bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesPolymarketDirector, GRC & Privacy Security

Director, GRC & Privacy Security

Polymarket · New York · Hybrid · Active · Ashby

Job facts

FieldValue
CompanyPolymarket
TitleDirector, GRC & Privacy Security
Normalized title-
Department / teamIT / IT
LocationNew York, NY, United States
Work modelHybrid / Hybrid
Employment typeFull Time
Salary-
Statusactive
ATS providerAshby
Posted / first seen / 2026-06-19
Changed / last seen2026-06-19 / 2026-06-19

Related slices

PageWhat it containsOpen
Company jobsActive postings from Polymarket.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in New York.Open
Department jobsActive postings in IT.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyPolymarket
Source7a8d1574-33af-4eda-9901-0815659078ab
ATS providerAshby

Description

About Polymarket Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future. We're growing fast — both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire. About the Role Polymarket is hiring a Director of GRC & Privacy to build and lead the governance, risk, and compliance function within our security organization. As a high-growth fintech operating across multiple jurisdictions with several subsidiary entities, we carry compliance obligations spanning PCI-DSS, SOC 2 Type II, data privacy regulations, and financial services requirements — and this role will establish the GRC program from scratch. This is a senior, high-visibility role reporting directly to the CISO. You'll hire and develop a team of three and serve as the primary interface between security, legal, finance, and external auditors and regulators. It requires equal fluency in regulatory requirements, risk management frameworks, and executive communication. What You'll Do Build and own the enterprise security risk management program — risk register, risk appetite framework, risk scoring methodology, and regular reporting to the CISO and executive leadership Establish and maintain the security control framework, mapping controls to applicable standards (SOC 2 TSCs, PCI-DSS, CIS Controls) across all entities and subsidiaries Drive security policy development and lifecycle management — authoring, reviewing, approving, and enforcing policies across the organization Lead the company's security committee and governance forums, ensuring risk decisions are documented, escalated appropriately, and tracked to resolution Own the end-to-end compliance program for SOC 2 Type II and PCI-DSS — scoping, control design, evidence collection, auditor management, and remediation tracking Build continuous audit readiness rather than a point-in-time posture; automate compliance evidence collection where possible Manage relationships with external auditors, certification bodies, and regulators; serve as the primary point of contact for audit engagements across all entities Own the third-party risk management program — vendor security assessments, contractual security requirements, ongoing monitoring, and escalation of high-risk findings Oversee the data privacy program in partnership with Legal, ensuring compliance with GDPR, CCPA, and applicable regulations across all jurisdictions where the company operates Ensure privacy-by-design is embedded in the product development process and that data processing activities are documented, lawful, and consistent with stated privacy notices Manage data subject rights obligations and privacy incident response, including breach notification requirements under applicable law What We're Looking For 8+ years of experience in GRC, information security compliance, or a related field, with 3+ years in a management or program leadership role Deep, hands-on experience with SOC 2 Type II — you have managed or led multiple audit cycles and understand the TSCs, evidence requirements, and auditor dynamics from the inside Strong working knowledge of PCI-DSS v4.0 and experience implementing or managing PCI compliance programs Demonstrated experience managing compliance across multiple legal entities or subsidiaries with overlapping and distinct regulatory obligations Experience building or significantly maturing a GRC program — not just maintaining one someone else built Working knowledge of GDPR and CCPA and the operational requirements they impose on a data-handling business Ability to communicate risk and compliance requirements clearly to technical teams, business stakeholders, and executive leadership Experience managing external auditor relationships and serving as the primary organizational point of contact during audit engagements (Plus) Experience in fintech, payments, cryptocurrency, or financial services — familiarity with money transmitter licensing or FinCEN obligations is a meaningful plus (Plus) Professional certifications: CISM, CRISC, CISSP, CIPP/E, CIPP/US, or equivalent (Plus) Exposure to ISO 27001, CIS, or NIST CSF as additional compliance frameworks (Plus) Experience with GRC platforms (Vanta, Drata, Tugboat Logic, ServiceNow GRC, or equivalent) (Plus) Familiarity with AWS cloud environments and how cloud-native architectures affect control design and evidence collection (Plus) Prior experience standing up a GRC function in a high-growth, previously unstructured environment Benefits Competitive salary & equity Unlimited PTO Full Health, Vision, & Dental coverage 401k match Hardware setup: new MacBook Pro, big display, & accessories

Full job record

Job IDf91370ea73c0c10d3be7c354bbab74eea2ad0f0b
Org ID61d1aa87-3b1a-4da1-becf-ee92895b4f32
Source ID7a8d1574-33af-4eda-9901-0815659078ab
Board ID7a8d1574-33af-4eda-9901-0815659078ab
Providerashby
Provider Job Keybb603b5e-15bf-4f64-a122-e1c21461cb37
TitleDirector, GRC & Privacy Security
Normalized Title
Statusactive
Activeyes
Location TextNew York
DepartmentIT
TeamIT
Employment Typefull_time
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionNY
CityNew York
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/polymarket/bb603b5e-15bf-4f64-a122-e1c21461cb37
Apply URLhttps://jobs.ashbyhq.com/polymarket/bb603b5e-15bf-4f64-a122-e1c21461cb37/application
First Seen At2026-06-19 09:26:46Z
Last Seen At2026-06-19 09:26:46Z
Last Checked At2026-06-19 09:26:46Z
Last Changed At2026-06-19 09:26:46Z
Inactive At
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=polymarket/date=2026-06-19/2026-06-19T09-26-13-496Z-9410de4c7166f8af190366184c55cd22e86afbd048148405afe13cd041e32fba.json
Event Fields
{
  "content_hash": "b1f3317352709c7a7bbbf2a8f1ae50eb2fe10d08a38e9d8cfa97daac0f053508",
  "source_hash": "7835946287565e70257877663bdcaa4424541ac45554ff5e30fb8d232cd6d2bc",
  "last_changed_at": "2026-06-19T09:26:46.079Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "New York",
    "city": "New York",
    "region": "NY",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.75
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-19T09:26:46.011Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "New York",
      "city": "New York",
      "region": "NY",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.75
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "bb603b5e-15bf-4f64-a122-e1c21461cb37",
  "team": "IT ",
  "title": "Director, GRC & Privacy Security",
  "jobUrl": "https://jobs.ashbyhq.com/polymarket/bb603b5e-15bf-4f64-a122-e1c21461cb37",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/polymarket/bb603b5e-15bf-4f64-a122-e1c21461cb37/application",
  "isListed": true,
  "isRemote": false,
  "location": "New York",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "IT ",
  "publishedAt": null,
  "workplaceType": "Hybrid",
  "employmentType": "FullTime",
  "secondaryLocations": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/f91370ea73c0c10d3be7c354bbab74eea2ad0f0b?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/61d1aa87-3b1a-4da1-becf-ee92895b4f32JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/7a8d1574-33af-4eda-9901-0815659078abJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/f91370ea73c0c10d3be7c354bbab74eea2ad0f0b/eventsJSON