bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesEhtl Fa Us6 Oraclecloud Com CXDirector, Governance, Risk, & Compliance (GRC)

Director, Governance, Risk, & Compliance (GRC)

Ehtl Fa Us6 Oraclecloud Com CX · Golden Valley, MN, United States; USA - Austin - TXB4, Austin, TX, US; USA - Golden Valley - MN10, Golden Valley, MN, US · On Site · Active · $7 / hour · Oracle Recruiting Cloud / Fusion HCM

Job facts

FieldValue
CompanyEhtl Fa Us6 Oraclecloud Com CX
TitleDirector, Governance, Risk, & Compliance (GRC)
Normalized title-
Department / teamInformation Technology Mgmt
LocationGolden Valley, MN, United States
Work modelOn Site
Employment typeFull Time
Salary$7 / hour
Statusactive
ATS providerOracle Recruiting Cloud / Fusion HCM
Posted / first seen2026-05-15 / 2026-05-31
Changed / last seen2026-05-31 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Ehtl Fa Us6 Oraclecloud Com CX.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Oracle Recruiting Cloud / Fusion HCM.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Golden Valley.Open
Department jobsActive postings in Information Technology Mgmt.Open
Work model jobsActive On Site postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyEhtl Fa Us6 Oraclecloud Com CX
Source1a98c44c-d165-4db2-90fd-8ebb67f4ab5e
ATS providerOracle Recruiting Cloud / Fusion HCM

Description

Description The Director of Governance, Risk & Compliance (GRC) is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that transforms governance from a compliance-focused function into a fast, intelligent, and risk-based engine for the business. Reporting directly to the CISO, this role serves as the architect of a scalable GRC capability that modernizes how cyber risk is identified, measured, prioritized, reported, and acted upon across the enterprise and product portfolio. The Director will leverage data, automation, analytics, and the responsible application of AI to create a single authoritative view of cyber risk, reduce operational friction, accelerate decision-making, and ensure governance operates at the speed and scale of the business. This role partners closely with Security, IT, Product Engineering, Legal, Privacy, Finance, Internal Audit, and executive leadership to embed risk-based governance into how the organization plans, builds, and operates. This is a transformational role for a builder—someone who can challenge legacy GRC models, simplify complexity, and deliver board-ready insights that clearly articulate business impact, financial exposure, and strategic trade-offs. The Director will create a program that is defensible, measurable, portfolio-driven, and future-ready, enabling enterprise resilience, product innovation, regulatory confidence, and informed risk ownership. Job Duties Cybersecurity Governance & Operating Model Define and maintain the enterprise cybersecurity governance framework, including decision rights, escalation paths, and exception handling. Own the cybersecurity policy, standards, and exception lifecycle across enterprise and product environments. Ensure clear ownership and accountability for security controls, compliance obligations, and accepted risks. Serve as a senior advisor to the CISO and executive leadership on governance decisions and material risk trade-offs. Enterprise, Product & Portfolio Risk Management Own the cybersecurity risk management framework, including risk taxonomy, scoring methodology, appetite, and acceptance thresholds. Maintain the enterprise risk register and an integrated portfolio view of cyber risk across enterprise, product, and third-party domains. Provide leadership with an aggregate, decision-ready risk posture to support prioritization, investment planning, and risk acceptance. Lead risk assessments for enterprise IT, cloud platforms, connected products, and critical suppliers. Ensure risk acceptance decisions are well-documented, time-bound, reviewed, and auditable. Executive & Board-Level Risk Communication Lead preparation of cybersecurity risk materials for executive leadership, board committees, and full board briefings. Translate technical and operational cyber risk into business impact, financial exposure, and strategic implications. Support the CISO in board-level discussions related to cyber risk posture, trends, and material risk decisions. Compliance & Regulatory Readiness (Enterprise & Product) Lead enterprise and product cybersecurity compliance programs aligned to regulatory, statutory, and customer requirements. Translate regulatory obligations into pragmatic, enforceable control expectations embedded into business and engineering workflows. Partner with Product Security and Engineering to integrate security-by-design and compliance into product development lifecycles. Monitor emerging regulations and contractual obligations and define readiness roadmaps that minimize disruption to delivery. Audit, Certification & Assurance Own security audit, customer assurance, and certification readiness across enterprise and product environments. Establish an always-audit-ready operating model with defined control ownership, evidence standards, and testing cadence. Oversee remediation of audit findings and control gaps using durable, sustainable solutions. Provide executive visibility into audit status, findings, trends, and remediation progress. Third-Party, Supply Chain & Cyber Insurance Support Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight. Define risk-based tiering, minimum security requirements, and escalation thresholds for suppliers. Partner with Finance, Legal, and Risk Management to support cyber insurance underwriting, renewals, and claims. Provide risk data, metrics, and control evidence required to support cyber insurance placement and renewal activities. Metrics, Reporting & Continuous Improvement Define and maintain key risk indicators (KRIs), compliance metrics, and portfolio-level reporting. Use automation, analytics, and AI-enabled capabilities to improve risk signal quality and reduce manual effort. Continuously optimize GRC processes to improve efficiency, decision speed, and risk transparency. Training, Awareness & Adoption Partner with HR and Security Leadership to reinforce governance and risk expectations through role-based training. Drive consistent adoption of governance practices across IT, engineering, and product organizations. Scope of Authority Accountable for enterprise and product cybersecurity governance, risk management, compliance, and portfolio reporting. Approves cybersecurity governance frameworks, risk methodologies, and compliance operating models. Escalates material risks, trends, and control gaps to the CISO with clear options and recommendations. You Must Have 10+ years of experience in cybersecurity governance, risk management, compliance, or assurance. 5+ years leading enterprise-scale GRC programs or teams. Demonstrated experience supporting executive and board-level risk discussions. We Value Strong executive communication and stakeholder management skills. Professional certifications such as CISSP, CISM, CRISC, or CISA. Experience with modern GRC platforms, automation, analytics, and AI-augmented GRC workflows. Experience applying AI responsibly in areas such as risk assessment, control testing, evidence management, or continuous monitoring. Experience with connected products, cloud platforms, or regulated technology environments. Experience operating in global or multi-jurisdiction organizations. Builder mindset with the ability to modernize and scale GRC capabilities. Business-oriented, risk-based decision-maker with strong judgment and integrity. Comfortable operating with board-level visibility and accountability. Able to influence executives, engineers, and partners with equal credibility. Pragmatic, structured, and execution-focused leadership style. WHAT'S IN IT FOR YOU Join a team that truly values work life integration and balance where your well being comes first. Grow your career while diving into cutting edge technologies and continuous learning opportunities. Help shape innovative IoT and control solutions that influence the everyday lives of millions. Channel your curiosity and passion for discovery while exploring new possibilities and bringing forward bold use cases that help us pioneer the future. #LI-MA1 #LI-HYBRID Company Resideo Technologies has announced its intention to spin off ADI Global Distribution and establish it as a separate, publicly traded company. Under this plan, ADI will continue its role as a leading global wholesale distributor serving commercial and residential markets, while Resideo will retain its manufacturing and product-solutions business. Upon separation, both companies will operate independently to better serve their respective markets and customers. The spin-off is currently targeted for completion in the second half of 2026, subject to customary conditions. Resideo is a $6.76 billion global manufacturer, developer, and distributor of technology-driven sensing and control solutions that help homeowners and businesses stay connected and in control of their comfort, security, energy use, and smart living. We focus on the professional channel, serving over 100,000 contractors, installers, dealers, and integrators across the HVAC, security, fire, electrical, and home comfort markets. Our products are found in more than 150 million residential and commercial spaces worldwide, with tens of millions of new devices sold annually. Trusted brands like Honeywell Home, First Alert, and Resideo power connected living for over 12.8 million customers through our Products & Solutions segment. Our ADI | Snap One segment spans 200+ stocking locations in 17 countries, offering a catalog of over 500,000 products from more than 1,000 manufacturers. With a global team of more than 14,000 employees, we offer the opportunity to make a real impact in a fast-growing, purpose-driven industry. Learn more at www.resideo.com . At Resideo, we bring together diverse individuals to build the future of homes. Resideo is an equal opportunity employer. Qualified applicants will be considered without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, sex, religion, or veteran status. For more information on applicable U.S. equal employment regulations, refer to the "EEO is the Law" poster , "EEO is the Law" Supplement Poster and the Pay Transparency Nondiscrimination Provision . Resideo complies with applicable equal employment laws in all countries where we do business. For more information on how we process your information in the job application process, please refer to Recruitment Privacy Notice . If you require a reasonable accommodation to apply for a job, please use Contact Us form for assistance.

Full job record

Job IDe72bbfcef57bfe39389f00e615f26caaa187f64a
Org IDe5d05530-407a-4053-a724-bbb57ff28ba3
Source ID1a98c44c-d165-4db2-90fd-8ebb67f4ab5e
Board ID1a98c44c-d165-4db2-90fd-8ebb67f4ab5e
Provideroracle_hcm
Provider Job Key18411
TitleDirector, Governance, Risk, & Compliance (GRC)
Normalized Title
Statusactive
Activeyes
Location TextGolden Valley, MN, United States; USA - Austin - TXB4, Austin, TX, US; USA - Golden Valley - MN10, Golden Valley, MN, US
DepartmentInformation Technology Mgmt
Team
Employment Typefull_time
Workplace Typeon_site
Remote Policy
CountryUnited States
RegionMN
CityGolden Valley
Salary RawDescription The Director of Governance, Risk & Compliance (GRC) is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that transforms governance from a compliance-focused function into a fast, intelligent, and risk-based engine for the business. Reporting directly to the CISO, this role serves as the architect of a scalable GRC capability that modernizes how cyber risk is identified, measured, prioritized, reported, and acted upon across the enterprise and product portfolio. The Director will leverage data, automation, analytics, and the responsible application of AI to create a single authoritative view of cyber risk, reduce operational friction, accelerate decision-making, and ensure governance operates at the speed and scale of the business. This role partners closely with Security, IT, Product Engineering, Legal, Privacy, Finance, Internal Audit, and executive leadership to embed risk-based governance into how the organization plans, builds, and operates. This is a transformational role for a builder—someone who can challenge legacy GRC models, simplify complexity, and deliver board-ready insights that clearly articulate business impact, financial exposure, and strategic trade-offs. The Director will create a program that is defensible, measurable, portfolio-driven, and future-ready, enabling enterprise resilience, product innovation, regulatory confidence, and informed risk ownership. Job Duties Cybersecurity Governance & Operating Model Define and maintain the enterprise cybersecurity governance framework, including decision rights, escalation paths, and exception handling. Own the cybersecurity policy, standards, and exception lifecycle across enterprise and product environments. Ensure clear ownership and accountability for security controls, compliance obligations, and accepted risks. Serve as a senior advisor to the CISO and executive leadership on governance decisions and material risk trade-offs. Enterprise, Product & Portfolio Risk Management Own the cybersecurity risk management framework, including risk taxonomy, scoring methodology, appetite, and acceptance thresholds. Maintain the enterprise risk register and an integrated portfolio view of cyber risk across enterprise, product, and third-party domains. Provide leadership with an aggregate, decision-ready risk posture to support prioritization, investment planning, and risk acceptance. Lead risk assessments for enterprise IT, cloud platforms, connected products, and critical suppliers. Ensure risk acceptance decisions are well-documented, time-bound, reviewed, and auditable. Executive & Board-Level Risk Communication Lead preparation of cybersecurity risk materials for executive leadership, board committees, and full board briefings. Translate technical and operational cyber risk into business impact, financial exposure, and strategic implications. Support the CISO in board-level discussions related to cyber risk posture, trends, and material risk decisions. Compliance & Regulatory Readiness (Enterprise & Product) Lead enterprise and product cybersecurity compliance programs aligned to regulatory, statutory, and customer requirements. Translate regulatory obligations into pragmatic, enforceable control expectations embedded into business and engineering workflows. Partner with Product Security and Engineering to integrate security-by-design and compliance into product development lifecycles. Monitor emerging regulations and contractual obligations and define readiness roadmaps that minimize disruption to delivery. Audit, Certification & Assurance Own security audit, customer assurance, and certification readiness across enterprise and product environments. Establish an always-audit-ready operating model with defined control ownership, evidence standards, and testing cadence. Oversee remediation of audit findings and control gaps using durable, sustainable solutions. Provide executive visibility into audit status, findings, trends, and remediation progress. Third-Party, Supply Chain & Cyber Insurance Support Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight. Define risk-based tiering, minimum security requirements, and escalation thresholds for suppliers. Partner with Finance, Legal, and Risk Management to support cyber insurance underwriting, renewals, and claims. Provide risk data, metrics, and control evidence required to support cyber insurance placement and renewal activities. Metrics, Reporting & Continuous Improvement Define and maintain key risk indicators (KRIs), compliance metrics, and portfolio-level reporting. Use automation, analytics, and AI-enabled capabilities to improve risk signal quality and reduce manual effort. Continuously optimize GRC processes to improve efficiency, decision speed, and risk transparency. Training, Awareness & Adoption Partner with HR and Security Leadership to reinforce governance and risk expectations through role-based training. Drive consistent adoption of governance practices across IT, engineering, and product organizations. Scope of Authority Accountable for enterprise and product cybersecurity governance, risk management, compliance, and portfolio reporting. Approves cybersecurity governance frameworks, risk methodologies, and compliance operating models. Escalates material risks, trends, and control gaps to the CISO with clear options and recommendations. You Must Have 10+ years of experience in cybersecurity governance, risk management, compliance, or assurance. 5+ years leading enterprise-scale GRC programs or teams. Demonstrated experience supporting executive and board-level risk discussions. We Value Strong executive communication and stakeholder management skills. Professional certifications such as CISSP, CISM, CRISC, or CISA. Experience with modern GRC platforms, automation, analytics, and AI-augmented GRC workflows. Experience applying AI responsibly in areas such as risk assessment, control testing, evidence management, or continuous monitoring. Experience with connected products, cloud platforms, or regulated technology environments. Experience operating in global or multi-jurisdiction organizations. Builder mindset with the ability to modernize and scale GRC capabilities. Business-oriented, risk-based decision-maker with strong judgment and integrity. Comfortable operating with board-level visibility and accountability. Able to influence executives, engineers, and partners with equal credibility. Pragmatic, structured, and execution-focused leadership style. WHAT'S IN IT FOR YOU Join a team that truly values work life integration and balance where your well being comes first. Grow your career while diving into cutting edge technologies and continuous learning opportunities. Help shape innovative IoT and control solutions that influence the everyday lives of millions. Channel your curiosity and passion for discovery while exploring new possibilities and bringing forward bold use cases that help us pioneer the future. #LI-MA1 #LI-HYBRID Company Resideo Technologies has announced its intention to spin off ADI Global Distribution and establish it as a separate, publicly traded company. Under this plan, ADI will continue its role as a leading global wholesale distributor serving commercial and residential markets, while Resideo will retain its manufacturing and product-solutions business. Upon separation, both companies will operate independently to better serve their respective markets and customers. The spin-off is currently targeted for completion in the second half of 2026, subject to customary conditions. Resideo is a $6.76 billion global manufacturer, developer, and distributor of technology-driven sensing and control solutions that help homeowners and businesses stay connected and in control of their comfort, security, energy use, and smart living. We focus on the professional channel, serving over 100,000 contractors, installers, dealers, and integrators across the HVAC, security, fire, electrical, and home comfort markets. Our products are found in more than 150 million residential and commercial spaces worldwide, with tens of millions of new devices sold annually. Trusted brands like Honeywell Home, First Alert, and Resideo power connected living for over 12.8 million customers through our Products & Solutions segment. Our ADI | Snap One segment spans 200+ stocking locations in 17 countries, offering a catalog of over 500,000 products from more than 1,000 manufacturers. With a global team of more than 14,000 employees, we offer the opportunity to make a real impact in a fast-growing, purpose-driven industry. Learn more at www.resideo.com . At Resideo, we bring together diverse individuals to build the future of homes. Resideo is an equal opportunity employer. Qualified applicants will be considered without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, sex, religion, or veteran status. For more information on applicable U.S. equal employment regulations, refer to the "EEO is the Law" poster , "EEO is the Law" Supplement Poster and the Pay Transparency Nondiscrimination Provision . Resideo complies with applicable equal employment laws in all countries where we do business. For more information on how we process your information in the job application process, please refer to Recruitment Privacy Notice . If you require a reasonable accommodation to apply for a job, please use Contact Us form for assistance.
Salary Min6.76
Salary Max
Salary CurrencyUSD
Salary Periodhour
Source URLhttps://ehtl.fa.us6.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX/job/18411
Apply URLhttps://ehtl.fa.us6.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX/job/18411
First Seen At2026-05-31 17:57:37Z
Last Seen At2026-06-06 19:31:52Z
Last Checked At2026-06-06 19:31:52Z
Last Changed At2026-05-31 17:57:37Z
Inactive At
Source Posted At2026-05-15 14:00:00Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=oracle_hcm/board=ehtl.fa.us6.oraclecloud.com|CX/date=2026-06-06/2026-06-06T19-31-42-177Z-324849bbc40b961145e18b5916fa522eb782eec3bb05eb34c049945d3812f6dd.json
Event Fields
{
  "content_hash": "2c3676b40edbcc5c3e6420300825284794c6e373f78cd6800de70131d14777db",
  "source_hash": "576d1e67211eb65d85d90f3ac9ef64e8afe30b496d7dce796cc0c4bbd8c2b667",
  "last_changed_at": "2026-05-31T17:57:37.470Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Golden Valley, MN, United States",
    "city": "Golden Valley",
    "region": "MN",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": 6.76,
  "inferred_at": "2026-06-06T19:31:52.327Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Golden Valley, MN, United States",
      "city": "Golden Valley",
      "region": "MN",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": null,
  "salary_period": "hour",
  "workplace_type": "on_site",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "detail": {
    "Id": "18411",
    "Title": "Director, Governance, Risk, & Compliance (GRC)",
    "media": [],
    "skills": [],
    "JobType": null,
    "Category": "Information Technology Mgmt",
    "JobGrade": null,
    "JobLevel": null,
    "JobShift": null,
    "WorkDays": null,
    "WorkHours": null,
    "WorkYears": null,
    "Department": null,
    "HotJobFlag": false,
    "StudyLevel": null,
    "WorkMonths": null,
    "WorkerType": null,
    "GeographyId": 300000002468504,
    "JobFamilyId": 300000006871789,
    "JobFunction": "Information Technology",
    "JobSchedule": "Full time",
    "BusinessUnit": null,
    "ContractType": null,
    "Organization": null,
    "TrendingFlag": true,
    "workLocation": [
      {
        "Country": "US",
        "Region1": "Travis",
        "Region2": "TX",
        "Region3": null,
        "Building": null,
        "Latitude": "30.38305",
        "Longitude": "-97.70534",
        "LocationId": 300025482820697,
        "PostalCode": "78758",
        "TownOrCity": "Austin",
        "AddressLine1": "2201 Donley Drive, Suite 100",
        "AddressLine2": null,
        "AddressLine3": null,
        "AddressLine4": null,
        "LocationName": "USA - Austin - TXB4"
      }
    ],
    "ContentLocale": "en",
    "HiringManager": null,
    "LegalEmployer": null,
    "RequisitionId": 300026259658160,
    "WorkplaceType": "On-site",
    "BusinessUnitId": 300000006497427,
    "OrganizationId": 1,
    "GeographyNodeId": 100000507379837,
    "JobFunctionCode": "D",
    "LegalEmployerId": 300024698389932,
    "PrimaryLocation": "Golden Valley, MN, United States",
    "RequisitionType": "Professional",
    "NumberOfOpenings": null,
    "WorkplaceTypeCode": "ORA_ON_SITE",
    "BeFirstToApplyFlag": false,
    "otherWorkLocations": [
      {
        "Country": "US",
        "Region1": "Hennepin",
        "Region2": "MN",
        "Region3": null,
        "Building": null,
        "Latitude": "45.01208",
        "Longitude": "-93.34133",
        "LocationId": 300000006875982,
        "PostalCode": "55422",
        "TownOrCity": "Golden Valley",
        "AddressLine1": "1985 Douglas Drive North",
        "AddressLine2": null,
        "AddressLine3": null,
        "AddressLine4": null,
        "LocationName": "USA - Golden Valley - MN10",
        "RequisitionWorkLocationId": 300026259684639
      }
    ],
    "secondaryLocations": [
      {
        "Name": "Austin, TX, United States",
        "Latitude": "30.45414",
        "Longitude": "-97.78254",
        "CountryCode": "US",
        "GeographyId": 300000002485194,
        "GeographyNodeId": 100000507392040,
        "RequisitionLocationId": 300026322461354
      }
    ],
    "ExternalContactName": null,
    "ShortDescriptionStr": "The Director of Governance, Risk & Compliance (GRC) is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that transforms governance from a compliance-focused function into a fast, intelligent, and risk-based engine for the business. Reporting directly to the CISO, this role serves as the architect of a scalable GRC capability that modernizes how cyber risk is identified, measured, prioritized, reported, and acted upon across the enterprise and product portfolio.",
    "ExternalContactEmail": null,
    "ExternalPostedEndDate": null,
    "OtherRequisitionTitle": null,
    "requisitionFlexFields": [
      {
        "Value": "RBP",
        "Prompt": "Incentive Eligible",
        "ControlType": "SingleChoiceList",
        "SequenceNumber": 6
      },
      {
        "Value": "Resideo",
        "Prompt": "Business",
        "ControlType": "SingleChoiceList",
        "SequenceNumber": 14
      },
      {
        "Value": "The typical hiring salary for this role, ranges from USD $177600.0 to $264960.0 per year but varies by specific work location. Within a range, Resideo determines base pay for an individual based on various factors, including market conditions, skills, and experience.",
        "Prompt": "Hiring Salary Range",
        "ControlType": "TextArea",
        "SequenceNumber": 16
      },
      {
        "Value": "This position is eligible for a performance-based bonus of up to 15% of the annual base salary. The bonus is contingent upon both individual and company performance.",
        "Prompt": "Incentive Eligible (RBP)\t",
        "ControlType": "TextArea",
        "SequenceNumber": 21
      },
      {
        "Value": "Resideo provides comprehensive benefits, including life and health insurance, life assistance program, accidental death and dismemberment insurance, disability insurance, 401k Plan, vacation & holidays.  ",
        "Prompt": "Benefits",
        "ControlType": "TextArea",
        "SequenceNumber": 25
      },
      {
        "Value": "This position is not eligible for US visa sponsorship",
        "Prompt": "US Visa Sponsorship Eligibility",
        "ControlType": "SingleChoiceList",
        "SequenceNumber": 26
      }
    ],
    "ApplyWhenNotPostedFlag": false,
    "DomesticTravelRequired": null,
    "ExternalDescriptionStr": "<p>The Director of Governance, Risk &amp; Compliance (GRC) is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that transforms governance from a compliance-focused function into a fast, intelligent, and risk-based engine for the business. Reporting directly to the CISO, this role serves as the architect of a scalable GRC capability that modernizes how cyber risk is identified, measured, prioritized, reported, and acted upon across the enterprise and product portfolio. The Director will leverage data, automation, analytics, and the responsible application of AI to create a single authoritative view of cyber risk, reduce operational friction, accelerate decision-making, and ensure governance operates at the speed and scale of the business. This role partners closely with Security, IT, Product Engineering, Legal, Privacy, Finance, Internal Audit, and executive leadership to embed risk-based governance into how the organization plans, builds, and operates.</p><p>This is a transformational role for a builder—someone who can challenge legacy GRC models, simplify complexity, and deliver board-ready insights that clearly articulate business impact, financial exposure, and strategic trade-offs. The Director will create a program that is defensible, measurable, portfolio-driven, and future-ready, enabling enterprise resilience, product innovation, regulatory confidence, and informed risk ownership.<br>&nbsp;</p><p><strong>Job Duties</strong><br><strong>Cybersecurity Governance &amp; Operating Model</strong></p><ul><li>Define and maintain the enterprise cybersecurity governance framework, including decision rights, escalation paths, and exception handling.</li><li>Own the cybersecurity policy, standards, and exception lifecycle across enterprise and product environments.</li><li>Ensure clear ownership and accountability for security controls, compliance obligations, and accepted risks.</li><li>Serve as a senior advisor to the CISO and executive leadership on governance decisions and material risk trade-offs.</li></ul><p><strong>Enterprise, Product &amp; Portfolio Risk Management</strong></p><ul><li>Own the cybersecurity risk management framework, including risk taxonomy, scoring methodology, appetite, and acceptance thresholds.</li><li>Maintain the enterprise risk register and an integrated portfolio view of cyber risk across enterprise, product, and third-party domains.</li><li>Provide leadership with an aggregate, decision-ready risk posture to support prioritization, investment planning, and risk acceptance.</li><li>Lead risk assessments for enterprise IT, cloud platforms, connected products, and critical suppliers.</li><li>Ensure risk acceptance decisions are well-documented, time-bound, reviewed, and auditable.</li></ul><p><strong>Executive &amp; Board-Level Risk Communication</strong></p><ul><li>Lead preparation of cybersecurity risk materials for executive leadership, board committees, and full board briefings.</li><li>Translate technical and operational cyber risk into business impact, financial exposure, and strategic implications.</li><li>Support the CISO in board-level discussions related to cyber risk posture, trends, and material risk decisions.</li></ul><p><strong>Compliance &amp; Regulatory Readiness (Enterprise &amp; Product)</strong></p><ul><li>Lead enterprise and product cybersecurity compliance programs aligned to regulatory, statutory, and customer requirements.</li><li>Translate regulatory obligations into pragmatic, enforceable control expectations embedded into business and engineering workflows.</li><li>Partner with Product Security and Engineering to integrate security-by-design and compliance into product development lifecycles.</li><li>Monitor emerging regulations and contractual obligations and define readiness roadmaps that minimize disruption to delivery.</li></ul><p><strong>Audit, Certification &amp; Assurance</strong></p><ul><li>Own security audit, customer assurance, and certification readiness across enterprise and product environments.</li><li>Establish an always-audit-ready operating model with defined control ownership, evidence standards, and testing cadence.</li><li>Oversee remediation of audit findings and control gaps using durable, sustainable solutions.</li><li>Provide executive visibility into audit status, findings, trends, and remediation progress.</li></ul><p><strong>Third-Party, Supply Chain &amp; Cyber Insurance Support</strong></p><ul><li>Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight.</li><li>Define risk-based tiering, minimum security requirements, and escalation thresholds for suppliers.</li><li>Partner with Finance, Legal, and Risk Management to support cyber insurance underwriting, renewals, and claims.</li><li>Provide risk data, metrics, and control evidence required to support cyber insurance placement and renewal activities.</li></ul><p><strong>Metrics, Reporting &amp; Continuous Improvement</strong></p><ul><li>Define and maintain key risk indicators (KRIs), compliance metrics, and portfolio-level reporting.</li><li>Use automation, analytics, and AI-enabled capabilities to improve risk signal quality and reduce manual effort.</li><li>Continuously optimize GRC processes to improve efficiency, decision speed, and risk transparency.</li></ul><p><strong>Training, Awareness &amp; Adoption</strong></p><ul><li>Partner with HR and Security Leadership to reinforce governance and risk expectations through role-based training.</li><li>Drive consistent adoption of governance practices across IT, engineering, and product organizations.</li></ul><p><strong>Scope of Authority</strong></p><ul><li>Accountable for enterprise and product cybersecurity governance, risk management, compliance, and portfolio reporting.</li><li>Approves cybersecurity governance frameworks, risk methodologies, and compliance operating models.</li><li>Escalates material risks, trends, and control gaps to the CISO with clear options and recommendations.<br>&nbsp;</li></ul><p><strong>You Must Have</strong></p><ul><li>10+ years of experience in cybersecurity governance, risk management, compliance, or assurance.</li><li>5+ years leading enterprise-scale GRC programs or teams.</li><li>Demonstrated experience supporting executive and board-level risk discussions.</li></ul><p><strong>We Value</strong></p><ul><li>Strong executive communication and stakeholder management skills.&nbsp;&nbsp;&nbsp;</li><li>&nbsp;Professional certifications such as CISSP, CISM, CRISC, or CISA.</li><li>Experience with modern GRC platforms, automation, analytics, and AI-augmented GRC workflows.</li><li>Experience applying AI responsibly in areas such as risk assessment, control testing, evidence management, or continuous monitoring.</li><li>Experience with connected products, cloud platforms, or regulated technology environments.</li><li>Experience operating in global or multi-jurisdiction organizations.</li><li>Builder mindset with the ability to modernize and scale GRC capabilities.</li><li>Business-oriented, risk-based decision-maker with strong judgment and integrity.</li><li>Comfortable operating with board-level visibility and accountability.</li><li>Able to influence executives, engineers, and partners with equal credibility.</li><li>Pragmatic, structured, and execution-focused leadership style.</li></ul><p><strong>WHAT'S IN IT FOR YOU</strong></p><ul><li>Join a team that truly values work life integration and balance where your well being comes first.&nbsp;</li><li>Grow your career while diving into cutting edge technologies and continuous learning opportunities.&nbsp;</li><li>Help shape innovative IoT and control solutions that influence the everyday lives of millions.&nbsp;</li><li>Channel your curiosity and passion for discovery while exploring new possibilities and bringing forward bold use cases that help us pioneer the future.</li></ul><p>&nbsp;</p><p>#LI-MA1<br>#LI-HYBRID<br><br>&nbsp;</p>",
    "ObjectVerNumberProfile": null,
    "PrimaryLocationCountry": "US",
    "CorporateDescriptionStr": "<p>Resideo Technologies has announced its intention to spin off ADI Global Distribution and establish it as a separate, publicly traded company. Under this plan, ADI will continue its role as a leading global wholesale distributor serving commercial and residential markets, while Resideo will retain its manufacturing and product-solutions business. Upon separation, both companies will operate independently to better serve their respective markets and customers. The spin-off is currently targeted for completion in the second half of 2026, subject to customary conditions.</p>\n<p>Resideo is a $6.76 billion global manufacturer, developer, and distributor of technology-driven sensing and control solutions that help homeowners and businesses stay connected and in control of their comfort, security, energy use, and smart living. We focus on the professional channel, serving over 100,000 contractors, installers, dealers, and integrators across the HVAC, security, fire, electrical, and home comfort markets. Our products are found in more than 150 million residential and commercial spaces worldwide, with tens of millions of new devices sold annually. Trusted brands like Honeywell Home, First Alert, and Resideo power connected living for over 12.8 million customers through our Products &amp; Solutions segment. Our ADI | Snap One segment spans 200&amp;#43; stocking locations in 17 countries, offering a catalog of over 500,000 products from more than 1,000 manufacturers. With a global team of more than 14,000 employees, we offer the opportunity to make a real impact in a fast-growing, purpose-driven industry. Learn more at&nbsp;<a href=\"http://www.resideo.com/\" target=\"_blank\" rel=\"nofollow\">www.resideo.com</a>.</p>\n<p>At Resideo, we bring together diverse individuals to build the future of homes. Resideo is an equal opportunity employer. Qualified applicants will be considered without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, sex, religion, or veteran status. For more information on applicable U.S. equal employment regulations, refer to the&nbsp;<a href=\"https://www.resideo.com/us/en/-/media/Resideo/Files/Corporate/Careers/EEO%20is%20the%20Law%20poster.pdf?rv=fdc492d184344b3ea4aec0c96b321632\" target=\"_blank\" rel=\"nofollow\">\"EEO is the Law\" poster</a>,&nbsp;<a href=\"https://www.resideo.com/us/en/-/media/Resideo/Files/Corporate/Careers/EEO%20is%20the%20Law%20Supplement%20Poster.pdf?rv=ebe367cad846443e8fa5aa86062813b6\" target=\"_blank\" rel=\"nofollow\">\"EEO is the Law\" Supplement Poster&nbsp;</a>and the&nbsp;<a href=\"https://www.resideo.com/us/en/-/media/Resideo/Files/Corporate/Careers/Pay%20Transparency%20Nondiscrimination%20Provision.pdf?rv=11a9cf6533ba426296b137d906b0ce01\" target=\"_blank\" rel=\"nofollow\">Pay Transparency Nondiscrimination Provision</a>. Resideo complies with applicable equal employment laws in all countries where we do business. For more information on how we process your information in the job application process, please refer to&nbsp;<a href=\"https://www.resideo.com/us/en/-/media/Resideo/Files/Corporate/Resideo%20%20-%20Recruitment%20Privacy%20Notice.pdf?rv=6d871e71bfa24982b181c92fda232b7a\" target=\"_blank\" rel=\"nofollow\">Recruitment Privacy Notice</a>. If you require a reasonable accommodation to apply for a job, please use&nbsp;<a href=\"mailto:[email protected]?subject=Contact%20Us%20Form%20%E2%80%93%20Job%20Application%20Assistance&amp;body=This%20mailbox%20is%20intended%20only%20for%20assistance%20applying.%20%20We%20require%20candidates%20apply%20through%20our%20website.%20%20Please%20visit%20www.resideo.com/careers%20to%20find%20positions%20matching%20your%20interests%20and%20experience%20to%20apply%20for.%20%20Resumes%20sent%20to%20this%20mailbox%20will%20not%20be%20accepted.%0D%0APlease%20describe%20reasonable%20accommodation%20needed%20or%20issues%20you%20are%20having%20with%20your%20application%20below.%20%20Including%20job%20requisition%20number,%20title%20and%20location%20will%20aid%20us%20in%20assisting%20you.\" target=\"_blank\" rel=\"nofollow\">Contact Us&nbsp;</a>form for assistance.</p>",
    "ExternalPostedStartDate": "2026-05-15T14:00:00+00:00",
    "ExternalQualificationsStr": "",
    "InternalQualificationsStr": "",
    "OrganizationDescriptionStr": "",
    "primaryLocationCoordinates": [
      {
        "Latitude": "44.98599",
        "Longitude": "-93.37778",
        "CountryCode": "US",
        "GeographyId": 300000002468504,
        "GeographyNodeId": 100000507379837
      }
    ],
    "ExternalResponsibilitiesStr": "",
    "InternalResponsibilitiesStr": "",
    "InternationalTravelRequired": null
  },
  "list_job": {
    "Id": "18411",
    "Title": "Director, Governance, Risk, & Compliance (GRC)",
    "JobType": null,
    "Distance": 1778803200000,
    "JobShift": null,
    "Language": "US",
    "WorkDays": null,
    "JobFamily": null,
    "Relevancy": 2,
    "WorkHours": null,
    "Department": null,
    "HotJobFlag": false,
    "PostedDate": "2026-05-15",
    "StudyLevel": null,
    "WorkerType": null,
    "GeographyId": 300000002468504,
    "JobFunction": "Information Technology",
    "JobSchedule": null,
    "BusinessUnit": null,
    "ContractType": null,
    "ManagerLevel": null,
    "Organization": null,
    "TrendingFlag": true,
    "workLocation": [
      {
        "Country": "US",
        "Region1": "Travis",
        "Region2": "TX",
        "Region3": null,
        "Building": null,
        "Latitude": 30.38305,
        "Longitude": -97.70534,
        "LocationId": 300025482820697,
        "PostalCode": "78758",
        "TownOrCity": "Austin",
        "AddressLine1": "2201 Donley Drive, Suite 100",
        "AddressLine2": null,
        "AddressLine3": null,
        "AddressLine4": null,
        "LocationName": "USA - Austin - TXB4"
      }
    ],
    "LegalEmployer": null,
    "MediaThumbURL": null,
    "WorkplaceType": "On-site",
    "BusinessUnitId": 300000006497427,
    "OrganizationId": 1,
    "PostingEndDate": null,
    "LegalEmployerId": 300024698389932,
    "PrimaryLocation": "Golden Valley, MN, United States",
    "WorkDurationYears": null,
    "WorkplaceTypeCode": "ORA_ON_SITE",
    "BeFirstToApplyFlag": false,
    "WorkDurationMonths": null,
    "otherWorkLocations": [
      {
        "Country": "US",
        "Region1": "Hennepin",
        "Region2": "MN",
        "Region3": null,
        "Building": null,
        "Latitude": 45.01208,
        "Longitude": -93.34133,
        "LocationId": 300000006875982,
        "PostalCode": "55422",
        "TownOrCity": "Golden Valley",
        "AddressLine1": "1985 Douglas Drive North",
        "AddressLine2": null,
        "AddressLine3": null,
        "AddressLine4": null,
        "LocationName": "USA - Golden Valley - MN10",
        "RequisitionWorkLocationId": 300026259684639
      }
    ],
    "secondaryLocations": [
      {
        "Name": "Austin, TX, United States",
        "Latitude": 30.45414,
        "Longitude": -97.78254,
        "CountryCode": "US",
        "GeographyId": 300000002485194,
        "GeographyNodeId": 100000507392040,
        "RequisitionLocationId": 300026322461354
      }
    ],
    "ShortDescriptionStr": "The Director of Governance, Risk & Compliance (GRC) is responsible for building and operating an AI-enabled, modern cybersecurity GRC program that transforms governance from a compliance-focused function into a fast, intelligent, and risk-based engine for the business. Reporting directly to the CISO, this role serves as the architect of a scalable GRC capability that modernizes how cyber risk is identified, measured, prioritized, reported, and acted upon across the enterprise and product portfolio.",
    "requisitionFlexFields": [
      {
        "Value": "Hybrid",
        "Prompt": "Workplace Model ",
        "DATATYPE": "String",
        "ContextCode": "Global Data Elements",
        "SegmentCode": "Workplace Model "
      }
    ],
    "DomesticTravelRequired": null,
    "PrimaryLocationCountry": "US",
    "ExternalQualificationsStr": null,
    "ExternalResponsibilitiesStr": null,
    "InternationalTravelRequired": null
  },
  "detail_meta": {
    "url": "https://ehtl.fa.us6.oraclecloud.com/hcmRestApi/resources/latest/recruitingCEJobRequisitionDetails?expand=all&onlyData=true&finder=ById;Id=%2218411%22,siteNumber=CX",
    "http_status": 200,
    "content_type": "application/json",
    "response_bytes": 18240
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/e72bbfcef57bfe39389f00e615f26caaa187f64a?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/e5d05530-407a-4053-a724-bbb57ff28ba3JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/1a98c44c-d165-4db2-90fd-8ebb67f4ab5eJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/e72bbfcef57bfe39389f00e615f26caaa187f64a/eventsJSON