Jobs and Careers
HU

Sr Director, Governance, Risk, and Compliance

HUB International
United Statesfull_timeVerifiedPosted 8 Aug 2025
💰 $190,000/yr($160,000/yr$190,000/yr)

About the role

ABOUT US

At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.

HUB is one of largest global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions.

Position Overview:

The Senior Director of Governance, Risk, & Compliance will oversee strategic initiatives to enhance the company's security posture, regulatory compliance, and risk management frameworks. This role leads efforts in data governance, third-party risk management, regulatory compliance, data privacy, cybersecurity response management (RFPs and inquiries), security audits including SOC2, SOX, and IT General Controls (ITGC), and access reviews. Collaboration with legal, compliance departments, business stakeholders, and control owners will be critical. The ideal candidate will have extensive expertise in managing security policy frameworks, security awareness programs, cyber risk assessments, technology initiatives, and reporting metrics in a large, complex insurance brokerage environment.

Key Responsibilities:

1. Data Governance:

  • Lead the implementation and continuous improvement of enterprise data governance frameworks.
  • Ensure compliance with data governance standards and policies.
  • Oversee data classification, ownership, integrity, privacy, and compliance monitoring initiatives.
  • Collaborate with business stakeholders and control owners to integrate data governance principles into business operations.

2. Third-Party Risk Management:

  • Develop, maintain, and enhance comprehensive third-party risk management programs.
  • Conduct risk assessments and continuous monitoring of third-party vendors and service providers.
  • Collaborate with procurement, legal, IT, business stakeholders, and control owners to ensure robust risk management practices.

3. Customer Cybersecurity and Compliance Responses:

  • Manage and streamline processes for responding to customer cybersecurity questionnaires, RFPs, and compliance-related inquiries.
  • Collaborate with sales, legal, IT, operations teams, business stakeholders, and control owners to ensure timely, accurate, and comprehensive responses.

4. Data Privacy and Regulatory Compliance:

  • Oversee compliance with applicable data privacy laws and regulations (e.g., GDPR, CCPA) through strong partnership with legal and other relevant stakeholders.
  • Provide strategic guidance on data privacy practices and regulatory compliance initiatives.
  • Coordinate response and remediation activities related to privacy incidents or breaches in collaboration with legal, business stakeholders, and control owners.

5. Audit & Compliance:

  • Lead Security Department compliance and audit activities related to SOC2, SOX, and IT General Controls.
  • Liaise with internal and external auditors, business stakeholders, and control owners, ensuring preparedness, remediation of findings, and continuous compliance.
  • Drive improvements in control environments based on audit findings and emerging regulatory requirements.

6. Security Policies & Security Awareness Training:

  • Develop, implement, and maintain comprehensive security policy frameworks aligned with industry standards and best practices.
  • Oversee the creation and delivery of effective security awareness and training programs for employees and stakeholders.
  • Regularly review and update policies to reflect evolving risks, compliance requirements, and industry standards in partnership with legal, compliance teams, business stakeholders, and control owners.

7. Risk Management:

  • Establish and maintain robust enterprise risk management frameworks.
  • Conduct and oversee comprehensive cyber risk assessments and drive actionable remediation plans.
  • Collaborate across business units, including legal, business stakeholders, and control owners, to ensure effective integration of risk management practices into day

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

HUB International

View company profile →