Senior Director, GRC

Okta
San Francisco
Workplace: OnsiteFull timeUSD 264,000 - 363,000 annuallyFunction: Executive & General ManagementExperience: 10+ yearsEducation: bachelorsSkills: ["Executive leadership","Risk management","Mentorship","Cross-functional collaboration","Operational excellence"]

Lead and scale an engineering-forward Governance, Risk, and Compliance (GRC) security organization. Build AI-first GRC programs, including automated evidence collection, risk scoring, policy mapping, and continuous audit readiness. Own enterprise cyber risk management and global compliance posture across major security and privacy frameworks, while leading vendor/SaaS and third-party risk governance and driving audit remediation in partnership with product, legal, privacy, infrastructure, and business technology teams.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Okta
Okta
1 day ago

Senior Director, GRC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live

Job Summary

Lead and scale an engineering-forward Governance, Risk, and Compliance (GRC) security organization. Build AI-first GRC programs, including automated evidence collection, risk scoring, policy mapping, and continuous audit readiness. Own enterprise cyber risk management and global compliance posture across major security and privacy frameworks, while leading vendor/SaaS and third-party risk governance and driving audit remediation in partnership with product, legal, privacy, infrastructure, and business technology teams.
Location: San Francisco
Workplace: Onsite
Employment Type: Full time
Job Function: Executive & General Management
Seniority: Sr. Director level

Key Responsibilities

  • •Integrate AI and agentic tools into daily GRC operations, including automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness.
  • •Operationalize Okta’s AI risk and governance framework, including training data protection, model risk management, responsible AI principles, and alignment to NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
  • •Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification.
  • •Maintain and expand Okta’s global compliance posture across security and privacy frameworks (e.g., SOC 1/2/3, ISO 27001, PCI-DSS, CSA STAR, HDS).
  • •Serve as executive lead for internal/external audits and drive rapid, engineering-led remediation of audit findings and control gaps.

Pay and Benefits

Salary: USD 264,000 - 363,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kFlexible SpendingPaid LeaveParental Leave

Key Requirements

  • •10+ years of progressive executive leadership in Security GRC in a high-growth SaaS, cloud-first or enterprise technology environment.
  • •Strong AI governance expertise, including generative and agentic AI security, data lineage, and global AI regulatory landscapes.
  • •Track record managing compliance for enterprise cloud environments across security and privacy requirements.
  • •Expertise in risk management methodologies, including translating complex technical risk for executive decision-making.
  • •Proven ability to recruit, mentor, and retain high-performing technical GRC engineering and risk management professionals.
Experience:10+ yearsSaaSCloud-firstEnterprise technologyCybersecurityGRCAI governance
Education:Bachelor's
Skills:Executive leadershipRisk managementMentorshipCross-functional collaborationOperational excellence
Languages:English
Tech Stack:AI governanceGenerative AIAgentic AIContinuous control monitoringCompliance-as-codeAI risk managementData lineageTraining data protectionModel risk managementNIST AI RMFISO/IEC 42001EU AI ActSOC 1SOC 2SOC 3ISO 27001ENS HighDPRPCI-DSSCSA STAR

Company Brief

Okta
Provides identity and access management cloud solutions that help organizations secure and manage user authentication, single sign-on, multi-factor authentication, and lifecycle management across applications and devices.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn