Jobs and Careers
SL

Director, Cybersecurity Governance, Risk, and Compliance

Sleep Number Corporation
Minneapolis, United Statesfull_timeVerifiedPosted 30 Jul 2025
💰 $240,267/yr($163,800/yr$240,267/yr)

About the role

Company Overview

Sleep Number is a sleep wellness technology leader. For nearly four decades, we have placed sleep at the center of wellbeing, improving over 15 million lives with our Sleep Number smart beds. We are guided by our purpose – to improve the health and wellbeing of society through higher quality sleep. This is exemplified through our 4,000+ mission-driven team members who passionately innovate to drive value creation through our vertically integrated business model, owning the process from start to finish, including selling in our over 650 stores nationwide.

Our team members are encouraged to bring their whole selves to work, sharing their unique perspectives, backgrounds and skills with Sleep Number every day. Whether you are entering, returning or experienced in the workforce, we have a place for you. We hope you join us in creating the future through higher quality sleep.

Position Purpose

As the Director, Cybersecurity Governance, Risk, and Compliance, you are responsible for overseeing enterprise-wide cybersecurity governance, risk management, and compliance programs. This highly visible leadership role ensures alignment with industry standards, regulatory requirements, and corporate policies as well as provides subject matter expertise and strategic guidance to mitigate cybersecurity risk and foster a culture of security across the organization. The Director, Cybersecurity Governance, Risk, and Compliance manages a team with responsibilities spanning policy management, risk assessments, business continuity/disaster recovery, third-party risk, audit support, security awareness and compliance monitoring. 

Primary Responsibilities

Cybersecurity Governance and Policy Development

  • Provide strategic leadership in the development and maintenance of enterprise-wide cybersecurity policies, standards, and procedures aligned with frameworks such as NIST, ISO/IEC 27001, and CIS.
  • Oversee the enterprise policy lifecycle, ensuring alignment with business objectives and regulatory requirements; lead executive-level policy review and approval processes. 
  • Champion the integration of GRC and business resiliency governance into enterprise IT and business workflows; serve as the executive advisor on policy interpretation and enforcement. 
  • Build and maintain strategic partnerships with Legal, Internal Audit, Privacy, and senior IT/business leaders to ensure cohesive risk governance across domains. 

Risk Management and Assessments

  • Direct the organization’s cybersecurity risk management strategy, including oversight of enterprise risk assessments, business impact analyses, and drive vulnerability remediation. 
  • Maintain executive ownership of the cybersecurity risk register, ensuring visibility and accountability for risk remediation across business units. 
  • Chair cross-functional steering committees to align cybersecurity risk and business resiliency priorities with enterprise risk appetite and strategic goals. 
  • Lead the development and continuous improvement of cybersecurity risk posture and reporting to ensure integration with broader enterprise risk initiatives and technology governance (e.g. Enterprise Architecture). 

Regulatory Compliance and Audit Support

  • Ensure enterprise compliance with regulatory, contractual, and industry standards (e.g., SOX, PCI DSS), serving as the executive liaison to auditors and regulators. 
  • Oversee the organization’s audit readiness and response strategy, including evidence management, control testing, and remediation tracking. 
  • Provide executive reporting on compliance posture and audit outcomes to senior leadership. 

Third-Party Risk and Security Awareness

  • Lead the strategic direction of the third-party cybersecurity risk program, ensuring robust due diligence and continuous monitoring of vendor security practices. 
  • Collaborate with Procurement and Legal leadership to embed cybersecurity requirements into enterprise sourcing and contracting processes. 
  • Sponsor enterprise-wide security awareness and training initiatives, ensuring alignment with organizational culture and risk profile; oversee metrics and reporting on program effectiveness. 

Team Leadership and People Management

  • Lead and coach a team of cybersecurity professionals, fostering a collaborative and high-performance culture. 
  • Set team priorities, provide feedback, support career development, and conduct performance evaluations. 
  • Allocate resources and assign work to ensure coverage across program areas. 
  • Promote continuous learning and professional growth in Cybersecurity, GRC and BC/DR disciplines, cybersecurity frameworks/technologies. 
  • <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sleep Number Corporation

View company profile →