Jobs › California › San Francisco Bay Area › Senior Director, GRC
Senior Director, GRC
Okta is hiring for the job of Senior Director, GRC, San Francisco, California (On-site). This is a Governance job in the governance, risk, and compliance field, with a posted range of $264,000. Review the full details below and apply directly with Okta.
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We re all in on this mission. If you are too, let s talk.
Position Overview:
We are seeking a visionary Senior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We don t view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist, we build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta’s workforce, taking direct responsibility for cyber risk, data governance, security compliance and product certifications to enable Okta to ship world class, secure products.
You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset, pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures.
This is not just a leadership role. This is a builder’s role.
Key Responsibilities:
Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness).
Enterprise Risk and Governance: Operationalize Okta’s AI risk and governance framework, addressing training data protection, model risk management, responsible AI principles, and alignment with emerging frameworks (NIST AI RMF, ISO/IEC 42001, and the EU AI Act).
Enterprise Cyber Risk Management: Lead enterprise-wide cyber risk identification, prioritization, treatment, and quantification
Regulatory and Compliance Assurance: Maintain and expand Okta’s global compliance posture across major security and privacy frameworks, including SOC 1/2/3, ISO 27001/ENS High/MS DPR/PCI-DSS/CSA STAR/HDS
Policy and Governance Lifecycle: Ensure our corporate information security policies and control standards to reflect evolving business priorities and emerging threats.
Third-Party and SaaS Risk Governance: Direct high-impact vendor risk assessment programs, ensuring third-party SaaS tools and supply chain risks meet Okta’s stringent security controls program.
Audit Management and Remediation: Serve as the primary executive lead for internal/external audits, customer assurances, and regulatory reviews. Drive rapid, engineering-led remediation of audit findings and control gaps.
Cross-Functional Partnership: Collaborate closely with Product Management, Legal, Privacy, Infrastructure, and Business Technology teams to align compliance requirements with product roadmaps and commercial objectives.
Requirements strong:
Proven Executive Leadership: 10+ years of progressive leadership in Security GRC within a high-growth SaaS, cloud-first, or enterprise technology environment.
AI Governance Expertise: Demonstrated understanding of AI/ML governance challenges, including generative and agentic AI security, data lineage and global AI regulatory landscapes.
Mastery of Security Frameworks: Extensive track record managing compliance for enterprise cloud environments
Risk Quantification Skills: Deep knowledge of risk management methodologies and the ability to translate complex technical risks into operational context for executives.
Team Scale and Mentorship: Track record of recruiting, mentoring, and retaining high-performing, technical GRC engineering and risk management professionals.
Education and Certifications: Bachelor s degree in Computer Science, Information Security, Engineering, or equivalent experience.
# -CH1
#P25608_3520635
The annual base salary range for this position for candidates located in the San Francisco Bay area is between:
span $264,000 span span $363,000 USD
span 400; Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: a span 400; https://rewards.okta.com/us span 400;.
The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:
span $236,000 span span $325,000 USD
The Okta Experience
a Supporting Your Well-Being
a Driving Social Impact
a Developing Talent and Fostering Connection + Community
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please a use this Form to request an accommodation.
Notice for New York City Applicants and Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please a click here to view our full NYC AEDT Notice.
Location and market context
This job is based in San Francisco on-site. Local candidates benefit from being close to Okta's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About governance jobs
Governance jobs design the structures, policies, and oversight that keep complex programs accountable, coordinating across legal, risk, compliance, and technology. Jobs like this one are typically evaluated against frameworks such as governance frameworks, policy standards, and oversight and reporting practices.
How to position yourself for this governance job
Strong candidates emphasize policy and standard-setting, committee and stakeholder coordination, oversight reporting, and translating strategy into durable operating structures. In your resume and outreach, tie your experience to how Okta would apply governance frameworks, policy standards, and oversight and reporting practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Lead, Security Controls Assurance - SOX · Anthropic · San Francisco, CA, WA New York City
- Senior GRC Analyst · Gusto · San Francisco, CA
- Product Manager, Multi-Cloud Trust & Safety · Anthropic · San Francisco, CA, NY Seattle
- KYC Investigator - Ongoing Due Diligence · Mercury · San Francisco, CA, New York · Remote
- Senior Customer Support Controls & Governance Program Manager · Mercury · San Francisco, CA, New York · Remote
- Accounting, Revenue Internal Controls · Anthropic · San Francisco, CA, WA
- Product Marketing Manager, IT Admin and Governance · Openai · San Francisco
- Threat Intel Manager, Model Exploitation & Fraud · Anthropic · San Francisco, CA
More jobs at Okta
- Staff Identity Governance and Access Engineer · Okta · Bellevue, Washington
- Corporate Counsel, U.S. Federal, Defense and National Security Compliance · Okta · New York, NY
- Director, Corporate Counsel - Privacy · Okta · Dublin, Ireland
More GRC jobs in San Francisco
- ERM Compliance Lead · Brex · San Francisco, California
- Privacy Counsel · Anthropic · San Francisco, CA, NY
- Security Compliance Lead · Asana · San Francisco
- Legal Program Manager (Regulatory Compliance) · Openai · San Francisco
- Security Risk Engineer · Asana · San Francisco
- Staff Data Scientist - Risk ML · Mercury · San Francisco, CA, New York · Remote
Hiring for Governance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Senior Director, GRC in San Francisco, California open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.