SlipstreamJobsFresh Startup & VC-Backed Jobs

Director, Governance, Risk & Compliance

Anomali - Redwood City, CA, United States - Hybrid - posted 2026-07-23

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Anomali is a Silicon Valley-based cybersecurity platform company delivering an Intelligence-Native Agentic SOC (Security Operations Center) platform used by governments and enterprises worldwide. The platform unifies a security data lake, threat intelligence repository, and agentic AI to accelerate detection, investigation, and response across any environment. You will serve as Director of Governance, Risk & Compliance, owning the end-to-end GRC strategy and execution for a rapidly scaling compliance program. This is a hands-on builder role focused on driving multi-jurisdiction certification portfolio maturity to unlock new markets and revenue. Key responsibilities include: **Program Ownership & Strategy**: Own the complete GRC roadmap spanning FedRAMP (Moderate/High), ISO 27001, SOC 2 Type II, and regional cloud security frameworks (UAE DESC, Saudi Arabia NCA/CCC, Australia IRAP). Prioritize and sequence certification efforts against go-to-market and revenue targets in partnership with sales, product, and executive leadership. Serve as primary liaison with assessors, auditors, and regulatory bodies. **FedRAMP Management**: Manage ongoing FedRAMP authorization activities including ATO maintenance, continuous monitoring, SAR/POA&M remediation in partnership with the 3PAO and sponsoring agency. Own documentation quality and escalation management. **ISO 27001 & SOC 2**: Maintain and evolve the Information Security Management System (ISMS), manage audit cycles, and drive continuous improvement. Own SOC 2 Type II audit readiness, evidence collection, control testing, and remediation across annual cycles. Ensure alignment between SOC 2 and overlapping ISO 27001/FedRAMP requirements. **Regional Certifications**: Drive DESC CSP certification for UAE market access, manage Saudi NCA compliance (ECC/CCC) with local partners, own Australia IRAP assessment coordination, and monitor emerging regional requirements. **Risk & Controls**: Build a unified controls framework mapping overlapping requirements across all frameworks. Own enterprise risk register, vendor/third-party risk management, and remediation tracking. Partner with engineering and product teams to ensure security controls are designed in. **Cross-Functional Leadership**: Partner with IT, Security, Cloud Infrastructure, Engineering, and Product teams to drive compliance outcomes. Support customer/prospect due diligence and partner with legal on regulatory obligations and contractual compliance. Required: 8+ years in GRC/information security compliance with 3+ years in leadership. Direct hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner. Demonstrated ownership of ISO 27001 certification, SOC 2 Type II audits, and at least one Middle East cloud security framework. Familiarity with Australia IRAP. Strong knowledge of cloud security architecture (AWS/Azure/GCP) and control mapping. Excellent stakeholder management and written communication skills. Preferred: CISSP, CISA, CISM, or ISO 27001 Lead Auditor certification. Experience in high-growth, venture-backed SaaS/cybersecurity companies. Prior experience managing multiple concurrent certifications. Familiarity with GRC tooling (Vanta, Drata, ServiceNow GRC). Note: No visa sponsorship available. Hybrid role for candidates within commutable distance of Redwood City; remote US candidates also considered.

Similar roles