Talent.com
Grant Thornton
Director, Information Security Audit & Compliance (Global)Grant Thornton • New York, NY, United States
Director, Information Security Audit & Compliance (Global)

Director, Information Security Audit & Compliance (Global)

Grant Thornton • New York, NY, United States
30+ days ago
Salary
$172,000.00–$258,000.00 yearly
Job type
  • Full-time
Job description

Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below.

We are seeking a Director of Information Security Audit & Compliance to lead and scale a global audit and compliance practice. This role will be responsible for establishing global delivery centers, managing internal and external audits, and ensuring the information security program is governed through a consistent, defensible framework aligned to NIST CSF and NIST 800-53.

The ideal candidate combines deep audit and regulatory expertise with strong operational leadership, enabling the organization to meet regulatory, client, and certification requirements while supporting business growth and innovation.

Key Responsibilities

Audit & Compliance Strategy

  • Define and lead the global information security audit and compliance strategy across the enterprise.
  • Establish and scale global delivery centers to support audits, evidence management, and continuous compliance operations.
  • Own the audit calendar and roadmap for ISO, NIST-based, HIPAA, and client-driven audits.

Audit Management & Execution

  • Lead enterprise-wide audits and assessments including ISO 27001, NIST, HIPAA, and client-specific security audits.
  • Act as the primary point of contact for external auditors, regulators, and client assessors.
  • Ensure timely, high-quality audit deliverables, responses, and remediation plans.

Governance, Risk & Control Framework

  • Align the information security governance program to NIST Cybersecurity Framework (CSF) and NIST 800-53.
  • Develop, maintain, and mature security policies, standards, and control frameworks.
  • Ensure controls are consistently implemented, tested, and evidenced across global teams.

Continuous Compliance & Control Assurance

  • Establish processes for continuous control monitoring, internal testing, and readiness assessments.
  • Track audit findings, remediation efforts, and risk acceptances through closure.
  • Partner with technology, security, and business teams to remediate gaps and strengthen control effectiveness.

Client & Regulatory Engagement

  • Support client due diligence, RFP security responses, and client-led audits.
  • Translate technical and control-based requirements into clear, business-aligned commitments.
  • Build trust with clients by demonstrating a mature, transparent compliance posture.

Leadership & Global Team Development

  • Build, lead, and mentor a globally distributed team of audit and compliance professionals.
  • Define roles, responsibilities, career paths, and training for audit and compliance staff.
  • Foster strong collaboration with security engineering, IT, legal, privacy, and risk teams.

Required Qualifications

  • 12+ years of experience in information security, audit, or compliance, with 5+ years in senior leadership roles.
  • Deep hands-on experience leading ISO 27001, 27701, 27017, NIST, HIPAA, and client-driven security audits.
  • Strong expertise in NIST CSF and NIST 800-53 governance, control design, and assessment.
  • Proven experience building or scaling global audit and compliance delivery models.
  • Strong understanding of information security controls, risk management, and regulatory expectations.
  • Excellent communication skills with the ability to engage executives, auditors, and clients.

Preferred Qualifications

  • Experience operating in global, highly regulated environments.
  • Familiarity with SOC 1 / SOC 2, cloud compliance, and third-party risk assessments.
  • Experience implementing GRC tooling to support audit and compliance workflows.
  • Professional certifications such as CISSP, CISA, CRISC, CISM, ISO 27001 Lead Auditor, or equivalent.

The base salary range for this position is between $172,000 and $250,000. Placement within the pay range is at Grant Thornton’s discretion, and it is based on multiple factors, including but not limited to, job-related knowledge/skills, experience, business needs, progression within the role, geographic location, and internal equity. At Grant Thornton, compensation decisions are dependent upon the facts and circumstances of each position and candidate.

Create a job alert for this search

Director, Information Security Audit & Compliance (Global) • New York, NY, United States

Similar jobs

Senior Director, Ecosystem Security & Product

P2PNew York, NY, United States
Full-time

A blockchain security company is hiring a Senior Director, Ecosystem & Product Security in New York, NY.This role involves defining and leading security strategies across the ecosystem, enhancing t... Show more

 • Promoted

Sr. Director of Architecture - Trust & Security

FairygodbossNew York, NY, United States
Full-time

Join JPMorgan Chase as Senior Director, Architecture within Connected Commerce Technology, leading technology innovation across multiple business and technical domains.Define target state architect... Show more

 • Promoted

Director, Ecosystem Security & Platform Risk

StellarNew York, NY, United States
Full-time

Stellar is seeking a Director, Ecosystem & Product Security to drive security strategy across the Stellar ecosystem and Foundation‑owned systems.You will own security outcomes for treasury and cust... Show more

 • Promoted

Director Information & Analytics

Metropolitan Transportation AuthorityNew York, NY, United States
Full-time

Job Title: Director, Information & Analytics.Department: Office Of Innovation.Salary Range: $136,505–$170,631.Position Classification: Non‑Safety Sensitive.Closing Date: Open Until Filled.Summary: ... Show more

 • Promoted

Chief Information Security Officer - Enterprise Cyber Risk Leader

DataCT LLCNew York, NY, United States
Full-time

DataCT LLC is seeking a Chief Information Security Officer to lead the organization's cybersecurity and risk management efforts.This role involves overseeing compliance frameworks such as Reg SCI, ... Show more

 • Promoted

Director of Security & Compliance

Verse MedicalNew York, NY, United States
Full-time

Director of Security & Compliance.We're hiring a Director of Security & Compliance to own and build our security program.This is a high-impact role where you'll define our security architecture, le... Show more

 • Promoted

Senior Director, Cyber Risk & Security Engineering

CHANELNew York, NY, United States
Full-time

CHANEL is seeking a Group Director of Cyber Risk & Security Engineering to lead security engineering, risk governance, and awareness programs for a global, hybrid environment.The role reports to th... Show more

 • Promoted

Director of Information Security

Collectors UniverseJersey City, NJ, United States
Full-time

Collectors is the leading creator of innovative technology that provides value-added services for collectors worldwide.We grade, authenticate, vault, and sell millions of record-setting collectible... Show more

 • Promoted

Director of LIHTC Compliance

Page GroupYonkers, NY, US
Full-time +1

The VP of LIHTC Compliance will oversee compliance programs and ensure adherence to regulatory requirements within the property industry.This role requires a strategic leader capable of implementin... Show more

 • Promoted

Sr. Director of Architecture - Trust & Security

Next Frontier CapitalNew York, NY, United States
Full-time

If you are ready to lead the way in technology innovation at JPMorganChase, we’ve got an exciting opportunity for a technology leader like you to make a real difference in the industry.As a Senior ... Show more

 • Promoted

Director, Cybersecurity Regulatory Engagement (1LOD)

BNYNew York, NY, United States
Full-time

Director, Cybersecurity Regulatory Engagement (1LOD).Location: New York, NY (Onsite).As an individual contributor within Cybersecurity Governance, Risk & Controls (CGRC), the Director leads first‑l... Show more

 • Promoted

Manager of Information Security and Compliance

ibossNew York, NY, United States
Full-time

Manager Of Information Security & Compliance.Company Overview iboss is a cloud security company that enables the modern workforce to connect securely and directly to all applications from wherever ... Show more

 • Promoted

Regional Cloud Security Sales Director

CrowdStrikeNew York, NY, United States
Full-time

CrowdStrike is seeking a Regional Sales Director in New York City to lead and manage a team of senior sales professionals.The ideal candidate will have over 10 years of experience in solution sales... Show more

 • Promoted

Senior Director, Secure Identity & Fraud Architecture

JPMorgan Chase & Co.New York, NY, United States
Full-time

Senior Director of Architecture to lead technology innovation within Connected Commerce Technology.This role involves defining target architectures, leading core capability architecture, and drivin... Show more

 • Promoted

Chief Information Security Officer – Enterprise Security Leader

The Security Executive CouncilNew York, NY, United States
Full-time

Compass International Holdings seeks a seasoned Chief Information Security Officer to own and evolve the enterprise security program.This executive role balances security strategy with technology a... Show more

 • Promoted

Asia Cybersecurity Operations Director | Hybrid

CitiNew York, NY, United States
Full-time

Asia Cyber Security Operations Lead (Director).Singapore, Singapore, Singapore.Working at Citi is far more than just a job.A career with us means joining a team of more than 230,000 dedicated peopl... Show more

 • Promoted

Platform Security, Managing Director

State StreetClifton, NJ, United States
Full-time

The Platform Security, Managing Director is a senior cybersecurity leader responsible for establishing and scaling a platform-aligned security model that embeds cyber accountability directly within... Show more

 • Promoted

Global IT Audit Leader & VP of Risk & Assurance

BroadridgeNew York, NY, United States
Full-time

Broadridge is seeking a Head of IT Audit in New York, NY to oversee the global technology audit strategy for a large fintech organization.The role involves leading a distributed team, managing risk... Show more

 • Promoted

Director, AI Security & Governance

International Rescue CommitteeNew York, NY, United States
Full-time

The International Rescue Committee is seeking a Director of AI Security to lead a newly created senior leadership role focused on the AI security function.This role combines security engineering, r... Show more

 • Promoted

Global CISO: AI-Driven Security & Cloud Transformation

Barnes & Noble Booksellers, Inc.New York, NY, United States
Full-time

Barnes & Noble Booksellers, Inc.Group Chief Information Security Officer to lead its Information Security program.This role involves developing and implementing a unified cybersecurity strategy, ov... Show more