Director leading global Information Security Governance, Risk & Compliance strategy. At LeoLabs, overseeing cybersecurity initiatives protecting assets in commercial and government missions.
Responsibilities
Lead and mature the enterprise cybersecurity and GRC strategy — build scalable governance frameworks and ensure alignment with business goals.
Assess and mitigate organizational risk — conduct risk assessments, close compliance gaps, and drive remediation of vulnerabilities.
Ensure regulatory and contractual compliance — manage frameworks such as FedRAMP, CMMC, NIST, ISO 27001, GDPR, and others.
Oversee incident response and resilience — develop and execute response plans, lead cross-functional remediation, and report to executive leadership.
Partner across the enterprise — build collaboration with Legal, HR, IT, and Operations to embed security and compliance awareness.
Drive major transformation initiatives — including AI adoption risk frameworks, Post-Quantum Cryptography, and Zero Trust architecture implementation.
Requirements
10–12 years of related experience, with 5+ years in supervisory or program/project management roles.
Expertise in cybersecurity governance, risk management, and compliance frameworks (NIST 800-53/171, CMMC, ISO 27001, Cloud Security Alliance).
Strong grasp of cloud infrastructure, access controls, and change management.
Demonstrated experience with agile methodologies and organizational change management.
Excellent executive communication, analytical, and problem-solving skills.
Proven ability to manage competing priorities in a fast-paced, global environment.
Results-oriented with exceptional attention to detail and accountability.
Benefits
Global workforce: flexible remote/hybrid opportunities
Work on complex, meaningful missions with real-world impact
Unlimited paid time off for most roles
Competitive salary and equity packages
Comprehensive health, dental, and vision coverage
Access to the forefront of commercial space operations and defense innovation
Job title
Director of Information Security Governance, Risk, and Compliance, GRC
AI Security Engineer at Prologis focused on securing AI integrations and developing AI security controls. Collaborating with engineering and business teams to promote secure AI practices.
Project Coordinator managing security projects at The Missing Link, ensuring client satisfaction and project deliverables. Coordinating teams and maintaining timelines for project success in the IT field.
Information Security Specialist ensuring optimal protection of data and systems at University of Toronto. Implementing security platforms and best practices for data integrity and threat mitigation.
Loss Prevention Agent responsible for security and loss prevention in logistics facilities. Ensuring safety and protection of property, clients, employees, and guests within the workspace.
Analyst Relations Manager shaping market understanding of Upwind's innovative cloud and AI security platform. Leading relationships with industry analysts to enhance visibility, credibility, and category leadership.
Sr Network Security Engineer designing security architectures and leading security initiatives for RBC. Collaborating across teams to deliver multi - layered security solutions and mentoring team members in engineering best practices.
Senior Threat Modeller enhancing cybersecurity threat modeling for RBC. Collaborating with diverse teams to improve and implement secure by design principles across the enterprise.
Senior Security Engineer supporting security engineering and SIEM administration at Ardent. Focused on improving threat detection and response within vSOC environments in Washington, D.C.
Mainframe Support Engineer ensuring stability and performance of enterprise mainframe systems. Troubleshooting complex issues and collaborating with development, operations, and security teams for optimal system management.
IAM / IGA Security Engineer designing and implementing identity governance solutions. Collaborating with Security, IT, HR, and business stakeholders to ensure secure access governance.