Sr Director, IT Governance, Risk & Compliance, North America
RentokilAbout the role
Benefits Start Day 1 for Full-Time Colleagues - No Waiting Period!
For more information about our benefits, see below!
We are proud to be a member of the Rentokil family of companies, the global leader in Pest Control and other services across more than 90 countries. We pride ourselves on being a trusted partner to many of the world's leading brands and serve consumer and business customers across multiple industries. We are extremely proud of our legacy of excellence and constantly work to fulfill our mission to "protect people, enhance lives, and preserve the planet."
Overview
The Head of GRC (Governance, Risk & Compliance) for North America is responsible for the strategic execution of regulatory compliance and risk management frameworks. Reporting directly to the NA CIO, this leader owns the regional risk posture and ensures that North American operations are fully aligned with global standards while meeting stringent local mandates. This role is the primary custodian of IT General Controls, SOX, and PCI-DSS governance, ensuring the business remains audit-ready and resilient against emerging threats.
Duties & Responsibilities
Core Governance & Strategic Oversight
Master Risk Accountability: Own and manage the central North American repository for all IT Audit, Risk, and Compliance actions. Drive the end-to-end accountability loop to ensure findings are not just identified, but remediated on schedule.
Best-in-Class ITGC Program: Lead the development, execution, and continuous maturation of a "best-in-class" IT General Controls (ITGC) program, ensuring proactive mitigation of financial, operational, and cyber risks.
Global Standard Influence: Actively shape best practices and standards by ensuring North America’s unique regulatory and operational perspectives are integral to the Group strategic direction.
Audit Interface Leadership: Serve as the primary, authoritative interface for all third-party auditors, Group Internal Audit, and regulatory bodies (PCI, SOX). Ensure a globally consistent audit approach and maintain absolute transparency in reporting.
Enterprise Risk Integration: Direct the identification, assessment, and prioritization of IT and Cyber risks, ensuring they are quantified and seamlessly integrated into the broader North American Enterprise Risk Management (ERM) framework.
Regulatory & Compliance Ownership
PCI-DSS & SOX Custodian: Own end-to-end regional compliance for PCI-DSS (Payment Card Industry) and SOX (Sarbanes-Oxley). Ensure all financial and payment systems meet strict audit requirements without exception.
Policy Enforcement: Localize and execute the global cyber security roadmap. Establish regional policies that bridge the gap between global requirements and local North American legal/mandated requirements.
Security Service Transition: Own the security "gatekeeping" process for new technology. Ensure that any new business tool or system undergoes rigorous security testing and risk assessment before entering the production environment.
Cyber Security Operations & Resilience
Incident Leadership: Serve as the lead coordinator for security incident response (IR). Own the communication bridge between technical containment teams and executive leadership (Legal, Finance, HR).
Executive Resilience Testing: Plan and execute regular tabletop activities and simulations for Executive Leadership Team (ELT) members to test and mature incident response capabilities.
Cross-Functional Posture Improvement: Coordinate proactively with technology and business teams to improve the overall security posture and drive measurable risk reduction across the North American region.
Field Education & Awareness: Drive a targeted field education strategy to build awareness and understanding of current risks and vulnerabilities among all relevant operational teams.
Threat & Vulnerability Oversight: Manage the regional vulnerability management program. Use the "Master Risk Register" to force-rank and drive the patching of critical infrastructure.
Security Culture & Awareness: Design and lead regional security training programs to foster a "security-first" culture, moving beyond compliance check-boxes to behavioral change.
Third-Party Risk Management: Oversee the security evaluation of all regional third-party vendors and partners to mitigate supply chain risks.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s