Director of Governance and Compliance

Posted 3 Days Ago
Be an Early Applicant
Minneapolis, MN, USA
In-Office
200K-230K Annually
Expert/Leader
Information Technology • Professional Services • Cybersecurity • Defense
The Role
Leads enterprise governance, compliance, privacy, and risk programs across a complex regulatory environment. Develops GRC frameworks, policies, annual compliance plans, and enterprise risk strategies; oversees audits, third-party risk assessments, supplier due diligence, and customer compliance questionnaires. Partners with Information Security and cross-functional leaders to align regulatory requirements with business initiatives, including GDPR, HITRUST, ISO 27001, HIPAA, NIST 800-53, SOC 2, and 21 CFR Part 11.
Summary Generated by Built In

Location: Minneapolis, MN (Hybrid-remote)
Job Type: Full-Time
Target Salary Range*: $200,000 - $230,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary

Position Overview

The Director of Governance and Compliance leads the strategic development, implementation, and oversight of a comprehensive compliance, privacy, governance, and risk management framework aligned with corporate business objectives, regulatory requirements, and industry best practices.

This role is responsible for ensuring organizational operations and practices comply with applicable state, federal, and international laws, regulations, contractual obligations, and industry standards while effectively identifying, assessing, and mitigating organizational risk.

The Director of Governance and Compliance partners closely with the Director of Information Security and cross-functional business leaders to integrate compliance initiatives with broader security, operational, and business strategies.

Key ResponsibilitiesCompliance and Regulatory Governance
  • Maintain a current understanding of business activities and applicable state, federal, and international laws and regulations.
  • Serve as the organization’s subject matter expert for governance, compliance, privacy, and regulatory requirements.
  • Ensure regulatory requirements and compliance practices are incorporated into business initiatives throughout the development lifecycle.
  • Identify, plan, prioritize, and manage organizational compliance and privacy activities based on risk.
  • Develop and maintain an annual compliance plan and associated governance cycle.
  • Manage compliance efforts across the organization to support adherence to applicable laws, regulations, and standards, including GDPR, 21 CFR Part 11, HITRUST, ISO 27001, HIPAA, NIST 800-53, and applicable AI frameworks.
Governance, Risk, and Privacy Frameworks
  • Develop, implement, and maintain the organization’s Governance, Risk, and Compliance policies, procedures, and frameworks.
  • Develop and implement compliance, risk, and privacy frameworks that support resilient business services, architectures, and processes.
  • Ensure governance and compliance programs align with business objectives, regulatory requirements, and organizational risk tolerances.
  • Translate regulatory requirements into actionable business unit initiatives and priorities.
  • Serve as a trusted advisor to business unit leadership on compliance, privacy, governance, and risk matters.
Enterprise Risk Management
  • Lead the company-wide Enterprise Risk Management program.
  • Collaborate with Product, Engineering, Business Operations, Sales, Support, Legal, Human Resources, and other operational teams to identify, evaluate, and mitigate risk.
  • Maintain ongoing risk assessment and monitoring processes.
  • Develop and implement effective risk mitigation strategies.
  • Proactively identify emerging compliance and regulatory risks and recommend corrective actions.
Audit and Assurance
  • Oversee internal and external audit assessments.
  • Evaluate compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards.
  • Coordinate audit readiness activities and support remediation of identified findings.
  • Assist with preparation of Regulatory Affairs briefings for the Executive Committee, Board of Directors, and Compliance Committees.
Third-Party and Supply Chain Risk Management
  • Lead Third-Party Supplier Management risk assessments and associated governance programs.
  • Ensure third-party risk management activities align with business objectives and organizational risk tolerances.
  • Manage supply chain risk processes, including vendor assessments, due diligence, and ongoing monitoring.
  • Evaluate supplier compliance, security, privacy, and regulatory risk.
Customer and Stakeholder Engagement
  • Respond to customer compliance questionnaires in a timely and thorough manner.
  • Develop customer-facing materials explaining organizational compliance policies, practices, and positions.
  • Collaborate with cross-functional stakeholders to integrate compliance and risk management into organizational programs.
  • Present complex regulatory, compliance, and risk topics to executive leadership, business stakeholders, customers, and other audiences.
Security, Privacy, and Organizational Compliance
  • Partner with the Director of Information Security to align compliance initiatives with security strategy.
  • Maintain awareness of information security practices and their relationship to compliance and privacy requirements.
  • Ensure compliance with company policies related to security, confidentiality, privacy, and data protection.
  • Support a secure and compliant operating environment across the organization.
QualificationsExperience
  • 8–10 years of experience in regulatory compliance, preferably within the healthcare or technology industry. [Required]
  • Proven experience developing, implementing, and overseeing governance and compliance frameworks in complex, multi-regulatory environments. [Required]
  • Experience assessing compliance risk and developing and implementing effective mitigation strategies. [Required]
  • Experience overseeing or supporting internal and external audits, regulatory assessments, and compliance reviews.
  • Experience with enterprise risk management, third-party risk management, and supplier due diligence.
Skills
  • Deep knowledge of regulatory frameworks, standards, and industry best practices, including HITRUST, ISO 27001, SOC 2, 21 CFR Part 11, and NIST 800-53. [Required]
  • Strong understanding of IT security standards, privacy laws, and compliance regulations. [Required]
  • Familiarity with information security practices and their intersection with compliance requirements. [Required]
  • Strong analytical skills and attention to detail. [Required]
  • Ability to identify inconsistencies, compliance gaps, and emerging regulatory risks. [Required]
  • Proactive problem-solving and risk mitigation capabilities. [Required]
  • Proficiency with compliance management software and tools. [Required]
  • Excellent project management skills. [Required]
  • Excellent written and verbal communication skills. [Required]
  • Ability to present complex regulatory frameworks and compliance requirements to technical, business, customer, and executive audiences. [Required]
Education / Certifications
  • Advanced education or professional certification demonstrating deeper expertise in compliance, regulatory affairs, governance, risk, privacy, or a related discipline. [Required]

Preferred Qualifications
  • Experience within healthcare, biomedical, life sciences, or technology-related industries.
  • Experience operating within highly regulated, multi-framework environments.
  • Experience integrating governance, compliance, privacy, and information security programs across complex organizations.

Skills Required

  • 8-10 years of experience in regulatory compliance, preferably in healthcare or technology
  • Deep knowledge of HITRUST, ISO 27001, SOC 2, 21 CFR Part 11, and NIST 800-53
  • Experience developing, implementing, and overseeing governance frameworks and programs in complex, multi-regulatory environments
  • Strong understanding of IT security standards, privacy laws, and compliance regulations
  • Strong attention to detail and ability to identify inconsistencies or potential regulatory issues
  • Strong analytical skills and experience developing and implementing compliance risk mitigation strategies
  • Proactive approach to identifying and resolving potential compliance issues
  • Proficiency with compliance management software and tools
  • Familiarity with information security practices and their relationship to compliance requirements
  • Excellent project management and communication skills, including presenting complex regulatory frameworks
  • Advanced education or certification demonstrating expertise in compliance and regulatory affairs
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
200 Employees
Year Founded: 2011

What We Do

The Amatriot Group is a talent solutions firm providing technology expertise to the federal and commercial sectors. With over a decade of experience delivering mission-critical support to the intelligence, defense, and national security sectors, the company specializes in delivering cutting-edge technology solutions by securing top-tier talent to bridge workforce gaps in the most complex and secure environments.

Similar Jobs

In-Office
Bloomington, MN, USA
14000 Employees
180K-248K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
14 Locations
40000 Employees
45K-85K Annually

Arrive Logistics Logo Arrive Logistics

Coverage Specialist

Logistics • Sales • Software • 3PL: Third Party Logistics
In-Office
St Paul, MN, USA
1700 Employees

Zeta Global Logo Zeta Global

Director of Paid Search, EDU

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
120K-140K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account