Director - Cybersecurity Compliance (Onsite - Raleigh, NC)
Function: Information Security Governance, Risk & Compliance (GRC)
Reports To: Chief Information Security Officer (CISO).
Position Summary:
This is a strategic leadership role requiring someone who can build and drive a cybersecurity compliance program. The candidate should be able to define strategy, execution steps, metrics, and monitoring/reporting mechanisms. Strong understanding of how risk, compliance, and governance interrelate is essential. The role will work alongside an existing compliance manager and analyst.
The Director - Cybersecurity Compliance is responsible for establishing, leading, and overseeing an enterprise-wide cybersecurity compliance program. This role ensures the organization consistently meets applicable regulatory, legal, and industry cybersecurity requirements while maintaining a repeatable, auditable, and scalable compliance posture.
Responsibilities:
Cybersecurity Compliance Program Leadership
- Establish and operate an enterprise-wide cybersecurity compliance program.
- Provide strategic direction and oversight for compliance activities.
- Align compliance efforts with business objectives and risk appetite.
Regulatory, Framework & Standards Oversight
- Lead compliance efforts for frameworks such as SOX, PCI, HIPAA, and NIST CSF.
- Oversee control mapping and framework alignment.
- Ensure policies and standards are updated regularly.
Audit, Monitoring & Evidence Management
- Oversee continuous compliance monitoring and control testing.
- Support internal and external audits.
- Maintain audit-ready processes.
Governance, Accountability & Risk Management
- Define roles and responsibilities across stakeholders.
- Facilitate governance and escalation of compliance issues.
- Partner with Enterprise Risk Management.
Reporting & Executive Engagement
- Provide regular reporting to leadership.
- Support board-level discussions with risk insights.
- Ensure transparency in compliance reporting.
Tooling & Enablement
- Oversee GRC tools such as OneTrust.
- Drive automation and standardization.
Required Skills/Qualifications:
- 8+ years of experience in cybersecurity/GRC.
- Experience with GRC platforms.
- Strong knowledge of compliance frameworks.
- Experience supporting audits and regulatory requirements.
- Ability to engage executive stakeholders.
- Experience in retail or regulated environments.
- Certifications such as CISSP, CISM, or CRISC.
- Bachelor s degree in a relevant field.
Other Job Details:
- Job Type: C2C or W2.
- Duration: 6 months with high possibility of extension.
- Locations: Hybrid - Raleigh, NC. Must be within commuting distance to Raleigh, NC.
- Work Schedule: 8:00 AM 5:00 PM EST.
- Pay Rate: Open to Market Rate (W2 and C2C).
- Interviews: 2 rounds via MS Teams (scheduled through Beeline).
- Docs required: ID proof will be required.