Director, Governance Risk and Compliance

Remote Full-time
Director, Governance Risk and Compliance
Remote - United States

The Opportunity:
Anthology offers the largest EdTech ecosystem on a global scale, supporting over 150 million users in 80 countries. Our mission is to provide dynamic, data-informed experiences to the global education community so that learners and educators can achieve their goals.

We believe in the power of a truly diverse and inclusive workforce. As we expand globally, we are committed to making diversity, inclusion, and belonging a foundational part of not only our hiring practices but who we are as a company.

For more information about Anthology and our career opportunities, please visit www.anthology.com.

The Director, Governance Risk and Compliance (GRC) is responsible for leading efforts to assess the confidentiality, integrity and availability of information via the framework set forth in the company’s global Information Security Management System (ISMS). This includes assessments of compliance with company security policies, operating an internal and third-party risk management process, and regular review and measurement of the effectiveness of information security controls. The successful candidate will liaise with and advise various teams including those responsible for systems architecture, systems deployments and application configuration. The position is a subject matter expert able to translate complex regulations in NIST, ISO, SOC, and PCI-DSS frameworks and standards into practical security controls and processes and reporting on the company's risk posture to senior management.

Primary responsibilities will include:
• Developing and maintaining the organization's ISMS documentation, including policies, standards, and procedures for risk management, compliance, and information security. Responsible for recommendations to the CISO, Product Management, Legal and Finance leadership teams that provide security program alignment with compliance requirements.
• Responsible for information risk management, collaborative design of information security controls, assessment of effective implementation of applicable controls, including identity and access management.
• Staying current on evolving regulatory environments, security threats, and compliance best practices, and updating policies and procedures accordingly.
• Responsible for maintaining and improving information security awareness in the organization.
• Translating business and information security needs and integrating these with the ISMS.
• Coordinating external audit engagements with 3PAO, ISO/SOC auditors, PCI DSS QSA firms and other security assessors, including coordinating responses and remediation efforts.
• Conducting vendor risk assessments and ensuring third-party compliance with security and privacy standards.
• Reviewing and monitoring the activities of the Security Incident Response and Business Continuity Management teams to ensure that the information security controls are used effectively during the complete life cycle of business continuity and disaster recovery response.
• Managing the recurring measurement of the effectiveness of ISMS controls implemented and communicate findings with senior management.
• Enforcing document control management processes for the Information Security Management System.
• Assisting with forecasting, planning and risk assessment relevant to evolving security control coverage in alignment with the company’s technology strategy.
• Maintaining and applying current industry knowledge and best practices. Researching and recommending use of new technologies.
• Project management including analysis of business requirements, creating and updating project plans, and tracking projects to successful completion.
• Assisting with vendor management, forecasting and program budget management.
• Managing personnel including mentoring and cross-training of team members to achieve business objectives.

The Candidate:
Required skills/qualifications:
• US Citizenship
• 10+ years of hands-on experience in IT audit and/or compliance
• Strong documentation and communication skills
• Strong understanding of security standards and frameworks including ISO27000 series, NIST Special Publication 800 series, SOC audits, and security requirements of Data Privacy laws
• Previous experience gaining an ATO or P-ATO for a cloud implementation under the FedRAMP, GovRAMP or IL-4 programs
• Understanding of software development lifecycle methodologies, cloud and server infrastructure, network technologies

Preferred skills/qualifications:
• Current CISA, CISM, CISSP or equivalent certification is strongly preferred
• Experience managing security staff, collaboration and relationship building with global teams

While the full salary range for this role is $154,000 - $231,000, the expected hiring range for this opening is $154,000 - $200,000, depending on experience and budget availability. We use national and industry-specific survey data to assist in determining compensation. Additionally, we consider factors such as external market rate, budget for the role, and the compensation rates of current employees performing the same function. Some roles will have variable pay.

This job description is not designed to contain a comprehensive listing of activities, duties, or responsibilities that are required. Nothing in this job description restricts management's right to assign or reassign duties and responsibilities at any time.

Anthology is an equal employment opportunity/affirmative action employer and considers qualified applicants for employment without regard to race, gender, age, color, religion, national origin, marital status, disability, sexual orientation, gender identity/expression, protected military/veteran status, or any other legally protected factor.

Apply Now

Apply Now
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Help Desk - Weekend Shift - FULLY REMOTE

Remote Full-time

Senior Marketing and Communications Specialist

Remote Full-time

(Remote Part-time jobs) Amazon Jobs: Work from Home Customer Service Opportunities

Remote Full-time

EHS Systems & Processes Director - Global Audit IN-WorkFromHome Indiana Indiana, United States Indiana United States EHS Systems & Processes Director - Global Audit

Remote Full-time

Onboarding Customer Support Specialist

Remote Full-time

Mergers & Acquisitions Analyst – Corporate Development

Remote Full-time

Outside Sales Representative

Remote Full-time

Associate Director - Online Threat Intelligence

Remote Full-time

Project Manager/Project Coordinator for General Construction Company

Remote Full-time

Chaplain Part Time - SoCal

Remote Full-time
← Back to Home