SVP, Cyber Governance, Risk and Compliance
TransUnionAbout the role
TransUnion's Job Applicant Privacy Notice
Personal Information We Collect
Team Overview
We are seeking a highly experienced and visionary Senior Vice President (SVP) of Cyber Governance, Risk, and Compliance (GRC) to lead our global GRC function. The SVP will be a critical member of the Office of the CISO and will be responsible for defining and executing our cybersecurity strategy, ensuring our organization operates within a robust and compliant security framework. This leader will drive a culture of security awareness and accountability across the enterprise, managing risk effectively to protect our assets and maintain stakeholder trust. This is a remote position which may require occasional in-person attendance at work-related events at the discretion of management.Role Overview and Core Responsibilities
Experience:
Minimum of 15 years of progressive experience in cybersecurity, with at least 7-10 years in a senior leadership role focused on GRC.
Intimate knowledge of SoX, SoC2, ISO27K, NYDFS regulation and relevant international equivalents are required
Proven experience in a complex, global organization, preferably within a highly regulated industry (e.g., financial services, healthcare, technology)
Demonstrated track record of successfully building and leading enterprise-wide GRC programs
Prior Board exposure in public companies
Education:
Bachelor's degree in Information Systems, Computer Science, or a related field is preferred.
Certifications:
ISACA, CISA, CISSP, CISM, or CRISC certifications are a plus.
Required Knowledge and Experiences
Develop and execute a comprehensive, long-term GRC strategy aligned with business objectives and regulatory requirements.
Present regularly to the Board and executive team on cyber risk posture and program effectiveness.
Oversee the design, implementation, and operation of our cybersecurity governance framework, policies, and standards (e.g., NIST, ISO 27001, CIS).
Manage and mature our cyber security policy lifecycle, including development, communication, and enforcement.
Lead the enterprise-wide cyber risk management program, including risk identification, assessment, mitigation, and reporting.
Lead an international group of senior security and business risk liaisons to disseminate and enforce regional and corporate compliance, offer central security services such as advisory and technology
Ensure the company's adherence to all relevant national and international cyber security regulations and compliance standards (e.g. SOX, PCI-DSS, NYDFS, etc.).
Act as the primary point of contact for external and internal audits related to cyber security, overseeing the remediation of any findings.
Build, mentor, and lead a high-performing team of GRC professionals.
Build strong relationships with internal and external partners, including legal, HR, IT, and business leaders, as well as regulators and industry peers.
10-20% travel and involves regular performance of job responsibilities virtuall
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s