About The Position

This position provides enterprise leadership for security risk and compliance by setting strategy, owning GRC outcomes, and ensuring regulatory alignment across the company and its subsidiaries. The Executive Director builds and sustains the enterprise GRC framework and leads all enterprise attestations and certifications, including SOX, HIPAA, and HITR HITRUST, supported by clear C suite and Board reporting. The role governs security policy, exceptions, security awareness initiatives, and third party risk management, while enabling consistent identification, tracking, remediation, and reporting of security risks across the enterprise. Responsibilities also include overseeing processes for threat and vulnerability management, ensuring adherence to established risk policies and standards, and continuously improving security risk management capabilities and controls. The Executive Director owns the enterprise information security risk posture, budget stewardship, and cross functional alignment with Legal, Compliance, IT, and Business stakeholders.

Requirements

  • Bachelor’s degree and 15 years of experience in IT/Information Security; or 19 years of experience without a degree.
  • Minimum 7 years of people leadership experience (multi‑team leadership preferred).
  • Proven experience leading enterprise GRC programs (risk, compliance, policy, third‑party risk, subsidiary governance).
  • Demonstrated success briefing executives/Board, owning budgets, and driving cross‑functional outcomes.

Nice To Haves

  • Executive experience with regulatory regimes (e.g., HIPAA/HITRUST, SOX) and enterprise control frameworks (NIST CSF/800‑53, ISO 27001).

Responsibilities

  • Provides enterprise leadership for security risk and compliance by setting strategy, owning GRC outcomes, and ensuring regulatory alignment across the company and its subsidiaries.
  • Builds and sustains the enterprise GRC framework.
  • Leads all enterprise attestations and certifications, including SOX, HIPAA, and HITRUST.
  • Governs security policy, exceptions, security awareness initiatives, and third party risk management.
  • Enables consistent identification, tracking, remediation, and reporting of security risks across the enterprise.
  • Oversees processes for threat and vulnerability management.
  • Ensures adherence to established risk policies and standards.
  • Continuously improves security risk management capabilities and controls.
  • Owns the enterprise information security risk posture.
  • Manages budget stewardship.
  • Ensures cross-functional alignment with Legal, Compliance, IT, and Business stakeholders.

Benefits

  • Health and wellness benefits
  • 401(k) savings plan
  • Pension plan
  • Paid time off
  • Paid parental leave
  • Disability insurance
  • Supplemental life insurance
  • Employee assistance program
  • Paid holidays
  • Tuition reimbursement
  • Other incentives
  • Annual incentive bonus plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service