Director of Governance, Risk & Compliance
Jobgether
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
429 open governance roles across 113 companies are on ApplySarthi right now, most of them in Bengaluru (21), Hyderabad (17), Mumbai (10).
- Risk & Governance InternRoche
- Director, Technical Product Owner (Data Governance & Privacy Experience)Abbott
- Staff Product Designer - Okta Identity GovernanceOkta
- Data Analyst - Enterprise Technology & Data Governance Process (Hybrid)Broadridge
- Principal - Cybersecurity Audit, Risk & Governance Architect – AI & Emerging TechVerizon
What governance roles keep asking for: Stakeholder management (17%), Python (13%) — counted across their open postings here.
Jobgether has 4,310 open roles listed here.
- Account Director
- Account Executive III - South Atlantic
- Associate Vice President (AVP) of PMO and Delivery
- Asst Dir-Customer Success Manager
- AVP Business Development
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for governance roles keep coming back to Stakeholder management, Python. Practise those questions before you sit with Jobgether.
Questions you are likely to be asked
- Why do you want to join Jobgether?
- What is your experience with Azure? Tell me one thing you learned the hard way.
- Tell me about a problem you solved at work that you are proud of.
- Tell me about a time you disagreed with your manager. What happened?
- Where do you want to be in three years?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Director of Governance, Risk & Compliance at Jobgether interview free →Accountabilities:: Own and mature the internal GRC program and lead the operational delivery of Managed GRC services, establishing standardized methodologies, processes, templates, evidence requirements, and quality controls. Lead risk assessments, control assessments, compliance readiness activities, policy governance, managed audits, managed security questionnaires, and other GRC engagements while managing client commitments, priorities, capacity, quality, and service performance. Lead federal compliance activities, including the development and maintenance of System Security Plans, control implementation statements, supporting evidence, POA&Ms, remediation plans, milestones, and responses to government, assessor, and auditor findings. Coordinate with engineers, security teams, control owners, and clients to validate how security controls are implemented and ensure documented controls accurately reflect the operating environment. Support requirements related to NIST SP 800-53, NIST SP 800-171, FISMA, CMMC, FedRAMP concepts, and agency-specific federal security requirements, including continuous monitoring, assessments, and authorization activities. Manage cybersecurity risk and compliance programs covering risk registers, control gaps, treatment plans, exceptions, remediation tracking, SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks. Oversee managed audit and security questionnaire methodologies, including audit readiness, evidence management, auditor coordination, findings, remediation, and reusable response and evidence libraries. Partner with senior security leadership to operate and strengthen internal compliance initiatives, including SOC 2 Type 2, policy and control governance, third-party risk, customer security reviews, audit coordination, and evidence management. Act as a senior GRC advisor to client security, IT, risk, compliance, and executive leaders, translating regulatory requirements into actionable technical and operational security improvements. Collaborate with Security Operations, cloud, Microsoft 365, and engineering teams to map compliance requirements to technical implementations, with working knowledge of Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy. Support vCISO engagements where governance, risk, audit, and compliance expertise is required, while partnering with Sales and Client Success on service scoping, statements of work, pricing, and complex opportunities. Lead, mentor, and develop GRC Analysts and Consultants while managing workload, capacity, priorities, quality assurance, escalations, and scalable processes that enable the practice to operate effectively without relying on the Director for every engagement. Identify opportunities to use automation and AI to improve GRC delivery, increase consistency, and scale services efficiently. Establish measurable progress through early workflow assessments and prioritized improvements, with long-term ownership of the GRC function, SOC 2 Type 2 program, Managed GRC delivery, federal SSP activities, team development, process maturity, and automation. Requirements 8+ years of experience in cybersecurity, Governance, Risk & Compliance, security assessment, audit, or a related field, with demonstrated experience leading GRC programs or teams. Hands-on experience with NIST SP 800-53, System Security Plans, POA&Ms, control implementation statements, and federal security requirements. Proven experience managing audits, evidence programs, risk assessments, control gaps, policies, remediation initiatives, and compliance activities. Ability to translate regulatory and compliance requirements into practical technical and operational security controls. Strong understanding of frameworks and standards such as SOC 2, NIST, CIS, ISO 27001, PCI DSS, HIPAA, CMMC, and Microsoft security benchmarks. Strong client-facing, executive communication, facilitation, and stakeholder management skills, with the ability to communicate effectively with both senior leaders and technical practitioners. Ability to work directly with engineers and control owners to understand, validate, and document security control implementations. Experience in an MSSP, MSP, consulting, professional services, federal program, or government contractor environment is preferred. Experience with Microsoft Azure and Microsoft 365 security technologies is strongly preferred. Familiarity with Azure, Entra ID, Defender, Sentinel, Intune, Purview, and Azure Policy is an advantage. Relevant certifications such as CISSP, CISM, CRISC, CISA, CGEIT, or similar are valued. Demonstrated leadership qualities including low-ego collaboration, initiative, accountability, empathy, situational awareness, and a bias toward practical problem-solving. Ability to operate strategically with executives while remaining comfortable engaging deeply with technical details, compliance evidence, assessments, and remediation activities. Benefits Competitive salary based on experience and skills. Performance-based compensation with bonus potential in addition to base salary. 401(k) plan with a 100% employer match on employee contributions up to 4% of salary. 100% employer-paid health, vision, and dental insurance premiums for employees. Company-paid life, AD&D, short-term disability, and long-term disability insurance. Three weeks of paid time off that can be used for vacation, personal time, or sick leave. 11 paid holidays each year. Paid community service leave for volunteering with organizations that are meaningful to you. Employee recognition and reward programs celebrating strong performance and contributions. Full-time remote work from anywhere in the United States, with the option to work from a local U.S. office when available. An opportunity to lead a strategic GRC function, develop a team, work on complex federal compliance programs, and build scalable processes and automation.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Art DirectorJobgether
- Art DirectorJobgether
- Art DirectorJobgether
- Art DirectorJobgether
- Chief Technology OfficerJobgether
- Chief Technology OfficerJobgether
- Chief Technology OfficerJobgether
- Chief Technology OfficerJobgether
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on lever · posted 2026-10-01. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.