RealPage

Senior Director, IT & Security GRC

RealPage$138K — $235K *
US-AnywhereRemote in Richardson, TX
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Business Administration, Accounting, Finance, Operations, Computer Science, Information Technology, Cybersecurity, or related field; advanced degree preferred.
  • 12+ years of experience in technology risk, IT audit, GRC, or information security, with 7+ years in leadership roles.
  • Hands-on expertise in SOX IT General Controls and the IT audit lifecycle.
  • Strong understanding of AI risk management with practical experience.
  • Experience in designing GRC programs aligned to NIST CSF 2.0 and similar frameworks.
  • Proven executive-level communication skills and experience authoring risk narratives.
  • Ability to influence and partner effectively with senior leaders.

Responsibilities

  • Partner with control owners to enhance controls and drive automation.
  • Monitor compliance of control design and its effectiveness.
  • Build and evolve the Technology Risk, Threat, and Control Library aligned with industry frameworks.
  • Establish a unified control taxonomy to improve efficiencies across compliance frameworks.
  • Prototype control automations and governance tools using AI technologies.
  • Develop executive-ready reports on technology risk posture and remediation status.
  • Advise on technology risk for strategic initiatives like AI and cloud transformation.

Benefits

  • Health, dental, and vision insurance.
  • Retirement savings plan with company match.
  • Paid time off and holidays.
  • Professional development opportunities.
  • Performance-based bonus opportunities.
Full Job Description
Overview

This role reports to VP, Technology GRC and Deputy CISO and has accountability for maturing SOX ITGC oversight, establishing a unified Technology Risk, Threat, and Controls Library, and delivering executive-level risk reporting and advisory services. It partners closely with senior leadership, Internal Audit, and business stakeholders to design and operate a scalable, framework-aligned risk and control environment across a complex SaaS ecosystem.

The position serves as a strategic advisor to executives, providing clear insight into technology risk posture, emerging threats, and remediation strategies while enabling regulatory compliance (SOX, PCI, SOC, NYDFS) and business objectives.

Responsibilities

SOX IT General Controls (ITGCs)
  • Partner with control owners (1st LOD) to mature controls, drive automation, and remediate control deficiencies prior to year-end.
  • Monitor compliance of control design and operating effectiveness


Technology Risks, Threats & Controls Library
  • Build, govern, and continuously evolve the enterprise Technology Risk, Threat, and Control Library, mapped to NIST CSF 2.0, COBIT 2019, ISO 27001, MITRE ATT&CK, and applicable regulatory regimes.
  • Establish a unified control taxonomy enabling control rationalization, framework crosswalks, and "test once, satisfy many" efficiencies across SOX, PCI DSS, SOC 1, SOC 2 and NYDFS.


AI Risk Management
  • Demonstrated interest or working proficiency in "vibe coding" and AI-assisted development workflows using tools (e.g., Claude Code, Cursor and GitHub Copilot), sufficient to prototype control automations, evidence collectors, and governance tooling without dependence on engineering backlog.
  • Hands-on familiarity with leading Large Language Models (LLMs) (e.g., Anthropic Claude (Opus, Sonnet, Haiku), OpenAI GPT-4/5 and o-series, Google Gemini, Meta Llama, and Mistral), with a practical understanding of model selection trade-offs (reasoning depth, context window, cost, latency, data residency).
  • Working knowledge of LLM application patterns - prompt engineering, retrieval-augmented generation (RAG), function/tool calling, agentic workflows, and Model Context Protocol (MCP) and the associated risk, control, and governance implications.
  • Familiarity with the AI/LLM risk landscape, including OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, and emerging regulatory expectations (EU AI Act, NYDFS AI guidance, state-level AI laws).
  • Ability to govern AI responsibly while using it productively leveraging LLMs to accelerate risk assessments, control narratives, policy drafting, audit evidence review, and Board reporting while maintaining accuracy, confidentiality, and IP boundaries.


Committee & Board Reporting
  • Develop and deliver executive ready reporting on technology risk posture, control health, emerging threats, regulatory developments, and remediation progress.


Advisory Services
  • Serve as a trusted advisor to IT, Information Security and Engineering on technology risk, control design, and regulatory implications of strategic initiatives, including AI/ML, cloud transformation, M&A, and platform migrations.
  • Provide proactive risk and control guidance on architecture decisions, technology investments, third-party engagements, and new product capabilities.
  • Embed risk and control thinking into enterprise programs and strategic pillars (Innovate, Expand, Protect, Transform), shaping outcomes earlier in the lifecycle.


Issue & Remediation Management
  • Own the enterprise technology risk and control issue lifecycle, including identification, root cause analysis, risk rating, remediation planning, tracking, and closure validation.
  • Drive accountability across control owners and remediation owners; escalate aging or critical issues to executive leadership and the Board with clear paths to resolution.
  • Maintain a single enterprise issue register with risk-rated, time-bound action plans and trend reporting for governance forums.


Risk Assessments
  • Perform risk assessment on AI agentic solutions.
  • Translate risk assessment outputs into actionable risk treatment plans, control improvements, capital and investment recommendations, and executive risk narratives.


Qualifications

Required Knowledge, Skills & Abilities
  • Bachelor's degree in Business Administration, Accounting, Finance, Operations, Computer Science, Information Technology, Cybersecurity, or a related field; advanced degree (MBA, MS) preferred.
  • Minimum 12+ years of progressive experience in technology risk, IT audit, GRC, or information security, with at least 7+ years leading and developing high-performing teams.
  • Deep, hands-on expertise across SOX IT General Controls, technology risk management, control design, and the IT audit lifecycle within a complex public company environment.
  • Strong understanding on AI risk management with practical experience working with AI solutions.
  • Demonstrated experience designing and operating GRC programs aligned to NIST CSF 2.0, COBIT 2019, COSO 2013, ISO 27001, and MITRE ATT&CK.
  • Proven track record of executive- and Board-level communication, including authoring risk narratives, committee materials, and Board updates.
  • Ability to be a change agent and influence positive outcomes by exercising critical thinking, strategic growth, and a bias toward action.
  • Exceptional ability to influence without authority and partner effectively with senior IT, Engineering, Security, Internal Audit, and business leaders.
  • Exceptionally strong quantitative and analytical skills, with experience applying formal risk and process improvement practices (e.g., FAIR, NIST 800-30, Lean, Six Sigma).
  • Excellent leadership, communication, interpersonal, and presentation skills, with the ability to operate from technical detail to Board-room strategy.
  • Ability to work extended hours when needed to meet department, audit, and regulatory deadlines.
  • Ability to challenge the status quo, go above and beyond, build and maintain trust, and strive for excellence.
  • Relevant certifications strongly preferred (e.g., CISA, CRISC, CISM, CISSP, CIA, CGEIT, ISO 42001).
  • Preferred 7+ years of experience in the Property Management, Multifamily Housing, SaaS, FinTech, or PropTech industries. #LI-REMOTE #LI-JL1


SALARY AND BENEFITS
  • RealPage provides a competitive salary package along with a comprehensive benefit plan that includes:
  • Health, dental, and vision insurance.
  • Retirement savings plan with company match.
  • Paid time off and holidays.
  • Professional development opportunities.
  • Performance-based bonus based on position.

Compensation may vary depending on your location, qualifications including job-related education, training, experience, licensure, and certification, that could result at a level outside of these ranges. Certain roles are eligible for additional rewards, including annual bonus, and sales incentives depending on the terms of the applicable plan and role as well as individual performance.

Pay Range

USD $138,400.00 - USD $235,600.00 /Yr.

About RealPage

RealPage is a provider of software and data analytics to the real estate industry. The company's platform enables property owners and managers to manage their properties, including leasing, accounting, and maintenance, among other services. RealPage's clients include property owners, managers, and investors. The company was founded in 1998 and is headquartered in Richardson, Texas.
Learn more about RealPage
Size
1 employees
Market Cap
$9 billion
Industry
Net Income
$46.3 million
Founded
1998
5 Year Trend
+19.8%
Revenue
$1.1 billion
NASDAQ

Similar Jobs

More Jobs at RealPage

  • RealPage
    Lead AI Engineer
    $125K — $213K *
    Richardson, TX 75080 (Dallas County)
    Consumer Technology
    In-Person
  • RealPage
    Product Manager
    $85K — $145K *
    Boston, MA 02115 (Suffolk County)
    Consumer Technology
    In-Person
  • RealPage
    Account Representative III
    $74K — $127K *
    Richardson, TX 75080 (Dallas County)
    Business Services
    In-Person
  • RealPage
    Acct Mgr II, Product
    $70K — $120K *
    Richardson, TX 75080 (Dallas County)
    Real Estate & Construction
    In-Person
  • RealPage
    Fraud Strategist
    $77K — $132K *
    Remote
    Finance & Insurance
    Remote in Richardson, TX

More Information Technology Jobs

Find similar Senior Director, IT & Security GRC jobs: