Nutanix

Senior Director, Governance, Risk & Compliance

Nutanix • $308K — $462K *
Enterprise Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 15+ years leading information security, GRC, or data protection in a large organization (>3000 FTEs).
  • Proven track record in maturing GRC and Data Security functions, including governance and operating models.
  • Expertise in modern compliance frameworks and translating them into technical controls.
  • Deep knowledge of Data Security and AI Security best practices.
  • Experience in a matrixed environment ensuring alignment between risk requirements and technical execution.
  • Strong executive presence with the ability to influence diverse stakeholders.
  • Excellent communication skills to simplify complex cyber risk concepts.

Responsibilities

  • Optimize and enhance GRC and Data Security functions with refined charters and risk appetites.
  • Enforce security principles tailored for GenAI and data environments.
  • Improve centralized visibility into enterprise risk and compliance through automation.
  • Lead a high-performing global team to enhance collaboration with technical execution teams.
  • Act as a primary business partner to security engineering, translating priorities into requirements.
  • Review and approve enterprise architecture designs ensuring alignment with compliance mandates.
  • Streamline the security and risk review process making it efficient and automated.

Benefits

  • Hybrid work arrangement, requiring office presence 3 days a week.
  • Opportunity to influence and drive strategic security initiatives at a high level.
  • Access to comprehensive medical, financial, and other benefits, including a 401(k).
  • Possibility of additional compensation elements like sign-on bonuses and stock options.
  • Engagement in a collaborative work culture focused on innovation and security excellence.
Full Job Description
The Opportunity: This role reports to the Chief Information Security Officer

Nutanix is maturing its security organization to stay ahead of an evolving digital landscape. We are seeking a pragmatic, strategic, and highly credible Head of Enterprise Security to lead our Governance, Risk, and Compliance (GRC), and Data Security with a clear focus on AI Security and Governance.

This role operates in a highly collaborative partnership model. Working in lockstep with our Head of Security Engineering, you will own the strategic "what and why" - defining the company's risk appetite, compliance requirements, AI policies, and data guardrails. You will rely on your engineering partners to deliver the architectural "how," ensuring that technical designs map directly to your risk and compliance mandates.

The successful candidate will be a master translator: capable of turning complex regulatory and cyber risk concepts into actionable requirements for engineering teams, while simultaneously explaining technical risk posture to executive leadership and the board.

About the Team:

This team is responsible for leading and continuously optimizing a centralized GRC, Data, and AI Security function that defines the enterprise risk landscape, sets the guardrails for secure innovation, and partners seamlessly with Security Engineering to ensure technology architectures meet those standards without slowing delivery.

Your Role:

Optimize and Enhance the GRC and Data Security Function

  • Refine and maintain the enterprise security charter, operating model, risk appetite, and annual priorities for GRC and data protection.
  • Maintain and enforce enterprise security principles, acceptable use policies, and technology guardrails, specifically tailored for GenAI and large-scale data environments.
  • Enhance our transparent, centralized view of enterprise risk, compliance gaps, and data repositories through workflow improvements and automation.
  • Lead and develop an established, high-performing centralized global team, continually refining the engagement model between Risk/GRC and technical execution teams.


Drive the Security Partnership Model

  • Act as the ongoing primary business partner to the Head of Security Engineering, translating strategic priorities, risk tolerances, and compliance frameworks into clear requirements for technical architecture.
  • Review and approve enterprise architecture designs from a risk and compliance perspective, ensuring Security Engineering's blueprints seamlessly align with global data protection mandates.
  • Collaborate with engineering leadership to evolve our multi-year security roadmap, maintaining the separation of policy definition (your team) from technical implementation (engineering).


Optimize Effective Governance and Decision Rights

  • Streamline and manage the existing security and risk review process, ensuring it remains rigorous, lightweight, focused on business outcomes, and increasingly automated.
  • Strengthen executive sponsorship and organizational adoption of GRC as a highly efficient, vital business enablement process, rather than merely an IT compliance checkpoint.
  • Facilitate our empowered Security Review Board (SRB) to maintain clear membership, decision rights, escalation paths, and operating cadence.
  • Optimize and automate mechanisms to identify and manage cyber risk, compliance debt, third-party vendor risk, and deviations from established security standards.


Modernize, Automate, and Secure the Enterprise
  • Evolve the strategic approach to Data and AI security to continually support trusted data flows, responsible AI adoption, interoperability, and scale.
  • Accelerate the direction for compliance automation, working closely with engineering to systematically reduce the manual burden of audits while maintaining continuous compliance.
  • Ensure security and governance requirements leverage automation to support engineering delivery velocity rather than becoming a barrier to innovation.


Lead Through Influence and Partnership
  • Build strong relationships with IT leadership, privacy, legal, and data teams.
  • Partner with Finance, Procurement, and Internal Audit to embed security into planning and vendor control processes.
  • Communicate complex cyber risks and AI security trade-offs in clear business language to create alignment among stakeholders with competing priorities.


First 12-18 Months: What Success Looks Like
  • The established GRC and Data/AI Security practice is operating with optimized, highly automated workflows for its charter, principles, standards, and exception processes.
  • A seamless operating rhythm exists between GRC and Security Engineering, with clear handoffs between policy definition and architectural execution.
  • Executive leaders have a continually updated, shared view of the enterprise risk profile and a sequenced compliance and security investment roadmap.
  • AI guardrails are refined and actively enabling the business to securely build and deploy AI solutions at scale.
  • The empowered risk decision-making body (SRB) operates with streamlined, efficient cadences and increasingly automated decision support.
  • Stakeholders experience security as a source of clarity, speed, and safety-the "Department of How" rather than the "Department of No."


What You Will Bring:

Leadership

You are a strategic thinker who excels at defining boundaries and building frameworks. You know that effective security requires specialized focus, and you excel at setting the standard while empowering technical experts to build the solution. You move fluidly between enterprise risk strategy and board-level reporting, ask incisive questions, and make recommendations grounded in value, risk, and feasibility. You know when to enforce strict standards, when to allow compensating controls, and when to accept risk with imperfect information. You earn influence through clarity, consistency, and a deeply collaborative approach to problem-solving.

  • 15+ years of experience leading information security, GRC, or data protection in a complex, global, high-tech organization (> 3000 FTEs).
  • Demonstrated success building or materially maturing a GRC and Data Security function, including governance, operating models, and global talent.
  • Deep expertise in navigating modern compliance frameworks and translating them into technical controls.
  • Strong fluency in Data Security (classification, DLP, privacy frameworks) and AI Security (acceptable use, NIST AI RMF, algorithmic risk).
  • Experience operating in a matrixed environment, effectively separating risk/requirements from technical execution while maintaining strong alignment with engineering teams.
  • Executive presence and the ability to influence senior leaders, legal partners, engineers, and architects with equal credibility.
  • Excellent written, verbal, and visual communication skills, including the ability to explain complex cyber risks simply.
  • BS/Masters degree or relevant experience.


Work Arrangement:

This role is Hybrid or based in San Jose, CA. Should the role be within 50 miles of a Nutanix office, it will require coming into an office a minimum of 3 days per week. Additional team-specific guidance and norms will be provided by your manager.

Pay Transparency:

The pay range for this position at commencement of employment is expected to be between USD $308,000 and USD $462,000 per year. However, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. The total compensation package for this position may also include other elements, including a sign-on bonus, restricted stock units, and discretionary awards in addition to a full range of medical, financial, and/or other benefits (including 401(k) eligibility and various paid time off benefits such as vacation, sick time, and parental leave), dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an "at-will position" and the Company reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

About Nutanix

Nutanix is a cloud computing software company that sells what it calls hyper-converged infrastructure (HCI) appliances and software-defined storage. Nutanix's software delivers a full infrastructure stack that integrates compute, virtualization, storage, networking, and security to power any application, at any scale. Nutanix software runs across different cloud environments to harmonize IT operations and bring frictionless mobility to all applications. Nutanix solutions are used by companies in a wide range of industries, including healthcare, manufacturing, education, and financial services.
Learn more about Nutanix
Size
6,080 employees
Market Cap
$6.3 billion
Industry
Net Income
-$978.4 million
Founded
2009
5 Year Trend
+13.3%
Revenue
$1.3 billion
NASDAQ

Similar Jobs

More Jobs at Nutanix

More Enterprise Technology Jobs

Find similar Senior Director, Governance, Risk & Compliance jobs: