Director - GRC for SOX Systems
MattelAbout the role
Company Description
CREATIVITY IS OUR SUPERPOWER. It’s our heritage and it’s also our future. Because we don’t just make toys. We create innovative products and experiences that inspire fans, entertain audiences and develop children through play. Mattel is at its best when every member of our team feels respected, included, and heard—when everyone can show up as themselves and do their best work every day. We value and share an infinite range of ideas and voices that evolve and broaden our perspectives with a reach that extends into all our brands, partners, and suppliers.
Job Description
The Opportunity:
We are seeking an experienced and strategic Director of Governance, Risk, and Compliance (GRC). You will report to the Senior Director - GRC and help with an evolving workload in a fast-paced environment. If you are passionate about continuous learning and keeping up with cutting edge technology and influencing the future of GRC leveraging data and automation, then this is the position for you! Whether it is facilitating Mattel’s SOX compliance efforts or conducting ITGCs, we strive to enhance the effectiveness, efficiency and scalability of the company’s processes, systems, and underlying IT control environment. You will be expected to problem solve, collaborate, and move fast while keeping attention to detail.
Position is expected to be Onsite role : El Segundo, CA
The Director will be instrumental in building a world-class IT GRC function, that provides assurance and advisory services regarding Mattel’s IT & Security governance, risk and control effectiveness.
The Director must demonstrate significant experience with assessing risk and demonstrate excellence in designing and implementing a risk-based approach.
What Your Impact Will Be:
• Partnering and strengthening relationships with key stakeholders (including Internal Audit, IT Engineering, Product Security teams, and external auditors) for ongoing risk assessments, proactive insights on risks and oversight on planned audit(s) planning & execution.
• Deep dive into Mattel’s IT environment to develop broad domain and technical understanding of our key policies, risks & controls in place to ensure that Mattel has a controlled IT environment.
• Overseeing the coordination and delivery of ITGCs and other IT controls to internal and external audit. Facilitate and lead IT control remediation efforts
• Be a GRC Liaison for all system implementations and its SDLC processes
• Strategic Leadership: Develop and implement the GRC strategy aligned with organizational goals and regulatory requirements.
• GRC Planning: Design and execute a comprehensive risk-based annual IT & Security internal GRC & audit plan for approval by all stakeholders that identifies and evaluates risk areas, controls, and compliance with internal policies and external regulations.
• Risk Assessment: Conduct risk assessments to identify system vulnerabilities, compliance gaps, and areas for improvement, ensuring robust protection against security threats and mismanagement.
• Team Management: Lead, mentor, and develop our high-performing GRC team, fostering a culture of continuous improvement (e.g., efficient and effective ways of testing controls leveraging data/ Snowflake product as needed) and professional growth.
• Reporting: Prepare and communicate clear, concise reports to senior management, highlighting significant findings, risks, and recommendations for improvement.
• Stakeholder Collaboration: Work closely with key stakeholders, including Engineering, Product Management, Security / IT risk management, IT Enterprise Apps teams, to build strong working relationships and facilitate collaborative approaches to managing risk.
• Continuous Improvement: Recommend enhancements to internal controls and processes based on audit findings and industry best practices, aiding in the establishment of an agile and responsive GRC function.
• Education and Awareness: Conduct training sessions to promote awareness of internal controls, risk management, and compliance across the organization
Qualifications
What We’re Looking For:
• 15+ years of experience with a combination of IT / Security / audit and Tech Industry background
• 10+ years in managing and building high performing teams
• Experience with system implementations like Oracle Cloud.
• Hands-on experience with GRC platforms (e.g., AuditBoard, Fastpath, Archer, ServiceNow, etc.) and risk management tools.
• Experience in leading an IT / Security audit function
• Bachelor’s or Master’s degree in Computer Science, Information Technology or Systems; or relevant MBA.
• CISA, CISSP, CISM, or similar certifications.
• Relevant work experience in IT SOX, other Technology or
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s