Director, IT Governance, Risk and Compliance

Prologis•Denver, CO
•$168,000 - $232,000•Onsite

About The Position

The Director, IT Governance, Risk, and Compliance (GRC) leads Prologis’ global IT GRC program and team, reporting to the CISO. This role establishes governance, risk, and compliance priorities across the countries where Prologis operates and partners with global business and technology teams to strengthen technology risk and control oversight. The Director works closely with Security, Infrastructure, Internal Audit, Legal, HR, Risk, Finance, and business leadership to address regulatory, audit, third-party, and information risk requirements. The role also modernizes and scales GRC processes through AI, automation, workflow improvements, and system integrations to improve efficiency, reporting, and control effectiveness.

Requirements

  • 10+ years of relevant experience in IT governance, risk, compliance, IT audit, or related disciplines.
  • 3+ years of people-management experience.
  • Demonstrated experience leading enterprise GRC programs.
  • Experience with the NIST Cybersecurity Framework (CSF) 2.0 and the Three Lines Model.
  • Experience with SOX, IT general controls, and technology-related regulatory requirements in a global environment.
  • Experience applying AI, workflow automation, and system integrations to streamline GRC processes, improve reporting, strengthen control monitoring, or increase operational efficiency.
  • Ability to influence executives and collaborate effectively across technology, Internal Audit, Legal, HR, Risk, Finance, and other global business functions.
  • Ability to exercise sound judgment and discretion when handling sensitive matters.

Nice To Haves

  • Bachelor’s degree or equivalent relevant experience.
  • Relevant GRC, audit, risk, or cybersecurity certification.
  • Ability to learn quickly and adapt to evolving regulatory and technology requirements in a global environment.
  • Demonstrates willingness and capability to leverage emerging technology, automation, and AI tools to improve efficiency, quality, and speed. Exercises sound judgment, creative thinking, and accountability for outcomes.

Responsibilities

  • Lead the global IT GRC program and establish strategy and priorities across governance, technology risk, compliance, and assurance.
  • Lead IT risk and controls oversight within the Three Lines Model, including risk assessments, control requirements, risk acceptance and exceptions, control monitoring, remediation oversight, and leadership reporting aligned with the NIST Cybersecurity Framework (CSF) 2.0 and applicable regulatory and audit requirements.
  • Oversee global technology compliance and assurance activities, including SOX, IT general controls (ITGC), GDPR, DORA, HIPAA, SWIFT, India’s Information Technology Act, and disaster recovery governance and testing oversight.
  • Govern third-party and cyber supply chain risk, data protection and information risk, investigations, eDiscovery, and technology and cybersecurity support for investor Operational Due Diligence (ODD) assessments and requests.
  • Monitor emerging technology risks and evolving regulatory requirements, assess their impact on Prologis, translate applicable changes into GRC and control requirements, and advise leadership on implications.
  • Modernize and scale GRC processes by applying AI, workflow automation, and system integrations to improve efficiency, reporting, control monitoring, and control effectiveness.
  • Lead and develop the GRC team, manage GRC technology and vendors, and oversee security awareness and IT policy governance, including training campaign planning, communications coordination, and IT policy and procedure governance.

Benefits

  • healthcare
  • dental
  • vision insurance
  • wellness programs
  • financial benefits
  • work/lifestyle-specific benefits
  • 401(k) retirement plan with company match
  • generous PTO
  • paid holidays
  • volunteer time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service