> Markdown version of [/jobs/ext/2632099-vp-governance-risk-and-compliance](https://www.wearedevelopers.com/jobs/ext/2632099-vp-governance-risk-and-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # VP, Governance Risk and Compliance - **Company:** Transunion's Internal - **Location:** Reston, VA, United States - **Experience:** Expert - **Salary:** $193,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Information Systems, Data Security, Decision Support Systems, Information Systems Security Architecture Professional, PCI Data Security Standards, Information Technology, RSA Archer Platform - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/aec7c608-33d0-47f6-a3b1-08df7f2dc2c7 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Business, Risk Management, or a related field, or equivalent experience and knowledge relevant to leading enterprise cybersecurity governance and compliance . * 10+ years of experience in cybersecurity, risk, compliance, governance, or audit leadership roles, with deep knowledge of governance frameworks, regulatory requirements, and control standards . * 7+ years of experience leading global teams and large-scale cybersecurity programs across complex organizations . * Experience presenting cybersecurity risk, compliance, and assurance matters to executive leadership, regulators, and board-level committees . * Proven ability to influence senior stakeholders, build cross-functional partnerships, and drive enterprise-wide change initiatives . Required Technical Skills * Working knowledge of PCI DSS (Payment Card Industry Data Security Standard), SOX (Sarbanes-Oxley Act), NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), and ISO/IEC 27001 . * Experience with cyber GRC (Governance, Risk, and Compliance) platforms used to manage controls, assessments, issues, policies, and compliance obligations . * Ability to develop and interpret key risk indicators, control-effectiveness metrics, executive dashboards, and regulatory or Audit Committee reporting . * Knowledge of automation and AI-enabled governance processes that improve oversight, evidence collection, reporting, and control assurance . We're also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we're happy to support your career development and growth in: * Financial services or other highly regulated industry experience . * Experience leading cybersecurity compliance programs across multiple regulatory environments and geographies . * Experience implementing modern GRC platforms and AI-enabled governance processes . * Relevant certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), PCI ISA/QSA, or ISO 27001 Lead Auditor . ## Description The Governance & Compliance team is responsible for defining and executing TransUnion's global cybersecurity governance, compliance, audit, and control assurance strategy, ensuring alignment with business objectives, regulatory requirements, and the company's risk appetite. The team provides oversight of cybersecurity policies, regulatory compliance programs, audit management, control effectiveness, and enterprise cyber risk reporting while partnering across Technology, Product, Legal, Privacy, Risk, and Internal Audit functions. This role reports to the Senior Vice President, Governance, Risk & Compliance and plays a key leadership role in advancing a modern, scalable, and data-driven cybersecurity governance program. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week. Role Overview and Core Responsibilities * Define and execute the enterprise cybersecurity governance and compliance strategy, including policies, standards, control frameworks, and operating processes that align with business priorities and risk appetite . * Establish governance processes and metrics that give executive leadership, regulators, and the Audit Committee clear visibility into cyber risk, control effectiveness, compliance posture, audit results, and emerging risks . * Oversee global cybersecurity compliance programs and readiness for regulatory examinations, external assessments, contractual obligations, and requirements including PCI DSS, SOX, NIST CSF, ISO 27001, privacy regulations, and customer security expectations . * Serve as executive sponsor for cybersecurity audits, assessments, and examinations; partner with Internal Audit and business stakeholders to strengthen assurance and drive timely remediation of findings and control deficiencies . * Lead enterprise cyber risk and control assessments, identify gaps, prioritize remediation, and establish accountability mechanisms that support risk reduction and issue closure . * Translate technical security issues into business-focused risk discussions and ensure material cybersecurity risks are appropriately communicated and escalated . * Modernize cyber governance, risk, and compliance capabilities through automation, modern GRC platforms, and AI-enabled processes that improve scale, consistency, and decision support . * Lead and develop a global team responsible for governance, compliance, policy, audit coordination, and control assurance, fostering accountability, transparency, innovation, and operational excellence . * Build strong partnerships across Technology, Product, Legal, Privacy, Risk, Internal Audit, and business functions to address evolving regulatory requirements and enable enterprise-wide change . ## Related Videos - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)