Director, Governance Risk & Compliance
Justworks, Inc.About the role
Who We Are
At Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people.
We’re helping businesses get off the ground by enabling them to focus on running their business. We solve HR issues. We’re data-driven and never stop iterating. If you’d like to work in a supportive, entrepreneurial environment, are interested in building something meaningful and having fun while doing it, we’d love to hear from you.
We're united by shared goals and shared motivations at Justworks. These are best summed up in our company values, which are reflected in our product and in our team.
If this sounds like you, you’ll fit right in.
Who You Are
Justworks’ Digital Security team is responsible for the security of Justworks products, platforms, services, and corporate operations. Led by the Chief Information Security Officer, Digital Security’s vision is to become the partner and enabler for business and engineering by working collaboratively with others to embed security in business hygiene and engineering DNA to strengthen our cyber resilience. We are very excited to search for an experienced and motivated security leader to join the team to lead and manage the Security Governance, Risk, and Compliance (GRC) function.
This Director of GRC role will provide expert leadership in all matters pertaining to governance, risk management, and compliance, ensuring security programs are successfully executed to protect Justworks customers and strengthen cyber resilience for Justworks. This role will be responsible for providing a risk management framework and process, governance oversight, and ensuring compliance with regulations and our internal policies/standards. This Director will report to the VP, Chief Information Security Officer (CISO).
Your Success Profile
What You Will Work On
- Work with the Chief Information Security Officer (CISO) to lead and manage enterprise-wide security governance and risk management program, and ensure Digital Security practices align with business objectives, digital security vision, and evolving threat landscape challenges.
- Design and drive the digital security and integrated risk management strategy, framework, tools, and processes.
- Responsible for strategizing, managing, resource planning and hiring, measuring (SLAs, OKRs), partner development, and other aspects of running GRC as a service.
- Introduce the necessary GRC tools or platforms to define, simplify, and automate the risk management processes, and enhance other processes with Digital Security. .
- Oversee, maintain, and track Justwork’s Security Risk Registry as part of the risk management process. Leverage AI to improve the efficiency and effectiveness of the process.
- Work with procurement, legal, IT and other stakeholders closely on the TPRM (3rd-party risk management) program to effectively manage vendor risks. Responsible for the initial and continuous vendor risk assessment as well as 3rd party risk tracking and remediation.
- Continue to enhance Justworks’ security policies and standards based on Justworks agile development, zero-trust environment, and emerging threat landscapes.
- Enhance the Security Compliance Program to ensure regulatory compliance, especially with business growth and scope changes, and to mature the program in the future to measure internal compliance against our new policies and standards.
- Build a cross-functional security governance model and effectively run various governance committees to ensure stakeholders align on the risk acceptance level, and priorities to manage risks.
- Continue to enhance and mature the security awareness and training program effectively.
- Work with the CISO to define security metrics and develop GRC dashboard. Continuously and routinely measure and report the effectiveness of the security programs, overall security resilience risk posture improvement, and maturity growth.
- Work closely with internal Audit and entities to support Enterprise Risk Management.
How You Will Do Your Work
As a Director, Governance, Risk & Compliance, how results are achieved is paramount for your success and ultimately result in our success as an organization. In this role, your foundational knowledge, skills, abilities and personal attributes are anchored in the following:
- Clear communication - The ability to articulate thoughts and express ideas effectiv
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s