Senior Director, GRC
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a visionarySenior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We don’t view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist-we build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta’s workforce, taking direct responsibility for cyber risk, data governance, security compliance and product certifications to enable Okta to ship world class, secure products.
You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset-pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures.
This is not just a leadership role. This is a builder’s role. Key Responsibilities:
- Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness).
- Enterprise Risk & Governance: Operationalize Okta’s AI risk and governance framework-addressing training data protection, model risk management, responsible AI principles, and alignment with emerging frameworks (NIST AI RMF, ISO/IEC 42001, and the EU AI Act).
- Enterprise Cyber Risk Management: Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification
- Regulatory & Compliance Assurance: Maintain and expand Okta’s global compliance posture across major security and privacy frameworks, including SOC 1/2/3, ISO 27001/ENS High/MS DPR/PCI-DSS/CSA STAR/HDS
- Policy & Governance Lifecycle: Ensure our corporate information security policies and control standards to reflect evolving business priorities and emerging threats.
- Third-Party & SaaS Risk Governance: Direct high-impact vendor risk assessment programs, ensuring third-party SaaS tools and supply chain risks meet Okta’s stringent security controls program.
- Audit Management & Remediation: Serve as the primary executive lead for internal/external audits, customer assurances, and regulatory reviews. Drive rapid, engineering-led remediation of audit findings and control gaps.
- Cross-Functional Partnership: Collaborate closely with Product Management, Legal, Privacy, Infrastructure, and Business Technology teams to align compliance requirements with product roadmaps and commercial objectives.
Requirements
- Proven Executive Leadership: 10+ years of progressive leadership in Security GRC within a high-growth SaaS, cloud-first, or enterprise technology environment.
- AI Governance Expertise: Demonstrated understanding of AI/ML governance challenges, including generative and agentic AI security, data lineage and global AI regulatory landscapes.
- Mastery of Security Frameworks: Extensive track record managing compliance for enterprise cloud environments
- Risk Quantification Skills: Deep knowledge of risk management methodologies and the ability to translate complex technical risks into operational context for executives.
- Team Scale & Mentorship: Track record of recruiting, mentoring, and retaining high-performing, technical GRC engineering and risk management professionals.
- Education & Certifications: Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent experience.
Benefits & conditions
Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us. The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $236,000 - $325,000 USD
The Okta Experience
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding pleaseuse this Form to request an accommodation.
About the company
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 150 - The shift to AI generated code, fingerprinting and OKRs vs. doing your job
Stephan Gillich - Bringing AI Everywhere
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship