Talent.com
Grant Thornton
Director, Information Security Audit & Compliance (Global)Grant Thornton • San Francisco, CA, United States
Director, Information Security Audit & Compliance (Global)

Director, Information Security Audit & Compliance (Global)

Grant Thornton • San Francisco, CA, United States
30+ days ago
Salary
$172,000.00–$258,000.00 yearly
Job type
  • Full-time
Job description

Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below.

We are seeking a Director of Information Security Audit & Compliance to lead and scale a global audit and compliance practice. This role will be responsible for establishing global delivery centers, managing internal and external audits, and ensuring the information security program is governed through a consistent, defensible framework aligned to NIST CSF and NIST 800-53.

The ideal candidate combines deep audit and regulatory expertise with strong operational leadership, enabling the organization to meet regulatory, client, and certification requirements while supporting business growth and innovation.

Key Responsibilities

Audit & Compliance Strategy

  • Define and lead the global information security audit and compliance strategy across the enterprise.
  • Establish and scale global delivery centers to support audits, evidence management, and continuous compliance operations.
  • Own the audit calendar and roadmap for ISO, NIST-based, HIPAA, and client-driven audits.

Audit Management & Execution

  • Lead enterprise-wide audits and assessments including ISO 27001, NIST, HIPAA, and client-specific security audits.
  • Act as the primary point of contact for external auditors, regulators, and client assessors.
  • Ensure timely, high-quality audit deliverables, responses, and remediation plans.

Governance, Risk & Control Framework

  • Align the information security governance program to NIST Cybersecurity Framework (CSF) and NIST 800-53.
  • Develop, maintain, and mature security policies, standards, and control frameworks.
  • Ensure controls are consistently implemented, tested, and evidenced across global teams.

Continuous Compliance & Control Assurance

  • Establish processes for continuous control monitoring, internal testing, and readiness assessments.
  • Track audit findings, remediation efforts, and risk acceptances through closure.
  • Partner with technology, security, and business teams to remediate gaps and strengthen control effectiveness.

Client & Regulatory Engagement

  • Support client due diligence, RFP security responses, and client-led audits.
  • Translate technical and control-based requirements into clear, business-aligned commitments.
  • Build trust with clients by demonstrating a mature, transparent compliance posture.

Leadership & Global Team Development

  • Build, lead, and mentor a globally distributed team of audit and compliance professionals.
  • Define roles, responsibilities, career paths, and training for audit and compliance staff.
  • Foster strong collaboration with security engineering, IT, legal, privacy, and risk teams.

Required Qualifications

  • 12+ years of experience in information security, audit, or compliance, with 5+ years in senior leadership roles.
  • Deep hands-on experience leading ISO 27001, 27701, 27017, NIST, HIPAA, and client-driven security audits.
  • Strong expertise in NIST CSF and NIST 800-53 governance, control design, and assessment.
  • Proven experience building or scaling global audit and compliance delivery models.
  • Strong understanding of information security controls, risk management, and regulatory expectations.
  • Excellent communication skills with the ability to engage executives, auditors, and clients.

Preferred Qualifications

  • Experience operating in global, highly regulated environments.
  • Familiarity with SOC 1 / SOC 2, cloud compliance, and third-party risk assessments.
  • Experience implementing GRC tooling to support audit and compliance workflows.
  • Professional certifications such as CISSP, CISA, CRISC, CISM, ISO 27001 Lead Auditor, or equivalent.

The base salary range for this position is between $172,000 and $250,000. Placement within the pay range is at Grant Thornton’s discretion, and it is based on multiple factors, including but not limited to, job-related knowledge/skills, experience, business needs, progression within the role, geographic location, and internal equity. At Grant Thornton, compensation decisions are dependent upon the facts and circumstances of each position and candidate.

Create a job alert for this search

Director, Information Security Audit & Compliance (Global) • San Francisco, CA, United States

Similar jobs

Director, Compliance Risk

QcellsSan Francisco, CA, United States
Full-time

EnFin is a financial services company that provides financing for residential solar PV and energy efficiency upgrades, backed by Qcells.We are seeking a strategic, execution-oriented Director, Comp... Show more

 • Promoted

Sr. Director, Security

ZapierSan Francisco, CA, United States
Full-time

At Zapier, we build and use automation every day to make work more efficient, creative, and human.If you're using AI tools while applying here, that's great! We just ask that you use them responsib... Show more

 • Promoted

Senior Director of Internal Audit & SOX Compliance

BitGoSan Francisco, CA, United States
Full-time

BitGo is seeking an Audit Manager to oversee Sarbanes-Oxley compliance and manage SOC audits from our San Francisco office.The ideal candidate has 10+ years of experience in audit and a strong unde... Show more

 • Promoted

Specialist Director, Managed Security Testing

KPMGSan Francisco, CA, US
Full-time

The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG.Looking ahead, we anticipate cont... Show more

 • Promoted

Director, Control Room Compliance

Royal Bank of CanadaSan Francisco, CA, United States
Full-time

Information Barriers Specialist.This role is responsible for maintaining the firm's Information Barriers to restrict the improper flow of information and prevent the misuse of material non-public i... Show more

 • Promoted

Director - Governance, Risk, Compliance & Privacy (GRC)

Beacon SoftwareSan Francisco, CA, United States
Full-time

Beacon is acquiring and operating a portfolio of vertical SaaS companies.Most private equity firms scale by adding people.We are building Beacon to scale by adding software.The thesis is simple: po... Show more

 • Promoted

Security Compliance Manager

HiveSan Francisco, CA, United States
Full-time

We are looking for a highly motivated Security Compliance Manager with a deep security and compliance background to lead system development and process improvement.As part of Hive's Security Team, ... Show more

 • Promoted

Director, Artificial Intelligence Compliance

Charles Schwab Inc.San Francisco, CA, United States
Full-time

At Schwab, you're empowered to make an impact on your career.Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry togeth... Show more

 • Promoted

Senior Director, Cloud Security, Compliance Lead

Lila SciencesSan Francisco, CA, United States
Full-time

Senior Director, Cloud Security, Compliance Lead.Cloud Security & Compliance Lead is responsible for the end-to-end security, governance, risk management, and regulatory compliance of Lila Sciences... Show more

 • Promoted

Director, Control Room Compliance

RBCSan Francisco, CA, United States
Full-time

Information Barriers Specialist.This role is responsible for maintaining the firm's Information Barriers to restrict the improper flow of information and prevent the misuse of material non-public i... Show more

 • Promoted

Senior Director, Compliance

GoFundMeSan Francisco, CA, United States
Full-time

GoFundMe is the world's most powerful community for good, dedicated to helping people help each other.By uniting individuals and nonprofits in one place, GoFundMe makes it easy and safe for people ... Show more

 • Promoted

Compliance Director

AltruistSan Francisco, CA, United States
Full-time

Altruist is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals.We partner with financial advisors nationwide, empowering them to g... Show more

 • Promoted

Director of IT - Oakland, CA

G2 Venture PartnersOakland, CA, United States
Full-time

Infrastructure & Security People Manager.MISUMI Americas Global (US / India / China / Mexico) Team of ~14 Up to 10% travel US citizen or permanent resident.MISUMI Americas is the product of tw... Show more

 • Promoted

Director of Governance, Risk, and Compliance

EliseAISan Francisco, CA, United States
Full-time

Director Of Governance, Risk, And Compliance (Grc).At EliseAI, we're improving the industries that matter most: housing and healthcare.Everyone needs a place to live and access to quality healthcar... Show more

 • Promoted

Head of Internal Audit & SOX Compliance

BitGo, Inc.San Francisco, CA, United States
Full-time

Head of Internal Audit to manage the company's audit program during a significant growth phase.Located in San Francisco, this role requires a seasoned audit leader who has extensive experience in S... Show more

 • Promoted

Director, Ecosystem Product Security

Stellar Development FoundationSan Francisco, CA, United States
Full-time

Director, Ecosystem & Product Security.Interested in working on cutting-edge blockchain technology and creating equitable access to the global financial system? Since 2014, the mission-driven team ... Show more

 • Promoted

Senior Manager, Internal Audit - Technology, AI, Security and Privacy Audit

IntuitSan Francisco, CA, United States
Full-time

Senior Manager, Technology Audit.We are seeking a highly motivated and experienced Senior Manager of Technology Audit to join our team.This role is crucial in leading and executing complex technolo... Show more

 • Promoted

Director, Quality Compliance and Audits

Gilead SciencesSan Mateo, CA, United States
Full-time

Director, Quality Compliance And Audits (Qca).At Gilead, we're creating a healthier world for all people.For more than 35 years, we've tackled diseases such as HIV, viral hepatitis, COVID-19 and ca... Show more

 • Promoted

Director of Information Governance

Lewis BrisboisSan Francisco, CA, United States
Full-time

Director Of Information Governance.The San Francisco, CA office of Lewis Brisbois, a full-service AmLaw 100 firm, is seeking a Director of Information Governance.The Director of Information Governa... Show more

 • Promoted

Director, R&D Information Systems

GileadSan Mateo, CA, United States
Full-time

Director, R&D Information Systems.At Gilead, we're creating a healthier world for all people.For more than 35 years, we've tackled diseases such as HIV, viral hepatitis, COVID-19 and cancer workin... Show more