Director, Governance, Risk, Compliance & Privacy
Vail ResortsAbout the role
Our mission is to create the Experience of a Lifetime for our employees, so they can, in turn, create the Experience of a Lifetime for our guests. We own and operate the most renowned destination resorts in the world as well as regional and local ski areas outside major cities, and connect them all through one unrivaled network. We are looking for ambitious leaders, innovators and creators to join our talented team. If you’re ready to pursue your fullest potential, we want to get to know you!
Candidates for year-round positions are reviewed on a rolling basis. Applications will be accepted up to 90 days after the posting date, or until the position is filled (whichever is first).
Job Summary:
Vail Resorts is seeking a Director of Governance, Risk, Compliance & Privacy (GRC&P) to lead enterprise GRC and privacy programs across a global, highly regulated, and technology-enabled business. This role is responsible for defining strategy, driving execution, and enabling informed risk decisions that protect the company while supporting business growth and innovation.
Reporting to the Vice President of Platform Services, this leader partners closely with Technology, Legal, Audit, Finance, and Business stakeholders to ensure risk and compliance practices are scalable, pragmatic, and aligned to business objectives. This role operates at the intersection of risk, technology, and business enablement, with regular interaction with senior executives.
Job Specifications:
- Starting Wage: $155,949.76 - $189,493.34 + annual bonus + equity
- Employment Type: Year Round
- Shift Type: Full Time hours available
- Minimum Age: At least 18 years of age
- Housing Availability: No
Job Responsibilities:
Enterprise GRC & Privacy Leadership
- Own and evolve the enterprise GRC and Privacy strategy aligned to business priorities, regulatory requirements, and industry best practices.
- Establish governance frameworks that enable consistent, transparent, risk-based decision making.
- Serve as a trusted advisor to senior leaders on risk, compliance, and privacy matters.
Risk Management & Compliance
- Define and drive enterprise audit strategy, including audit readiness, evidence standardization, and control rationalization.
- Reduce audit fatigue by streamlining control frameworks across SOX, PCI, and privacy.
- Act as the primary interface with QSAs and external auditors to ensure efficient, predictable outcomes.
- Lead enterprise risk assessment, mitigation, and monitoring across technology and business domains.
- Oversee compliance programs including SOX, PCI DSS, and global privacy regulations (GDPR, CCPA).
- Partner with Legal, Internal Audit, and external auditors to ensure well-governed audits and assessments.
- Oversee or partner on third-party risk management.
Privacy & Data Governance
- Lead privacy and data governance programs including policy, operations, and regulatory response.
- Embed privacy by design into systems and business processes.
- Serve as escalation point for privacy risk and regulatory inquiries.
- Partner with Legal to operationalize global privacy regulations.
- Lead data classification, retention, and lifecycle governance.
- Support AI governance and responsible data use.
Program Management, Metrics & Reporting
- Define KPIs, dashboards, and reporting to measure program maturity.
- Provide executive-level reporting on risk posture and trends.
- Drive continuous improvement through benchmarking and lessons learned.
- Rationalize and harmonize controls across frameworks (PCI, SOX, NIST, privacy).
- Drive adoption of common control frameworks and automation.
- Leverage GRC platforms to improve monitoring, evidence collection, and reporting.
- Drive maturity toward continuous compliance.
People & Leadership
- Build and lead a high-performing GRC &
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Associate Director, Content
The Clorox Company
$309,000/yr
Director, Codes & Standards - Data Centers & Direct Current Applications
EATON
$242,000/yr
Director, Global Regulatory Affairs – Chemistry, Manufacturing and Controls (CMC), Platform Innovation – Synthetic Peptides and Oligonucleotides
Lilly
$257,400/yr