Jobs › Virginia › McLean › Director, Information Security Governance, Risk, and Compliance (GRC)
Director, Information Security Governance, Risk, and Compliance (GRC)
PenFed Credit Union is hiring for the job of Director, Information Security Governance, Risk, and Compliance (GRC), McLean, VA (On-site). This is a Risk job in the governance, risk, and compliance field, with a posted range of $121,800 - $283,648. Review the full details below and apply directly with PenFed Credit Union.
PenFed is hiring a (Hybrid) Director, Information Security Governance, Risk, and Compliance (GRC) at our Tysons, Virginia location. The primary purpose of this role is to operationalize and execute the enterprise Information Security Governance, Risk, and Compliance (GRC) strategy established by the VP, Information Security Risk and Governance. The Director translates strategic direction into priorities, work plans, team guidance, and hands-on risk and compliance activities to ensure high-quality, timely outcomes. This role serves as the primary Information Security point of contact for NCUA examinations and audits; coordinates work across Information Security, Technology, Enterprise Risk, Internal Audit, Legal, and business teams; and is accountable for the quality and timely completion of Document Request List (DRL) responses, findings, exceptions, risk assessments, control activities, and remediation commitments. The Director balances leadership with direct operational involvement to strengthen the organization’s security posture and enable consistent, risk-based decision-making.
Equivalent combination of education and experience is considered.
- Master’s Degree and/or bachelor’s degree in computer science or equivalent in related field preferred.
- Minimum of ten (10) years of relevant Information Security risk management experience.
- Proven experience leading, coaching, and developing teams while establishing priorities, driving accountability, and delivering high-quality outcomes in a complex Information Security, risk, or compliance environment.
- Experience in the management of security control capabilities within large, complex financial services organization.
- Solid working knowledge of understanding key security controls (Access Control, Encryptions, etc.)
- Ability to communicate effectively and influence Business and IT leadership, staff, and other stakeholders, company-wide, to implement security recommendations.
- Ability to establish and develop effective, trusting relationships with internal business units, together with a proven knowledge of the methods necessary to assess information security within a large organization.
- Experience with risk management tracking tools (e.g., Archer, ServiceNow GRC, or similar platforms) to document risks, monitor remediation progress, maintain control inventories, and deliver accurate, data‑driven risk reporting.
- Experience in formal risk assessment and risk management practice.
- Strong familiarity with information security, risk management, and IT government standards and frameworks (e.g. NIST 800-53, NIST Cyber Security Framework, ISO 27001/2, etc.)
- Experience using AI tools preferred.
Supervisory Responsibility
This position will supervise employees.
Licenses and Certifications
CISSP, CISA, CISM, CRISC, etc.
Work Environment
While performing the duties of this job, the employee is regularly exposed to an indoor office setting with moderate noise.
*Most roles require working in an office setting with moderate noise and the ability to lift 25 pounds.*
Travel
Ability to travel to various worksites and be on call is required.
Pay Transparency The anticipated starting salary range for this role is $121,800.00 - $283,648.00This position is eligible for an organizational performance based annual bonus, subject to board discretion and approval.This position is eligible for an individual performance based annual bonus.
Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. This is not intended to be an all-inclusive list of job duties, and the position will perform other duties as assigned.
- Lead and actively execute the Information Security risk management program, including identifying, assessing, analyzing, monitoring, and reporting risks and working directly with stakeholders to define appropriate treatment and remediation actions.
- Perform and oversee detailed Information Security risk assessments, including Risk and Control Self-Assessments (RCSAs); review work completed by team members; and clearly document risk conclusions.
- Execute and operationalize security risk management strategies and frameworks established by Enterprise Risk Management. Maintain and mature security risk frameworks, policies, and standards that guide consistent, enterprise-wide information security risk management practices.
- Oversee third-party Information Security risk management activities, including the vendor security risk assessments, risk analysis, issue escalation, risk acceptance, remediation follow-up, and ongoing monitoring.
- Lead and actively support Information Security control management, including maintaining the control inventory, mapping controls to risks, confirming ownership, improving control documentation, coordinating assessments and testing, evaluating gaps, and monitoring remediation to strengthen control design and operating effectiveness.
- Lead, coach, and develop the Information Security GRC team, including providing hands-on guidance, reviewing and improving work products, clarifying expectations, removing barriers, and directly contributing to complex or time-sensitive work. Establish clear priorities and accountability while building the capabilities of team members with varying levels of experience.
- Develop, maintain, validate, and report risk and compliance metrics, dashboards, and key performance and risk indicators. Ensure supporting information is complete and accurate, identify overdue commitments, and provide execution status, risk insights, and escalation recommendations to the VP, Information Security Risk and Governance and other stakeholders as appropriate.
- Prepare, review, and deliver clear, accurate, and timely risk and compliance reporting for senior leadership, regulators, the Cyber Risk Management Council, and the Board of Directors.
- Serve as the primary Information Security point of contact for NCUA ex
Certifications this role asks for
Studying for one of these? Try the free CISA practice questions or the free CISM practice questions in our academy. No signup, no cost.
Location and market context
This job is based in McLean on-site. Local candidates benefit from being close to PenFed Credit Union's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how PenFed Credit Union would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Manager, Risk Management (Global Payments Network) · Capital One · Richmond, VA, McLean
- Third-Party & Supply Chain Risk Analyst · True Anomaly · Denver, CO, CA or Washington
- Senior, Business Risk & AI Automation · Reddit, Inc. · Canada · Remote
- Senior Data Modeler, Fraud Risk Detection · Experian · United States
- Senior Risk Analyst – Data Science & Analytics · Experian · Mumbai, in
- Credit Risk Manager (F/H) · Younited · Paris
- Risk Manager · GE Vernova · 3 Locations
- IP Security & Risk Leader · GE Vernova · 3 Locations
More GRC jobs in McLean
- Director of Compliance · SteerBridge · Vienna, VA
- Senior Solutions Marketing Lead - Risk, Compliance & Legal · Appian · McLean, Virginia
- Data Catalog and Governance Associate Manager · Accenture Federal Services · Arlington, VA
- Data Strategy and Governance Lead · Accenture Federal Services · Chantilly, VA
- Auditor · Office of the Director of National Intelligence · McLean, Virginia
Hiring for Risk?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Director, Information Security Governance, Risk, and Compliance (GRC) in McLean, VA open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.