globalrelay

Director, Security Governance Risk & Compliance

Apply Now

At a Glance

Location
Vancouver, British Columbia, Canada
Experience
15+ years
Posted
2026-07-08T13:48:24-04:00

Key Requirements

Certifications

  • CISA
  • CISM
  • CISSP
  • ISO

Domain Knowledge

  • Cybersecurity
  • Education
  • Healthcare
  • Regulatory

Requirements

10-15+ years of experience in cybersecurity, governance, risk management, audit, compliance or related disciplines.

5+ years of leadership experience managing teams and security programs.

Strong understanding of governance, risk management, assurance and compliance principles.

Experience leading audits, certifications and regulatory assessments.

Deep knowledge of frameworks such as ISO 27001, SOC 2, NIST, FedRAMP and CIS Controls.

Knowledge of emerging technology governance concepts, evolving regulatory requirements and industry frameworks, including ISO/IEC 42001.

Responsibilities

As Director, Governance Risk & Compliance, you are responsible for defining and leading Global Relay’s Governance, Risk & Compliance function.

Reporting to the Chief Information Security Officer, you establish the frameworks, governance structures and operating model that enable consistent security decision-making, transparent risk management and trusted assurance across the organization.

You provide strategic leadership for security governance, risk management, assurance, cybersecurity compliance, third-party risk management and security awareness programs.

Working closely with executive leadership, business stakeholders and technology teams, you translate complex security and technology risks into business context, influence strategic priorities and ensure the organization maintains a strong and resilient security posture while meeting regulatory, contractual and organizational requirements.

You ensure emerging technologies, including AI, are governed in a manner that aligns with organizational objectives, risk appetite and regulatory obligations.

Define and maintain the enterprise security governance framework, including policies, standards, control frameworks and governance processes.