ForgeApply · Job listing
Director of Governance, Risk, and Compliance / TPRM
Independencepet Group
See all 50 open roles at Independencepet Group →
Tailor your resume for this Independencepet Group job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Independencepet Group's site. Free trial, no card required.
About this role
Established in 2021, Independence Pet Holdings is a corporate holding company that manages a diverse and broad portfolio of modern pet health brands and services, including insurance, pet education, lost recovery services, and more throughout North America. We believe pet insurance is more than a financial product and build solutions to simplify the pet parenting journey and help improve the well-being of pets. As a leading authority in the pet category, we operate with a full stack of resources, capital, and services to support pet parents. Our multi-brand and omni-channel approach include our own insurance carrier, insurance brands and partner brands.
Position Overview:
The Director of Governance, Risk & Compliance (GRC) and Third-Party Risk Management (TPRM) is an enterprise leadership role accountable for the design, implementation, and continuous maturation of a unified risk and compliance program across a $2.5 billion insurance holding company. This position holds end-to-end accountability for the information security compliance posture of an organization comprised of 12 Managing General Agencies (MGAs) and 2 insurance carriers, operating within a complex and highly regulated environment.
Operating at the intersection of cybersecurity, regulatory compliance, and third-party governance, this leader serves as the central authority for aligning disparate control environments into a cohesive, measurable, and defensible enterprise risk framework. The role requires executive-level influence, regulatory fluency, and the ability to drive consistency across a federated, acquisition-driven operating model.
Key Responsibilities:
Enterprise Accountability & Regulatory Posture • Own and maintain the enterprise-wide information security compliance posture across all operating entities, ensuring alignment with regulatory expectations and internal risk appetite.
• Establish a defensible, evidence-driven control environment capable of withstanding regulatory scrutiny across multiple jurisdictions.
• Serve as the authoritative leader for compliance strategy across MGAs and carrier entities with differing regulatory obligations.
Enterprise GRC Strategy & Architecture • Design and implement a unified GRC operating model across multiple insurance entities with varying levels of maturity.
• Establish a control-centric framework leveraging NIST 800-53, ISO 27001, SOC 2, and PCI DSS.
• Transition the organization from periodic, interview-based assessments to continuous, evidence-driven compliance measurement.
• Define and operationalize KRIs, control effectiveness metrics, and executive reporting.
Regulatory & Audit Leadership • Serve as the central point of accountability for regulatory readiness, including NYDFS, state insurance regulators, and international frameworks where applicable
• Lead enterprise-wide audit strategy (SOC 2 Type II, ISO 27001, internal audits)
• Interface directly with regulators and external auditors to ensure consistent narratives, defensible controls, and successful audit outcomes
• Drive enterprise remediation strategies with measurable timelines and executive accountability
Third-Party Risk Management (TPRM) • Build and scale a comprehensive TPRM program across the full vendor lifecycle.
• Establish risk tiering, due diligence, and continuous monitoring aligned with enterprise risk tolerance.
• Integrate TPRM into procurement, legal, and business operations to ensure consistent enforcement.
• Oversee risk acceptance and exception governance frameworks.
• Operational Integration & Transformation
• Harmonize fragmented GRC practices across acquired entities into a centralized and scalable function.
• Drive automation strategy leveraging GRC platforms (audioboard, Drata, or equivalent) to enable real-time compliance visibility and evidence collection.
• Embed security, privacy, and identity governance into enterprise-wide control frameworks.
• Advance organizational maturity toward a “Security First” operating model.
• Executive Engagement & Cross-Functional Collaboration
• Provide regular reporting to executive leadership and board-level stakeholders (e.g., Audit Committee, Risk Committee).
• Collaborate daily with the Chief Privacy Officer (CPO) and Chief Risk Officer (CRO) organizations to ensure alignment across privacy, enterprise risk management, and information security compliance
• Translate complex regulatory and technical requirements into business-aligned decision frameworks.
• Influence enterprise investment decisions through quantified risk exposure and control effectiveness.
Leadership & Organizational Complexity • Lead a multi-layered global GRC and TPRM organization, including, 4 senior GRC functional leaders, a transversal offshore operations team and a dedicated outsourced delivery pod (India-based) supporting scaled compliance and assessment activities
• Establish governance models, performance management, and operational rigor across distributed teams.
• Drive talent strategy, succession planning, and capability development aligned to enterprise scale.
Qualifications Experience • 12–15+ years of progressive experience in cybersecurity, risk management, compliance, or audit.
• 5–7+ years in senior leadership roles within insurance or highly regulated financial services environments (required).
• Proven success leading enterprise GRC and TPRM programs across complex, multi-entity organizations.
Professional Background • Licensed attorney (JD) or Certified Public Accountant (CPA) strongly preferred, particularly with experience in regulatory interpretation, audit, or assurance.
• Background in external audit, internal audit, or regulatory advisory highly desirable.
• MBA or equivalent advanced business degree preferred.
Certifications (Preferred) • CISSP (Certified Information Systems Security Professional)
• CISM (Certified Information Security Manager)• CRISC (Certified in Risk and Information Systems Control)
•
Tailor your resume for this Independencepet Group role before you apply.
Tailor my resume for this jobSimilar jobs
- Sr. Engineer, Governance, Risk & Compliance (TPRM) — NextGen · Remote
- Director of Governance, Risk, and Compliance — Eliseai · New York City
- Manager, Governance, Risk & Compliance — Plains · Houston, TX
- Third Party Risk Mgmt (TPRM) Governance Specialist — Vanguard · Malvern, PA
- Senior Director, IT Governance, Risk and Compliance — Wwecorp · Remote
- Governance, Risk, and Compliance Manager — Decagon · San Francisco
- Governance, Risk, and Compliance Manager — Tensorwave · Las Vegas, Nevada
- Director, Governance, Risk, and Compliance (GRC) — Cloverhealth · Remote
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview