SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 264,000 - 363,000 / annual
Okta is seeking a visionary Senior Director of Governance, Risk and Compliance (GRC) to lead and scale the company's world-class GRC Security organization. This is a builder's role reporting directly to Security Executive leadership, with direct responsibility for cyber risk, data governance, security compliance, and product certifications.
Key responsibilities include:
• Drive AI-first transformation by integrating AI and agentic tools into GRC operations, including automated evidence collection, risk scoring, policy mapping, and continuous audit readiness.
• Operationalize Okta's AI risk and governance framework, addressing training data protection, model risk management, responsible AI principles, and alignment with emerging standards (NIST AI RMF, ISO/IEC 42001, EU AI Act).
• Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification across the organization.
• Maintain and expand Okta's global compliance posture across major frameworks including SOC 1/2/3, ISO 27001, ENS High, MS DPR, PCI-DSS, CSA STAR, and HDS.
• Ensure corporate information security policies and control standards reflect evolving business priorities and emerging threats.
• Direct high-impact vendor risk assessment programs and third-party SaaS governance to ensure supply chain risks meet Okta's security controls standards.
• Serve as primary executive lead for internal/external audits, customer assurances, and regulatory reviews, driving rapid remediation of audit findings.
• Collaborate closely with Product Management, Legal, Privacy, Infrastructure, and Business Technology teams to align compliance with product roadmaps and commercial objectives.
The ideal candidate brings 10+ years of progressive leadership in Security GRC within high-growth SaaS or cloud-first environments, demonstrated expertise in AI/ML governance, mastery of enterprise security frameworks, deep knowledge of risk quantification methodologies, and a proven track record of building and mentoring high-performing technical teams.