Senior Director, Cybersecurity Governance, Risk, and Compliance
CFA InstituteAbout the role
CFA Institute is seeking a strategic, hands-on cybersecurity leader to build and mature our global GRC program—aligning risk reduction with business priorities, guiding enterprise policy and standards, and ensuring compliance across a complex regulatory landscape. If you love rolling up your sleeves to solve real-world governance, risk, and compliance challenges while advising executives and the board, this role is for you.
Please note: CFA Institute does not provide work authorization or visa sponsorship (including student or temporary worker visas) for this position.
What You’ll Do
Own the cyber GRC framework: Establish and continuously improve the organization’s IT and cybersecurity governance model to drive measurable risk reduction aligned with business objectives.
Set policy & standards: Develop, implement, and enforce global IT and cybersecurity policies, standards, and procedures that meet international and regional regulations.
Advise leadership: Lead the cybersecurity committee/working group; provide regular, executive-ready updates to senior leadership and the board on risk posture and program performance.
Run enterprise risk management for cyber/IT: Build and execute comprehensive risk assessment processes, identify vulnerabilities, prioritize mitigations, and track remediation to closure.
Manage third-party risk: Partner with IT, operations, and business units to assess and monitor vendor and partner risks across the lifecycle.
Measure what matters: Define KRIs and metrics to monitor risk levels and drive decisions, reporting trends and insights to stakeholders.
Lead compliance programs: Ensure and maintain compliance with global regulations (e.g., GDPR, CCPA) and frameworks (e.g., NIST, ISO 27001); lead internal/external audits and close findings.
Sustain certifications: Maintain and improve certifications and attestations (e.g., SOC 2, HIPAA, PCI DSS), coordinating with legal and privacy teams.
Build capability & culture: Lead and mentor a high-performing team; develop training and awareness to strengthen a security-first mindset across the organization.
What You’ll Bring
Minimum Qualifications
Bachelor’s degree in cybersecurity, computer science, information systems, or related field.
10+ years in cybersecurity with significant GRC leadership experience.
Deep knowledge of global frameworks and regulations (e.g., ISO 27001, NIST CSF, GDPR, CCPA).
Proven track record conducting risk assessments, leading audits, and sustaining compliance certifications (e.g., SOC 2, HIPAA, PCI DSS).
Strong leadership and program/project management skills with the ability to manage multiple priorities in a dynamic, global environment.
Excellent communication and stakeholder management skills, including presenting to senior leadership and boards.
Preferred Qualifications
Advanced degree in a relevant field.
Security certifications such as CISSP, CISM, and/or CRISC.
Experience establishing KRIs/metrics and executive dashboards for ongoing risk monitoring.
Demonstrated success leading third-party risk programs and cross-functional, global initiatives.
Experience designing and delivering enterprise security awareness and training.
Why Join Us?
Lead at scale: You’ll architect and drive a mission-critical GRC program with meaningful visibility at the executive and board levels.
Collaborate globally: Partner with privacy, legal, IT, and business teams to embed security into enterprise processes and strategic initiatives.
Flex your craft: A hands-on environment where your expertise directly improves resilience and reduces risk.
Work flexibly: Role is eligible for flexible working arrangements within approved U.S. jurisdictions.
At CFA Institute, we are committed to transparency and equity in our hiring process. In compliance with wage transparency laws in many of the jurisdictions in which we recruit, we provide the following information regarding compensation for this position:
Expected salary range: $190,000 - $230,000
Other benefits include eligibility for annual incentives, 12% retirement employer contribution, and competitive medical benefits.
All salary ranges are subject to adjustment based on experience, education, and other factors relevant to the position. CFA Institute is an equal opportunity employer and encourages applications from a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s