FreshRemote.Work

Director, Security Governance, Risk, and Compliance

Remote - USA

The Mission and The Challenge

Reporting to the CISO, The Director of Cybersecurity Governance, Risk, and Compliance is responsible for managing and overseeing HubSpot's cybersecurity risk landscape. This role will lead the development and implementation of a robust cybersecurity governance framework, identify and assess risks, and ensure compliance with relevant laws, regulations, and industry standards.

Responsibilities 

  • Lead functions related to cybersecurity risk management and compliance, shaping strategic vision for HubSpot’s risk program and continually improving HubSpot’s program in response to changing threats and industry trends.
  • Operationalize GRC capability areas including policy and exception management, security awareness and training, maturity assessment, external audits, enterprise security risk management, compliance management, business continuity, and disaster recovery.
  • Develop and oversee the governance structure for integrating cyber risk into the enterprise risk management framework. Ensure cyber risks are aligned with overall business risks and priorities and that appropriate risk mitigation strategies are in place with a governance framework that supports risk-based decision-making and prioritization.
  • Collaborate with risk management, legal, finance, and other functional teams to ensure that cyber risks are consistently evaluated and integrated into the broader enterprise risk assessments, including financial, operational, and strategic risks.
  • Establish key metrics and reporting mechanisms to regularly update leadership on the organization’s cyber risk posture and mitigation effectiveness. Provide clear, actionable reporting that connects cyber risks to business outcomes and organizational objectives.
  • Promote a culture of Security, Risk, and Compliance awareness through organization-wise forums, regular communications, and a robust Security/Risk awareness/training program.
  • Develop and deliver the GRC strategic roadmap and investment plan addressing People, Process, and Technology.

Qualifications

  • 10+ years experience in cybersecurity governance, risk, and compliance, including 5+ years of management and leadership experience (managing people, projects, budgets, and processes).
  • Proven track record of promoting and collaborating on risk and compliance policies and practices across IT and organizational business units.
  • Strong understanding of cybersecurity risk frameworks and industry standards and regulations (NIST, SOX, PCI, ISO, GDPR, CCPA, HITRUST, etc.), including the ability to lead the execution and implementation of frameworks and articulate their value and purpose.
  • Experience developing, tracking, and reporting key KRIs and KPIs.
  • Strong organizational, project management, communication, and stakeholder management skills, particularly at the executive leadership level.
  • Ability to determine and set the strategic direction of the Cybersecurity GRC function(s), including managing expectations and delivering results with professionalism, self-motivation, and integrity.
  • Understanding of cybersecurity risk management and control principles, with a proven ability to anticipate and identify risks and effective mitigating actions.
  • Experience working with FAIR (Factor Analysis of Information Risk) Framework for quantitative cybersecurity risk analysis and measurement.

Cash compensation range: 228000-342000 USD Annually

This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.

The cash compensation above includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are based on a few different factors unique to each candidate, including their skills, experience, qualifications and other job-related reasons.

We know that benefits are also an important piece of your total compensation package. To learn more about what’s included in total compensation, check out some of the benefits and perks HubSpot offers to help employees grow better.

At HubSpot, fair compensation practices isn’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.

If you need accommodations or assistance due to a disability, please reach out to us using this form. This information will be treated as confidential and used only for the purpose of determining an appropriate accommodation for the interview process.

At HubSpot, we value both flexibility and connection. Whether you’re a Remote employee, or work from the Office, we want you to start your journey here by building strong connections with your team and peers. 

If you are joining our Engineering team in a full-time role, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you’ll also attend other in-person events such as HubSpot’s annual PEER week, your Product Group Summit, and other in-person gatherings to continue building on those connections.

If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements.

Germany Applicants: (m/f/d) - link to HubSpot's Career Diversity page here.

India Applicants: link to HubSpot India's equal opportunity policy here.

About HubSpot

HubSpot (NYSE: HUBS) is a leading customer relationship management (CRM) platform that provides software and support to help businesses grow better. We build marketing, sales, service, and website management products that start free and scale to meet our customers’ needs at any stage of growth. We’re also building a company culture that empowers people to do their best work. If that sounds like something you’d like to be part of, we’d love to hear from you.

You can find out more about our company culture in the HubSpot Culture Code, which has more than 5M views, and learn about our commitment to creating a diverse and inclusive workplace, too. Thanks to the work of every employee globally, HubSpot was named the #2 Best Place to Work on Glassdoor in 2022 and has been recognized for its award-winning culture by Great Place to Work, Comparably, Fortune, Entrepreneur, Inc., and more.

Headquartered in Cambridge, Massachusetts, HubSpot was founded in 2006. Today, thousands of employees across the globe work remotely and in HubSpot offices. Visit our careers website to learn more about the culture and opportunities at HubSpot. 

By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. HubSpot's Privacy Notice explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over HubSpot’s use of your personal information. 

Apply

Job Profile

Regions

North America

Countries

United States

Benefits/Perks

Annual bonus Annual bonus targets Benefits and perks Bonus Targets Cash compensation Connection Equity plan Flexibility Inclusive workplace In-person events In-person onboarding On-target commission Overtime pay Restricted Stock Units Total compensation package

Tasks
  • Collaborate with functional teams
  • Develop governance framework
  • Ensure compliance
  • Ensure compliance with laws and regulations
  • Establish metrics and reporting mechanisms
  • Manage cybersecurity risk landscape
  • Project management
  • Promote security awareness
Skills

Analysis Business Continuity Communication Compensation Compliance CRM Customer Relationship Management Cybersecurity Disaster Recovery Engineering Enterprise Security Risk Management External audits Fair Factor Analysis Finance Frameworks Governance Framework GRC Hubspot Leadership Legal Compliance Management Marketing Maturity Assessment Metrics Reporting NIST Onboarding Organization Organizational Policy Management Prioritization Project Management Recruiting Relationship Management Reporting Risk Management Risk mitigation Sales Security Security Awareness Software SOX Stakeholder management Strategic vision Technology Training Website management

Experience

10 years

Education

Business Engineering Finance Marketing

Certifications

CCPA GDPR HITRUST ISO NIST PCI SOX

Timezones

America/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9