Startups

Director, Governance, Risk & Compliance

Anomali · Redwood City, CA · Hybrid

← All jobs
About Anomali

Discover how Anomali uses AI-driven threat intelligence and a powerful security operations platform to improve visibility, detection and cyber resilience. Backed by General Catalyst, GV and IVP.

About the role

Anomali is scaling its compliance program to support an AI-native cybersecurity platform used by governments and enterprises worldwide. We're looking for a hands-on GRC leader who can own and drive our multi-jurisdiction certification portfolio — spanning U.S. federal (FedRAMP), global (ISO 27001, SOC 2), and regional cloud security frameworks (UAE DESC, Saudi Arabia NCA/CCC, Australia IRAP) — while building the scalable compliance infrastructure to support continued international expansion.

What they're looking for

  • 8+ years in GRC, information security compliance, or related audit/assurance roles, with 3+ years in a leadership capacity
  • Direct, hands-on experience with FedRAMP (Moderate or High) as a CSP-side practitioner — not just advisory
  • Demonstrated ownership of ISO 27001 certification and ongoing ISMS management
  • Demonstrated ownership of SOC 2 Type II audits, from readiness through report delivery
  • Experience with at least one Middle East cloud security framework (DESC, Saudi NCA/CCC, or equivalent)
  • Familiarity with Australia IRAP assessment process
More about this role

Anomali, headquartered in Silicon Valley, delivers the first Intelligence-Native Agentic SOC Platform — unifying a security data lake, the world's largest IOC repository, threat intelligence, and agentic AI into a single modern experience. The platform accelerates detection, investigation, and response, delivering earlier insights, faster action, and scalable modernization across any environment.

Whether augmenting existing tools or delivering complete SOC capabilities end-to-end, Anomali empowers security teams to operate faster, smarter, and with confidence.

Learn more at www.anomali.com

Anomali is scaling its compliance program to support an AI-native cybersecurity platform used by governments and enterprises worldwide. We're looking for a hands-on GRC leader who can own and drive our multi-jurisdiction certification portfolio — spanning U.S. federal (FedRAMP), global (ISO 27001, SOC 2), and regional cloud security frameworks (UAE DESC, Saudi Arabia NCA/CCC, Australia IRAP) — while building the scalable compliance infrastructure to support continued international expansion.

This is a builder role, not a maintainer role. You'll be the single point of accountability for keeping...

Read the full posting on Anomali's site ↗

CEO/Legal

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.