SlipstreamJobsFresh Startup & VC-Backed Jobs

Director, Governance, Risk & Compliance

MX Technologies - Lehi, UT, United States - In-office - posted 2026-07-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

MX Technologies is a fintech company empowering financial institutions and fintechs to deliver smarter financial experiences. The company is in a phase of renewed momentum and scale, with a solid foundation and clear vision for growth. Reporting to the VP & Chief Information Security Officer, the Director of Governance, Risk & Compliance will lead the enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This role owns the strategy, execution, and continuous improvement of MX's security governance, privacy, and regulatory compliance initiatives. Key responsibilities include: **Governance & Strategy**: Develop and execute the enterprise GRC strategy. Build, mature, and continuously improve security, privacy, and risk management programs aligned with business objectives and regulatory requirements. Develop and operationalize enterprise-wide security policies, standards, controls, and governance processes. Establish scalable compliance frameworks supporting company growth while reducing organizational risk. **Privacy & Regulatory Compliance**: Lead the global privacy program across multiple jurisdictions. Ensure compliance with GDPR, CCPA, HIPAA, PIPEDA, UK Data Protection Act, and emerging regulations. Partner with Legal, Engineering, Product, and business stakeholders on Privacy Impact Assessments and privacy requirements throughout the product lifecycle. Develop governance frameworks for data collection, storage, processing, retention, and sharing. Oversee data mapping, vendor privacy reviews, and data governance practices. **Audits & Customer Assurance**: Own all internal and external security, privacy, and compliance audits. Lead certification efforts including SOC 2, ISO 27001, PCI DSS, and other applicable frameworks. Serve as executive owner for customer security and privacy questionnaires. Partner with Sales and Customer Success on enterprise customer due diligence and security reviews. **Risk Management**: Continuously assess organizational security, compliance, and privacy risks. Monitor effectiveness of security controls and recommend improvements. Build reporting and metrics providing executive visibility into organizational risk posture. Develop mitigation strategies and partner across engineering and operations to reduce risk. **Team Leadership**: Lead, mentor, and grow a high-performing Compliance and Privacy team. Foster a culture of accountability, operational excellence, and continuous improvement. Develop scalable processes improving efficiency while maintaining regulatory compliance. **Cross-Functional Partnerships**: Partner closely with Security, Engineering, Legal, Product, Sales, Support, and Operations to embed security and privacy into business processes. Influence stakeholders to balance business objectives with regulatory obligations. Lead company-wide privacy and compliance awareness initiatives and employee training programs. Required qualifications include a bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Business, Legal Studies, or related field, plus 10+ years of experience leading Information Security Governance, Risk, Compliance, Privacy, or Security Operations programs. Deep expertise with compliance frameworks and experience implementing GRC programs required.

Similar roles