DescriptionThe Director, Enterprise Risk will mature and integrate AppFolio's Enterprise Risk Management (ERM) framework, lead the Technology Compliance function, and build a new Risk Analysis capability - while partnering with first-line teams so that risk management accelerates fast, well-informed decisions rather than constraining them.
Your impact
- Mature and integrate AppFolio's ERM framework and program in partnership with senior leaders and cross-functional stakeholders, and support the Enterprise Risk Committee (ERC) that administers the program.
- Build a new Risk Analysis capability for coordinating risk identification, assessment, and monitoring activities across the business.
- Lead the Technology Compliance team - owning compliance policies, ongoing monitoring, and audit readiness across SOX and SOC reviews, and supporting a Common Controls Framework (CCF).
- Stand up a continuous, rolling risk-identification cadence that surfaces and escalates emerging risks in real time, complementing the annual enterprise risk assessment and the quarterly ERC and RCOC cycles.
- Partner with and enable first-line functions - including R&D (Product and Engineering) - embedding risk-informed decision-making into their workflows so risk is a natural, owned part of moving quickly.
- Assist management with risk-related reporting to the Board, and communicate ERM program updates to the Risk & Compliance Oversight Committee (RCOC).
- Advance the three-lines-of-defense model and the broader GRC strategy, aligning ERM activity, cadence, and Top Risks with the company's operating model and OKRs.
Qualifications
- Extensive experience in enterprise risk management, GRC, internal audit, or a closely related second-line function, including maturing or scaling an ERM program.
- A track record of building and leading teams, developing talent through individual development plans (IDPs), and planning succession for key roles.
- Strong command of enterprise risk frameworks and the three-lines-of-defense model (e.g., COSO ERM), plus working knowledge of technology compliance domains such as SOX ITGCs and SOC 1 / SOC 2.
- Demonstrated ability to influence senior leaders and to communicate risk clearly to executive and Board-level audiences, including audit or risk committees.
- Experience partnering with first-line functions - ideally R&D, Product, or Engineering - to embed risk-informed decision-making without slowing the business.
- A data-driven approach to risk monitoring, including defining risk metrics and enhancing monitoring and reporting capabilities.
- Relevant professional certifications are a plus (e.g., CRISC, CRMA, CISA, CPA, or CISSP).
Must have
- 5+ years of progressive experience in enterprise risk management, internal audit, GRC, or technology compliance, including direct people-leadership experience.
- Deep, hands-on understanding of enterprise risk frameworks and the three-lines-of-defense model, with experience operating or maturing an ERM program.
- Proven ownership of technology compliance and audit readiness (SOX and/or SOC), including serving as a primary liaison to internal and external auditors.
- Excellent executive communication and stakeholder-management skills, with experience reporting to senior leadership and/or a Board committee.
Location
This position is based in our San Diego, CA, or our Santa Barbara office. Find out more about our locations by visiting our site.
All late-stage candidates complete an in-person meeting with an AppFolian as part of our hiring process.
Compensation & Benefits
The compensation that we reasonably expect to pay for this role is: $184,000 - $230,000 base pay. The actual compensation for this role will be determined by a variety of factors, including but not limited to the candidate's skills, education, experience, and internal equity.
Please note that compensation is just one aspect of a comprehensive Total Rewards package. The compensation range listed here does not include additional benefits or any discretionary bonuses you may be eligible for based on your role and/or employment type.
Regular full-time employees are eligible for benefits - see here.
#LI-KB1