Director, Governance, Risk & Compliance

Anomali
Redwood City
Workplace: HybridFull timeUSD 180,000 - 230,000 annuallyFunction: Legal, Risk & ComplianceExperience: 8+ yearsSkills: ["Stakeholder management","Written communication","Leadership","Risk management","Cross-functional leadership"]

Own Anomali’s multi-jurisdiction compliance program for an AI-native cybersecurity platform. Drive the end-to-end GRC roadmap across FedRAMP, ISO 27001, and SOC 2, plus regional frameworks like UAE DESC, Saudi NCA/CCC, and Australia IRAP. Maintain certifications to be audit-ready, manage assessor and auditor relationships, build a unified controls framework, and partner cross-functionally to align security controls with technical implementation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Anomali
Anomali
1 month ago

Director, Governance, Risk & Compliance

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 20 minutes agoStatus: Live

Job Summary

Own Anomali’s multi-jurisdiction compliance program for an AI-native cybersecurity platform. Drive the end-to-end GRC roadmap across FedRAMP, ISO 27001, and SOC 2, plus regional frameworks like UAE DESC, Saudi NCA/CCC, and Australia IRAP. Maintain certifications to be audit-ready, manage assessor and auditor relationships, build a unified controls framework, and partner cross-functionally to align security controls with technical implementation.
Location: Redwood City
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Director level

Key Responsibilities

  • •Own the end-to-end GRC roadmap across FedRAMP, ISO 27001, SOC 2, and regional frameworks like DESC, Saudi NCA/CCC, and Australia IRAP.
  • •Manage FedRAMP authorization activities, including ATO maintenance, continuous monitoring, and documentation escalation (SSP, SAR, POA&M).
  • •Maintain and evolve the ISMS, manage audit cycles, and drive continuous improvement of controls and risk assessments under ISO 27001.
  • •Own SOC 2 Type II audit readiness and execution, including evidence collection, control testing, and remediation of exceptions.
  • •Build a unified controls framework across overlapping requirements, manage enterprise risk and third-party risk, and coordinate due diligence with sales and customers.

Pay and Benefits

Salary: USD 180,000 - 230,000 annually

Key Requirements

  • •8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity.
  • •Direct, hands-on FedRAMP (Moderate or High) experience as a CSP-side practitioner.
  • •Demonstrated ownership of ISO 27001 certification and ongoing ISMS management.
  • •Demonstrated ownership of SOC 2 Type II audits from readiness through report delivery.
  • •Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent).
Experience:8+ yearsSaaSCybersecurityInformation securityGRC
Skills:Stakeholder managementWritten communicationLeadershipRisk managementCross-functional leadership
Certifications:CISSPCISACISMISO 27001 Lead Auditor/Implementer
Tech Stack:FedRAMPISO 27001SOC 2UAE DESCSaudi NCA/CCCAustralia IRAPAWSAzureGCPISO/IEC 27001:2013ISO/IEC 27002:2013ISO/IEC 27017:2015CSA Cloud Controls Matrix 3.0.1VantaDrataServiceNow GRC

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Anomali
Provides threat intelligence and detection solutions that help enterprises detect, investigate, and respond to cyber threats by integrating intelligence feeds, analytics, and security platform integrations.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Redwood City, United States
Founded: 2013
WebsiteLinkedIn