> Markdown version of [/jobs/ext/2512145-senior-director-grc](https://www.wearedevelopers.com/jobs/ext/2512145-senior-director-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Director, GRC - **Company:** Okta, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $264,000.0 - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Software as a Service, Cyber Security, Data Governance, PCI Data Security Standards, Okta, Cyber Threat Analysis, Information Technology, Data Lineage, Build Process - **Published:** August 18, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17979389?backUrl=%2Fcareer%2F17979389%2FSenior-Director-Grc-California-San-Francisco ## About the Role * Proven Executive Leadership: 10+ years of progressive leadership in Security GRC within a high-growth SaaS, cloud-first, or enterprise technology environment. * AI Governance Expertise: Demonstrated understanding of AI/ML governance challenges, including generative and agentic AI security, data lineage and global AI regulatory landscapes. * Mastery of Security Frameworks: Extensive track record managing compliance for enterprise cloud environments * Risk Quantification Skills: Deep knowledge of risk management methodologies and the ability to translate complex technical risks into operational context for executives. * Team Scale & Mentorship: Track record of recruiting, mentoring, and retaining high-performing, technical GRC engineering and risk management professionals. * Education & Certifications: Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience. ## Description We are seeking a visionarySenior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist-we build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta's workforce, taking direct responsibility for cyber risk, data governance, security compliance and product certifications to enable Okta to ship world class, secure products. You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset-pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures. This is not just a leadership role. This is a builder's role. Key Responsibilities: * Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness). * Enterprise Risk & Governance: Operationalize Okta's AI risk and governance framework-addressing training data protection, model risk management, responsible AI principles, and alignment with emerging frameworks (NIST AI RMF, ISO/IEC 42001, and the EU AI Act). * Enterprise Cyber Risk Management: Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification * Regulatory & Compliance Assurance: Maintain and expand Okta's global compliance posture across major security and privacy frameworks, including SOC 1/2/3, ISO 27001/ENS High/MS DPR/PCI-DSS/CSA STAR/HDS * Policy & Governance Lifecycle: Ensure our corporate information security policies and control standards to reflect evolving business priorities and emerging threats. * Third-Party & SaaS Risk Governance: Direct high-impact vendor risk assessment programs, ensuring third-party SaaS tools and supply chain risks meet Okta's stringent security controls program. * Audit Management & Remediation: Serve as the primary executive lead for internal/external audits, customer assurances, and regulatory reviews. Drive rapid, engineering-led remediation of audit findings and control gaps. * Cross-Functional Partnership: Collaborate closely with Product Management, Legal, Privacy, Infrastructure, and Business Technology teams to align compliance requirements with product roadmaps and commercial objectives. ## Related Videos - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Fireside Chat: Deep Learning, Deep Impact: Harnessing AI for Language Innovation](https://www.wearedevelopers.com/videos/612-fireside-chat-deep-learning-deep-impact-harnessing-ai-for-language-innovation) - [Enjoying SQL data pipelines with dbt](https://www.wearedevelopers.com/videos/823-enjoying-sql-data-pipelines-with-dbt) - [Exploring 5 Key Applications of AI Abundance with Blockchain Assurance](https://www.wearedevelopers.com/videos/971-exploring-5-key-applications-of-ai-abundance-with-blockchain-assurance) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [A Data Mesh needs Open Metadata](https://www.wearedevelopers.com/videos/505-a-data-mesh-needs-open-metadata) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 150 - The shift to AI generated code, fingerprinting and OKRs vs. doing your job](https://www.wearedevelopers.com/magazine/533-dev-digest-150-the-shift-to-ai-generated-code-fingerprinting-and-okrs-vs-doing-your-job) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)