Job Title: Director, Global Governance, Risk, and Compliance (GRC)
Location: Westerville, OH (On-site)
Reports to: Global Chief Information Security Officer (CISO)
Job Summary
The Director of Global GRC is a critical leadership role responsible for the design, implementation, and management of Vertiv’s information security Governance, Risk Management, and Compliance function. You will serve as the primary architect of our IT Risk Register and the lead coordinator for IT General Controls (ITGC) and SOX compliance.
As a global leader, you will manage a geographically dispersed team, ensuring a unified and aware security posture. This role requires extensive systems knowledge, soft skills, executive presence capable of driving consensus across a diverse, international stakeholder base. It also requires fierce program ownership and accountability.
Key Responsibilities
- Global Team Leadership: Lead, mentor, and develop a high-performing, globally dispersed GRC team. Foster a culture of accountability and follow-through and collaboration across different time zones, languages, and cultural work styles.
- Customer & Sales Enablement: Lead the global process for responding to customer security questionnaires. Maintain, improve and finalize a centralized "Trust Center" to accelerate the sales cycle globally.
- Third-Party Risk Management (TPRM): Build and scale a global vendor risk program covering both Direct and Indirect procurement, ensuring consistency in how we vet global suppliers.
- IT Risk & Vulnerability Governance: Manage the Enterprise IT Risk Register. Translate technical vulnerabilities (scans/pen tests) into business risk terms and remediation trackers for IT leaders.
- SOX & IT General Controls (ITGC): Lead the ITGC program in collaboration with Internal Audit. Ensure Vertiv remains compliant with SOX requirements through continuous monitoring of global controls.
- Security Awareness & Training: Own the global security training strategy, ensuring training materials are culturally relevant and localized where necessary.
- Pentest & Audit Oversight: Serve as the central point of contact for all global security audits. Oversee the tracking and closure of remediation items across all business units.
- Governance Committee Leadership: Lead our Cyber Risk Oversight Committee which is the primary forum for discussing Enterprise Cyber and Compliance risk.
Required Skills & Qualifications
- Experience: 10+ years in Information Security, with 5+ years in a dedicated GRC leadership role.
- Global Leadership: Proven experience managing and scaling globally dispersed teams. Must demonstrate success in leading remote subordinates and maintaining high engagement across disparate geographic regions.
- Regulatory Knowledge: Deep expertise in SOX (ITGC) controls and procedures, NIST CSF, ISO 27001, and GDPR.
- Risk Methodology: Proven track record of managing an Enterprise Risk Register and applying risk-quantification frameworks (e.g., FAIR or NIST 800-30).
- Communication: Exceptional ability to communicate complex security risks to non-technical stakeholders across the globe.
- Strategy, Organization and Accountability: Top notch skills in assessing current state, devilment of roadmap and actions in a qualitative and quantitative manner aligned with CMMI.
- Travel:Ability to travel internationally to Vertiv’s global offices and regional hubs to conduct internal reviews, meet with regional leaders, and support audit activities.
- Certifications: CISM, CRISC, CISA, or CISSP.
- Tooling: Experience implementing GRC platforms (e.g., ServiceNow GRC, OneTrust) on a global scale.
- Education: Bachelor’s degree in Computer Science, Information Technology or Sciences, or related field; Master's preferred.
#LI-RB1