Director of Security Governance, Risk, and Compliance
AvidXchangeAbout the role
Job Overview:
The candidate should have a strong information security background, understand GRC principles, and translate regulatory requirements into policies, controls, and procedures. They will enhance the organization's security posture, ensure regulatory compliance, and promote security risk awareness. Reporting to the Sr. Director SEARCH, this role is vital in reducing enterprise risk.
What you'll do:
- Develop and implement an Information Security GRC strategy that aligns with business objectives and risk tolerance, including a 5-year road-map based on company policies, security frameworks, and regulatory requirements.
- Lead the creation and upkeep of security policies, standards, and procedures to comply with regulations and industry standards (e.g., SOX, GDPR, HIPAA, PCI 4.0, ISO 27001, NYDFS, NACHA).
- Implement continuous monitoring processes for security controls and metrics to improve the security program.
- Oversee regular risk assessments and security audits to identify vulnerabilities and enhance the organization's security posture.
- Enhance user awareness and behavior management by implementing robust training programs and policies. Deploy and manage a Security Culture Framework to reduce human error and risk.
- Lead and guide a team of Security GRC professionals, fostering a culture of continuous improvement and innovation.
- Oversee the implementation and management of Security GRC tools and platforms to streamline processes and enhance visibility into the organization's risk and compliance status.
- Increase efficiency by leveraging technologies such as AI and machine learning to automate routine tasks, improve accuracy, and provide more timely insights.
- Develop and implement data classification policies, controls, and best practices, and maintain data classification platforms.
- Collaborate with cross-functional teams to ensure Security GRC practices are integrated across all business units, including IT operations.
- Prepare and present quarterly reports to the executive team and board of directors on the organization's GRC posture and initiatives, including quantitative and qualitative metrics demonstrating the effectiveness of security investments.
- Develop and maintain relationships with key stakeholders, including executive leadership, to communicate Security GRC initiatives, risks, and compliance status.
- Stay informed about emerging regulations, industry standards, and best practices in security GRC, and incorporate them into the organization's strategy.
- Manage third-party risk by overseeing vendor assessments and ensuring compliance with security requirements.
- Strategic thinking and planning
- Risk management and analytical skills
- Leadership and team management
- Stakeholder engagement and communication
- Project management and organizational skills
- Adaptability and continuous learning
- Attention to detail and commitment to quality
What we're looking for:
- Bachelor's in Information Security, Computer Science, Business Administration, or related field; Master's preferred or 5-10 years of focused information security experience with at least 5 years in GRC leadership.
- In-depth knowledge of security frameworks (NIST, ISO 27001, NYDFS, PCI, SOC2 Type 2).
- Strong understanding of risk management and compliance processes.
- Excellent communication and presentation skills for technical and non-technical audiences.
- Proven success in implementing and managing GRC programs.
- Relevant certifications (CISM, CRISC, CGEIT, CISSP) highly desirable.
About AvidXchange
AvidXchange is a leading provider of accounts payable (“AP”) automation software and payment solutions for middle-market businesses and their suppliers. By trade, we are a technology company, but if you ask anyone who works here, they’ll tell you our people are at the core of who we are. We focus on creating a culture of Diversity, Inclusion & Belonging, and are proud to be a safe place where teammates can bring their whole selves to work. At AvidXchange, mindset is everything. We are Connected as People, Growth Minded, and Customer Obsessed. The
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s