Vice President of Cyber Governance, Risk & Compliance
Role details
Job location
Tech stack
Job description
We are seeking a seasoned Vice President of Cyber Governance, Risk & Compliance to lead the strategy, execution, and continuous maturation of our cybersecurity governance, risk, and compliance program. Reporting to the Chief Information Security Officer, this leader will oversee the frameworks, processes, and teams responsible for cyber risk governance, regulatory readiness, policy management, control assurance, and third-party cyber risk oversight.
This executive will serve as a key strategic partner to the CISO and senior leadership team, translating complex cyber and technology risks into actionable business insights while ensuring the organization maintains a strong control environment appropriate for a highly regulated financial services institution.
The ideal candidate brings extensive experience building and scaling cyber GRC programs within complex, regulated environments and has demonstrated success leading teams through program transformation and maturity uplift.
Role Responsibilities:
- Lead the cyber GRC function and define strategic roadmap, operating model, and maturity targets.
- Maintain governance structures supporting cyber risk decision-making, escalation, and executive oversight.
- Drive cyber risk appetite, exception management, and risk acceptance processes.
- Oversee cyber and technology risk assessment methodologies and execution.
- Develop and maintain executive and Board-level cyber risk reporting and metrics.
- Lead preparation and coordination for regulatory exams, internal/external audits, and customer assessments related to cybersecurity.
- Oversee control framework management, evidence programs, and issue remediation governance.
- Own lifecycle management of security policies, standards, and governance documentation.
- Oversee cyber due diligence and ongoing risk monitoring for third-party vendors, partners, and strategic providers.
- Build, mentor, and scale a high-performing GRC team., * Assess and baseline current cyber GRC maturity.
- Deliver a prioritized GRC uplift roadmap.
- Improve executive and Board cyber risk transparency.
- Strengthen regulatory and audit readiness.
- Mature policy, exception, and issue management processes.
- Enhance first-line ownership of cyber and technology risk., Own and evolve Sonar's AI-native internal platform: design, build, and operationalize agent/connector integrations (Claude/MCP, Rovo), administer and productize Jira Service Management and Atlassian Cloud, implement scalable automations and integrations, maintain CMDB/assets, enforce ITSM/ITIL processes, support security/compliance audits, and partner across teams to drive platform roadmap and stakeholder enablement. Top Skills: AnthropicAtlassian AutomationAtlassian CloudBamboohrBitbucketClaudeConfluenceEnterprise Apps ConnectorsGroovyGuardJavaScriptJira Service ManagementJira SoftwareJsm AssetsJSONJumpcloudLoomMcpNetSuiteOktaPythonRest ApisRovoSalesforceServicenow CmdbSlackTrelloWebhooksZoom CrowdStrike, The VP of Agentic Systems will lead data science research and development, focusing on AI systems to enhance cybersecurity operations, requiring strong leadership and collaboration across technical teams. Top Skills: Artificial IntelligenceBig DataCybersecurityMachine Learning Ericsson
MS Delivery Manager
An Hour Ago In-Office Expert/Leader Expert/Leader Cloud * Information Technology * Internet of Things * Machine Learning * Software * Cybersecurity * Infrastructure as a Service (IaaS) Lead end-to-end service delivery for hyperscale data center projects across the Americas, managing optical fiber installs, rack-and-stack, decommissioning, and build activities. Ensure SLA and budget compliance, drive operational performance and automation, present executive-level insights, resolve escalations, manage KPIs and risks, and lead matrixed teams to improve customer experience and scalability. Top Skills: AIAutomationData Center BuildExcelMicrosoft PowerpointOptical Fiber InstallationPower BIRack-And-Stack
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
Requirements
- Bachelor's degree required; advanced degree preferred.
- 15+ years of experience in cybersecurity, technology risk, audit, compliance, or governance roles.
- 7+ years of people leadership experience with increasing organizational scope.
- Proven experience building, transforming, or materially uplifting cyber GRC programs in financial services or similarly regulated industries.
- Deep knowledge of cybersecurity governance, financial services regulatory expectations, security/control frameworks, audit/regulatory exams, and third-party cyber risk programs.
- Possesses at least one of the following professional credentials (or other industry-related credential): CISSP, CRISC, CISM or CISA
Benefits & conditions
Be an Early Applicant Hybrid Denver, CO, USA 240K-260K Annually Expert/Leader Hybrid Denver, CO, USA 240K-260K Annually Expert/Leader Lead and mature the cyber Governance, Risk & Compliance program: set strategy and operating model, manage governance and risk appetite, oversee assessments, controls, policy lifecycle, regulatory exam and audit readiness, third-party cyber risk, and build a high-performing GRC team to improve board-level visibility and control assurance. The summary above was generated by AI, You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific to your country. If applicable, additional role-specific benefits will be mentioned during your interview process or in an offer of employment.
Your United States specific benefits include:
- Parental Leave
- Family First Programs
- Medical, Dental, and Life Insurance
- Tuition Repayment Assistance Program
For residents of Colorado, California, Connecticut, Delaware, Minnesota, and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information., The base salary range is $240,000 - $260,000 USD per year, total on target compensation includes a base salary plus a variable target incentive that aligns with individual and company performance.