Jobs and Careers
TH

Cybersecurity GRC Product Owner (Associate Director)

The Clorox Company
Pleasanton, United Statesfull_timeVerifiedPosted 27 Jan 2026
💰 $309,000/yr($128,100/yr$309,000/yr)

About the role

Clorox is the place that’s committed to growth – for our people and our brands. Guided by our purpose and values, and with people at the center of everything we do, we believe every one of us can make a positive impact on consumers, communities, and teammates. Join our team. #CloroxIsThePlace

Your role at Clorox:

We are seeking an experienced leader to spearhead our enterprise Cybersecurity Governance, Risk, and Compliance (GRC) program. This role encompasses cyber risk management, governance, compliance, Third Party Vendor Risk Management, and Human Risk Management. As a leader, you will be accountable for identifying, evaluating, reporting, and managing information security risks to meet compliance and regulatory requirements, while building business confidence in our cybersecurity program.

Success in this role requires proactive collaboration with cross-functional stakeholder teams across the enterprise to ensure alignment and application of practices that support business goals and meet defined policies and standards for information security.

As a strategic thinker, you will navigate the complex landscape of regulatory requirements, privacy concerns, and evolving security threats. You will define product roadmaps, prioritize features, and manage your product team to uphold the organization’s cybersecurity standards and governance. Collaboration with key stakeholders across the organization is crucial to ensure the maintenance and continuous evolution of the GRC environment, ensuring sensitive data is appropriately managed and risk processes are aligned with our enterprise strategic objectives

In this role, you will:

Governance

  • Develop and maintain the security governance framework, policies, and procedures aligned with industry standards and best practices. 
  • Ensure that the organization adheres to established governance guidelines. 
  • Ensure AI capabilities are governed, secure, explainable, compliant, and humanaccountable, while delivering measurable risk and efficiency outcomes without increasing regulatory or data exposure.
  • Collaborate with the business, IT Infrastructure and Applications leaders to implement and enforce standards and control objectives throughout the organization. 

Risk Management 

  • Identify, assess, and prioritize security risks related to assets, systems, and data. 
  • Define security improvements to resolve or mitigate security findings or otherwise enhance security posture to achieve compliance with all security initiatives. 
  • Implement risk mitigation strategies and controls to minimize exposure to threats and vulnerabilities. 
  • Conduct regular security risk assessments and provide recommendations for remediation actions. 
  • Evaluate and manage security risks associated with third-party vendors and service providers. 
  • Overseeing audits, penetration tests, and forensic investigations, ensuring that findings are comprehensively understood and effectively remediated. 

Compliance

  • Establish and maintain an effective compliance framework aligned with applicable laws, regulations, and global industry standards. 
  • Ensure compliance with regulatory mandates and reporting requirements. 
  • Oversee internal and external audits, addressing findings and implementing corrective actions. 
  • Enforce standards of multiple security frameworks, including SOX, PCI, and Global Privacy regulations (e.g., CCPA, GDPR) 
  • Ensure AI capabilities meet regulatory and compliance expectations by understanding applicable AI, privacy, and sectorspecific regulations (e.g., EU AI Act) and mapping AI use cases to established control frameworks (SOX, ISO 27001, SOC 2, NIST, and privacy requirements)

Training and Awareness

  • Drive strategy for the Human Risk Management Program 
  • Lead educational initiatives to promote a culture of risk awareness and compliance among employees and third parties. 
  • Address the unique threats and risks specific to the organization’s business and technological environment. 

Stakeholder Engagement

  • Collaborate with executive leadership and internal stakeholders to align security initiatives with business objectives. 
  • Serve as the main liaison for business units and functions, ensuring cybersecurity risks are effectively identified, assessed, and managed. 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

The Clorox Company

View company profile →