← Back to job listings
AN
Director of Governance, Risk & Compliance
Anomali · Redwood City, United States
About The Role
Join Anomali, a leading AI-native cybersecurity platform, as the Director of Governance, Risk & Compliance. In this hands-on role, you will own and drive our multi-jurisdiction certification portfolio, including FedRAMP, ISO 27001, SOC 2, and various regional cloud security frameworks. You will be responsible for maintaining our certifications, ensuring audit readiness, and strategically sequencing efforts to unlock new markets and revenue. This is a builder role, not a maintainer role, and you will be the single point of accountability for compliance outcomes.
- Own and drive the multi-jurisdiction certification portfolio, including FedRAMP, ISO 27001, SOC 2, and regional cloud security frameworks.
- Manage ongoing FedRAMP authorization activities, maintain and evolve the ISMS for ISO 27001, and ensure SOC 2 Type II audit readiness.
- Build and maintain a unified controls framework that maps overlapping requirements across all frameworks to avoid duplicated effort.
- Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
- Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
- Strong working knowledge of cloud security architecture (AWS/Azure/GCP) and how controls map to technical implementation
- Excellent stakeholder management — comfortable working directly with C-suite, auditors, and government sponsors
- Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
- This position is not eligible for employment visa sponsorship. The successful candidate must not now, or in the future, require visa sponsorship to work in the US
- 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
- For candidates residing within commutable distance of Redwood City, CA, this position will be hybrid. Remote candidates based in the US, will also be considered
- Exceptional written communication skills (SSPs, policies, board-level reporting)
- Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
- Familiarity with Australia IRAP assessment process
- Certifications: CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer
- Experience in a high-growth, venture-backed SaaS or cybersecurity company
- Prior experience managing multiple concurrent certifications across regions
- Experience with GRC tooling (Vanta, Drata, ServiceNow GRC, or similar)
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring