FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Director, Governance Risk and Compliance
Anthology Careers. Lead efforts to assess the confidentiality, integrity and availability of information through the company's global ISMS framework .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in managing information security programs, including risk management, compliance with security standards, and effective communication with leadership. Proficient in developing and maintaining ISMS documentation and conducting vendor risk assessments while ensuring alignment with regulatory requirements.
Highest-signal resume keywords
10+ Years IT Audit ExperienceISO27000 Series KnowledgeCISA, CISM, CISSP CertificationFedRAMP, GovRAMP, IL-4 ExperienceSecurity Incident Response Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information Security Management System (ISMS)Risk ManagementCompliance AssessmentSecurity Controls Effectiveness MeasurementIdentity and Access ManagementVendor Risk AssessmentDocumentation ManagementBusiness Continuity ManagementProject ManagementSecurity Standards and Frameworks
Soft Skills
Strong Communication SkillsCollaborationMentoringRelationship BuildingOrganizational Awareness
Tools & Technologies
Cloud InfrastructureNetwork TechnologiesSecurity Incident Response ToolsAudit Management ToolsCompliance Management Software
Certifications & Qualifications
CISACISMCISSP
Industry Keywords
IT AuditComplianceData Privacy LawsSecurity ThreatsISO/SOC AuditsThird-Party Risk ManagementSecurity AwarenessRegulatory ComplianceSecurity Program AlignmentSoftware Development Lifecycle
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Lead efforts to assess the confidentiality, integrity and availability of information through the company's global ISMS framework
- Assess compliance with company security policies
- Operate internal and third-party risk management processes
- Review and measure the effectiveness of information security controls
- Liaise with and advise systems architecture, systems deployments, and application configuration teams
- Develop and maintain ISMS documentation, including policies, standards, and procedures
- Recommend security program alignment with compliance requirements to the CISO, Product Management, Legal, and Finance leadership teams
- Manage information risk and collaboratively design and assess information security controls, including identity and access management
- Monitor evolving regulations, security threats, and compliance best practices and update policies and procedures
- Maintain and improve organizational information security awareness
- Translate business and information security needs into the ISMS
- Coordinate external audits with 3PAO, ISO/SOC auditors, PCI DSS QSA firms, and other security assessors, including responses and remediation
- Conduct vendor risk assessments and ensure third-party compliance with security and privacy standards
- Review and monitor Security Incident Response and Business Continuity Management activities across business continuity and disaster recovery lifecycles
- Measure ISMS control effectiveness and communicate findings to senior management
- Enforce document control management processes for the ISMS
- Assist with forecasting, planning, and risk assessment for evolving security control coverage aligned with technology strategy
- Maintain and apply industry knowledge and best practices
- Research and recommend new technologies
- Manage projects, including business requirements analysis, project plans, and completion tracking
- Assist with vendor management, forecasting, and program budget management
- Manage personnel, including mentoring and cross-training team members
Requirements
What you’ll need- US Citizenship
- 10+ years of hands-on experience in IT audit and/or compliance
- Strong documentation and communication skills
- Strong understanding of security standards and frameworks including ISO27000 series, NIST Special Publication 800 series, SOC audits, and security requirements of Data Privacy laws
- Previous experience gaining an ATO or P-ATO for a cloud implementation under the FedRAMP, GovRAMP or IL-4 programs
- Understanding of software development lifecycle methodologies, cloud and server infrastructure, network technologies
- Experience managing security staff, collaboration and relationship building with global teams
- Fluency in written and spoken English
- Current CISA, CISM, CISSP or equivalent certification is strongly preferred
- Candidates must be legally authorized to work in the country where the role is based at the time of hire and must maintain that authorization for the duration of employment
- The company does not provide visa sponsorship or immigration support for this position
Benefits
Comp & perks- Additional compensation such as company bonus or benefits
- Equal employment opportunity/affirmative action protections