Director of Governance, Risk and Compliance - Global jobs in United States
cer-icon
Apply on Employer Site
company-logo

Ashley Furniture Industries ยท 16 hours ago

Director of Governance, Risk and Compliance - Global

Ashley Furniture Industries, Inc. is the largest manufacturer of furniture in the world. The Director of Governance, Risk and Compliance will develop and execute a comprehensive global GRC strategy, ensuring compliance with regulations and managing risks across the organization.

FurnitureManufacturing
check
H1B Sponsor Likelynote

Responsibilities

Develop and execute a comprehensive global GRC strategy aligned with organizational objectives, risk appetite, and business growth initiatives
Lead strategic GRC leadership initiatives including the development of executive risk dashboards and board-level risk reporting systems
Establish and maintain cyber risk reporting and metrics to be shared with the CISO
Direct the development, implementation, and ongoing improvement of GRC frameworks, measurement tools, and reporting mechanisms
Partner with business units to identify, assess, and prioritize key information security risks across all global operations
Ensure global compliance with all relevant regulations and standards including HIPAA, PCI-DSS, CCPA, NIST CSF, and SOC 2
Manage audit and regulatory readiness programs, ensuring timely closure of audit issues and continuous improvement of internal controls
Monitor legislative and regulatory changes affecting the business across all international markets
Serve as the key liaison with auditors, and third-party partners during security assessments or investigations
Direct third-party and vendor risk management programs, including comprehensive vendor control validation frameworks
Oversee vendor reassessment processes and coordinate external audits to ensure compliance with organizational standards
Partner with legal, procurement, and business teams to assess and mitigate third-party risks
Establish governance frameworks for vendor relationship management and ongoing risk monitoring
Partner with Vendor Management team to ensure Vendor Risk management is embedded in their processes
Oversee global vulnerability management programs including vulnerability assessment, patch management, and remediation tracking to ensure timely resolution of security exposures across enterprise assets
Lead enterprise-wide vulnerability scanning initiatives and coordinate with Cybersecurity teams to maintain comprehensive asset inventories
Establish vulnerability management SLA compliance metrics and drive continuous improvement in remediation timelines
Direct the implementation of automated patch management systems and ensure critical security updates are deployed within established timeframes
Lead policy and compliance management including policy creation, incident response protocols, crisis management procedures, and secure SDLC governance
Establish and enforce corporate policies, ethics programs, and training related to governance and compliance
Foster an organizational culture of accountability, transparency, and ethical business conduct
Drive continuous improvement initiatives across all GRC processes and procedures
Partner with legal, risk, audit, IT, operations, and business unit teams to protect organizational assets and reputation globally
Collaborate with executive leadership to ensure GRC considerations are integrated into strategic business decisions
Build and maintain relationships with internal and external stakeholders, including board members, regulators, and business partners
Translate complex regulatory and risk requirements into practical business guidance

Qualification

GRC strategy developmentRisk management frameworksRegulatory complianceVendor risk managementVulnerability managementCybersecurity collaborationAudit readinessPolicy managementStakeholder relationship managementContinuous improvementEthical business conductCross-functional collaboration

Required

Develop and execute a comprehensive global GRC strategy aligned with organizational objectives, risk appetite, and business growth initiatives
Lead strategic GRC leadership initiatives including the development of executive risk dashboards and board-level risk reporting systems
Establish and maintain cyber risk reporting and metrics to be shared with the CISO
Direct the development, implementation, and ongoing improvement of GRC frameworks, measurement tools, and reporting mechanisms
Partner with business units to identify, assess, and prioritize key information security risks across all global operations
Ensure global compliance with all relevant regulations and standards including HIPAA, PCI-DSS, CCPA, NIST CSF, and SOC 2
Manage audit and regulatory readiness programs, ensuring timely closure of audit issues and continuous improvement of internal controls
Monitor legislative and regulatory changes affecting the business across all international markets
Serve as the key liaison with auditors, and third-party partners during security assessments or investigations
Direct third-party and vendor risk management programs, including comprehensive vendor control validation frameworks
Oversee vendor reassessment processes and coordinate external audits to ensure compliance with organizational standards
Partner with legal, procurement, and business teams to assess and mitigate third-party risks
Establish governance frameworks for vendor relationship management and ongoing risk monitoring
Partner with Vendor Management team to ensure Vendor Risk management is embedded in their processes
Oversee global vulnerability management programs including vulnerability assessment, patch management, and remediation tracking to ensure timely resolution of security exposures across enterprise assets
Lead enterprise-wide vulnerability scanning initiatives and coordinate with Cybersecurity teams to maintain comprehensive asset inventories
Establish vulnerability management SLA compliance metrics and drive continuous improvement in remediation timelines
Direct the implementation of automated patch management systems and ensure critical security updates are deployed within established timeframes
Lead policy and compliance management including policy creation, incident response protocols, crisis management procedures, and secure SDLC governance
Establish and enforce corporate policies, ethics programs, and training related to governance and compliance
Foster an organizational culture of accountability, transparency, and ethical business conduct
Drive continuous improvement initiatives across all GRC processes and procedures
Partner with legal, risk, audit, IT, operations, and business unit teams to protect organizational assets and reputation globally
Collaborate with executive leadership to ensure GRC considerations are integrated into strategic business decisions
Build and maintain relationships with internal and external stakeholders, including board members, regulators, and business partners
Translate complex regulatory and risk requirements into practical business guidance

Benefits

Health, Dental, Vision, Employee Assistance Program
Paid Vacation, Holidays, and Your Birthday off
Generous Employee Discount on home furnishings
Professional Development Opportunities
Ashley Wellness Centers (location specific) and Medical Tourism
Telehealth
401(k) and Profit Sharing
Life Insurance

Company

Ashley Furniture Industries

company-logo
Ashley Furniture Industries is the furniture manufacturer, delivering home furnishing values, stylish furnishings, and home decor.

H1B Sponsorship

Ashley Furniture Industries has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (21)
2024 (24)
2023 (19)
2022 (40)
2021 (39)
2020 (23)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Richard Teachout
Chief Technology Officer
linkedin
Company data provided by crunchbase