Jobs and Careers
AC

Director, Governance, Risk & Compliance

Accommodations Plus International
United Statesfull_timeVerifiedPosted 11 Jun 2026
💰 $190,000/yr($160,000/yr$190,000/yr)

About the role

Who We Are


Accommodations Plus International (API) is a technology and services company focused on driving innovation across the travel and transportation industry. We partner with organizations in the airline, cruise, and rail sectors to deliver solutions that improve layover operations, enhance customer experience, and support long-term growth.

Our mission is to make layovers simpler and more efficient for crew members—and we bring that to life through deep industry expertise and a practical, results-driven approach.

Today, API’s platform powers over 18 million crew room nights each year for 100+ airlines and travel operators worldwide. Our Global Reach ensures that airline crews are rested, transported, and connected so global aviation runs on time.

At API, we’re building a culture rooted in succeeding and thriving together. It’s a place where people are encouraged to take ownership, develop their skills, and contribute to work that matters.

If you’re looking to grow your career in a company that values steady progress, real impact, and long-term development, we’d like to meet you!


Overview

The Director of Governance, Risk Management & Compliance (GRC) will lead API’s global IT and security GRC program, reporting to the CISO. This leader is accountable for the company’s cyber risk management framework, regulatory compliance posture, vendor risk program, and data governance strategy.
Success in this role requires the ability to identify, evaluate, and communicate security risks — and to influence strategy across a diverse technology landscape that spans new platforms and legacy business-critical systems. This leader must balance rigorous risk management with business agility, positioning security as an enabler rather than an obstacle.


Key Responsibilities


  • Risk Management: Lead organization-wide risk analysis, maintaining a risk register with documented remediation and mitigation plans. Serve as the primary advisor on information security risks to security management and business unit leads.
  • Compliance & Audit: Establish and own the strategy for managing security audits, compliance checks, and external assessments — including GDPR, SOC 2, ISO 27001, CCPA, and other applicable standards. Liaise with internal and external auditors to implement and sustain required controls.
  • Vendor & Third-Party Risk: Build and manage a comprehensive vendor risk program, evaluating the cybersecurity and data protection controls of third parties, vendors, and business partners.
  • GRC Program Maturation: Drive ongoing security program improvement by amplifying areas of strength and developing actionable plans to address gaps. Develop and report key metrics to security and business leadership.
  • Data Governance & Protection: Lead data governance and data protection programs, ensuring alignment with enterprise risk management principles and up-to-date documentation of systems and processes.
  • Controls & IT Compliance: Facilitate IT compliance across identified controls, including IT general controls (ITGCs), application, cloud, and cybersecurity controls.
  • Policy & Communications: Document, communicate, and enforce security policies that balance risk with business operations. Champion cybersecurity best practices across all business units to reduce the organization’s attack surface.
  • Incident Response: Oversee GRC-related incident response activities, tracking occurrences and resolutions with strict documentation and reporting protocols.
  • Access Review: Manage the access review process to ensure appropriate access is consistently granted, maintained, and revoked.


Success Metrics


Risk register is current, with documented mitigation plans and clear ownership for all identified risks.

SOC 2, ISO 27001, and other applicable certifications and audits are managed on schedule with no critical findings.

Vendor risk program covers all strategic third parties with completed assessments and remediation tracking.

Security metrics are reported regularly to executive leadership with measurable program improvement over time.

Security policies are actively communicated, adopted, and embedded across business units.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Accommodations Plus International

View company profile →