Intuitive Surgical, Inc

IT Sr Director, Compliance and Risk Governance

Intuitive Surgical, Inc$175K — $210K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, or related field.
  • 12+ years of leadership experience in cybersecurity and risk management.
  • 7+ years managing enterprise-scale cybersecurity GRC programs.
  • Deep expertise in regulatory compliance and industry frameworks.
  • Exceptional communication and stakeholder management skills.

Responsibilities

  • Define and implement the cybersecurity governance framework.
  • Lead risk management initiatives to identify and mitigate cybersecurity risks.
  • Establish compliance programs with regulatory standards.
  • Oversee third-party cybersecurity risk assessments and management.
  • Serve as an advisor to senior leadership on governance and compliance matters.

Benefits

  • Market-competitive compensation packages, including base pay and incentives.
  • Opportunity to lead and develop a high-performing cybersecurity team.
  • Engagement with senior leadership on strategic decision-making.
  • Involvement in transformative initiatives for process modernization.
  • Support for continuous improvement and professional development.
Full Job Description
Primary Function of Position:
Responsible for providing strategic leadership and oversight of the enterprise
Cybersecurity Governance, Risk, and Compliance (GRC) program. This role
establishes the vision, operating model, and governance framework necessary to
effectively identify, assess, manage, and communicate cybersecurity and
technology risks across the organization. Serves as a trusted advisor to senior
leadership, business stakeholders, and technology teams, ensuring that
cybersecurity risk management practices align with organizational objectives,
regulatory requirements, and industry best practices. This leader drives a risk-
informed culture and enables the business to innovate securely while maintaining
compliance and operational resilience.
Roles & Responsibilities

Cybersecurity Governance
Define, implement, and continuously mature the enterprise cybersecurity
governance framework, including policies, standards, procedures, and
oversight mechanisms.
Establish strategic direction for cybersecurity governance, ensuring
alignment with corporate objectives, risk appetite, and business priorities.
Lead governance forums, steering committees, and executive reviews to
drive accountability and informed decision-making.
Develop and monitor key performance indicators (KPIs), key risk
indicators (KRIs), and executive dashboards that measure program
effectiveness and organizational risk posture.
Drive governance modernization initiatives through automation, process
optimization, and data-driven decision support.
Enterprise Risk Management
Lead the enterprise cybersecurity risk management program, ensuring
risks are identified, assessed, prioritized, mitigated, and monitored
effectively.
Develop risk assessment methodologies and reporting frameworks that
provide actionable insights to executive leadership.
Partner with business and technology leaders to implement risk mitigation
strategies that balance security, operational efficiency, and business
objectives.

Facilitate enterprise-level risk discussions and support
strategic decision-making by translating technical and cyber risks into
business-relevant impacts.
Compliance Oversight
Establish and maintain programs to ensure compliance with applicable
regulations, standards, and industry frameworks, including ISO 27001,
ISO 27036, NIST Cybersecurity Framework (CSF), as well as other
relevant frameworks such as AI risk management.
Lead internal and external audits, assessments, and regulatory reviews.
Ensure remediation activities are effectively managed and tracked through
closure.
Monitor emerging regulatory requirements and industry developments,
advising leadership on compliance obligations and risk implications.
Third-Party Risk Management
Establish and oversee governance processes for evaluating and
monitoring third-party cybersecurity and technology risks.
Collaborate with Procurement, Legal, Privacy, and business stakeholders
to assess vendor security posture and contractual risk requirements.
Drive continuous improvement of supplier risk management practices to
support organizational resilience and compliance objectives.
Engagement & Business Partnership

Serve as key advisor to senior leadership on cybersecurity
risk, governance, and compliance matters.
Provide clear, concise, and impactful reporting to executive leadership and
governance bodies.
Influence strategic business initiatives by integrating security, risk, and
compliance considerations into planning and execution activities.
Foster strong partnerships across business functions to promote risk-
aware decision-making and regulatory readiness.
Leadership & Organizational Development
Build, lead, and develop a high-performing team of cybersecurity
governance, risk, and compliance professionals.
Establish organizational goals, resource strategies, and performance
expectations aligned with enterprise priorities.
Manage departmental budgets, strategic planning activities, and program
investments.
Champion a culture of accountability, transparency, continuous
improvement, and risk awareness throughout the organization

Qualifications

Skills, Experience, Education, & Training:
Bachelor's degree in Cybersecurity, Information Technology, Information
Systems, Computer Science, Business Administration, or a related
discipline.

12+ years of progressive leadership experience in
cybersecurity, information security, governance, risk management,
compliance, or related disciplines.
7+ years of experience leading enterprise-scale cybersecurity GRC
programs and teams.
Demonstrated success developing and executing enterprise governance
and risk management strategies within complex, highly regulated
environments.
Experience presenting cybersecurity risk, compliance, and governance
topics to executive leadership, senior management, and governance
committees.
Proven track record of leading external audits, regulatory assessments,
and compliance initiatives.
Deep expertise in cybersecurity governance, enterprise risk management,
regulatory compliance, and industry frameworks.
Strong understanding of cybersecurity standards and frameworks,
including ISO 27001, ISO 27036, ISO 42001, NIST CSF, NIST AI RMF,
CSA AISMM, and related control frameworks.
Exceptional executive communication, stakeholder management, and
influencing skills.
Ability to translate complex technical concepts into clear business-focused
recommendations

Strong strategic thinking, analytical, problem-solving, and
organizational leadership capabilities.
Experience driving organizational transformation, process modernization,
and program maturity initiatives.
Preferred certifications:
o CISSP
o CISM
o CRISC
o CISA

Additional Information

Due to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19. Details can vary by role.

This position may be filled at a different job level than listed here depending on
business need and/or on the selected candidate's experience, knowledge and skills.
Compensation will be based primarily on the job level at which the role is filled and the
candidate's qualifications, consistent with applicable law.

We provide market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity. It would not be typical for someone to be hired at the top end of range for the role, as actual pay will be determined based on several factors, including experience, skills, and qualifications. The target compensation ranges are listed.

About Intuitive Surgical, Inc

Intuitive Surgical, Inc. is an American corporation that develops, manufactures, and markets robotic products designed to improve clinical outcomes of patients through minimally invasive surgery, most notably with the da Vinci Surgical System. The company is part of the NASDAQ-100 and S&P 500. Intuitive Surgical has installed more than 5,000 surgical systems worldwide, and has more than 4,000 employees.
Learn more about Intuitive Surgical, Inc
Size
9,793 employees
Market Cap
$93.6 billion
Industry
Net Income
$1 billion
Founded
1999
5 Year Trend
+16.1%
Revenue
$4.3 billion
NASDAQ

Similar Jobs

More Jobs at Intuitive Surgical, Inc

More Information Technology Jobs

Find similar IT Sr Director, Compliance and Risk Governance jobs: