical security controls, processes, and reporting
  • •Previous experience gaining an ATO or P-ATO for a cloud implementation under FedRAMP, GovRAMP or IL-4 programs
Experience:10+ yearsIT auditInformation securityComplianceCloud securityFedRAMPGovRAMPIL-4Third-party risk management
Skills:DocumentationCommunicationRisk managementRelationship buildingStakeholder collaboration
Certifications:CISACISMCISSP
Tech Stack:ISMSNISTISO 27000SOCPCI-DSSFedRAMPGovRAMPIL-4ATOP-ATOIdentity and access managementCloud implementationSecurity incident responseBusiness continuity managementDisaster recovery

Eligibility

Nationality:US National

Company Brief

Anthology
Provides cloud-based software and services for higher education institutions, including student information systems, learning management, analytics, enrollment, and alumni engagement solutions to support the student lifecycle and institutional operations.
Industry: EdTech
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Website