ForgeApply · Job listing
Director of Security Compliance
Jda
See all 58 open roles at Jda →
Tailor your resume for this Jda job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Jda's site. Free trial, no card required.
About this role
Reports to: Senior Director of GRC Location: Scottsdale, AZ / Dallas, TX / Remote (US) Synonymous Business Title (s): Security & Compliance Director
About Blue Yonder and the Team:
Blue Yonder is a world leader in digital supply chain transformation. Retailers, manufacturers, and logistics providers across the globe rely on our AI-driven platform to plan, execute, and optimize the flow of goods from source to consumer. Our software touches on the operations of some of the most recognizable brands in the world, which means the trust our customers place in the security, resilience, and integrity of our services is central to everything we do.
The Blue Yonder Governance, Risk, & Compliance (GRC) team protects that trust. We build and operate the programs that keep Blue Yonder secure, compliant, and audit-ready across a broad portfolio of SaaS products and the cloud platforms that run them. This is a role for a leader who wants their work to be visible to customers, regulators, and executives alike – and who sees compliance not as a checkbox exercise, but as a durable business enabler.
The GRC team sits within Blue Yonder’s Global Cyber Security, Risk & Compliance organization. We are the group that turns Blue Yonder’s security posture into evidence the world can trust – the certifications customers require, the attestations regulators expect, and the controls that keep our platform resilient. We partner closely with Engineering, Product, Privacy, Internal Audit, Legal, and Customer Trust, and our work directly enables revenue, shortens sales cycles, and protects the company’s reputation. We value clear thinking, durable process, and using automation to do more meaningful work with less manual toil.
Overview:
The Director of Security Compliance leads the team responsible for planning, executing, and sustaining Blue Yonder’s portfolio of information security and IT compliance certifications and attestations. Reporting to the Senior Director of GRC, you will own the end-to-end audit and compliance lifecycle – scoping, evidence, control operation, auditor management, and reporting – across a multi-product, multi-cloud environment.
You will lead a team of compliance professionals delivering ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, and Sarbanes-Oxley / IT General Controls (ITGC) audits, alongside other information security–based assessments across the Blue Yonder portfolio of services. Just as importantly, you will mature how we operate these programs – replacing point-in-time scrambles with continuous, evidence-backed control operation, shared control frameworks, and automation that lets the team spend more time on judgment and less on collection.
Scope/Responsibilities: • Lead the compliance team responsible for delivering Blue Yonder’s information security certifications and attestations, including ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, and SOX / ITGC – setting direction, priorities, and operating cadence. • Own the end-to-end audit lifecycle across the portfolio: scoping, control mapping, evidence collection, control operation, auditor coordination, issue remediation, and final reporting. • Manage external auditors and certification bodies as the primary point of accountability – negotiating scope, timelines, and sampling, and driving clean, defensible outcomes. • Rationalize the control environment by building and maintaining a shared, cross-framework control set that lets a single control satisfy multiple obligations, reducing duplicate evidence and audit fatigue. • Mature SOX / ITGC compliance in partnership with Internal Audit, Finance, and control owners – ensuring IT general controls over financially relevant systems are designed, operating, and evidenced effectively. • Stand up and scale emerging frameworks including ISO 42001 for AI management systems, aligning Blue Yonder’s AI governance and responsible-AI practices with certification requirements. • Drive continuous compliance by championing automation, evidence pipelines, process improvements, and GRC tooling that shift the program from periodic firefighting toward always-audit-ready operation. • Partner across the business with Engineering, Product, Cloud Platform, Privacy, Legal, Internal Audit, and Customer Trust to embed control requirements into how services are built and run. • Translate compliance into business value by preparing clear reporting for executives, customers, and regulators, maturing support model for customer audits, and by enabling Sales and Customer Trust with current, accurate attestations and evidence. • Develop the team through coaching, clear ownership, and career growth – building bench strength across frameworks and cloud platforms.
What You’ll Do: • Proven leadership of a security compliance, IT audit, or GRC function in a complex, multi-product SaaS or technology environment, including direct management of a team of compliance professionals. • Deep, hands-on expertise delivering the audits central to this role – ISO 27001, SOC 1, and SOC 2 – with demonstrable experience managing certification bodies and audit firms end to end. • Working knowledge across the broader framework portfolio including ISO 27701 (privacy), ISO 22301 (business continuity), ISO 42001 (AI management systems), and Sarbanes-Oxley / ITGC. • Cloud fluency across the platforms that run our services – Microsoft Azure (preferred), with familiarity across AWS, GCP, and OCI, and an understanding of how cloud shared-responsibility models shape control scope and evidence. • Practical command and control frameworks and the ability to map many overlapping requirements to a single, coherent control environment rather than running each audit as a silo. • A continuous-compliance mindset with real experience applying automation, evidence pipelines, and GRC platforms to scale audit readiness. • Strong cross-functional influence – able to work credibly with Engineering and Product
Salary insight
The midpoint of this range ($192k) is about 37% above the median disclosed salary for Dallas roles listed on ForgeApply ($140k across 961 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Jda role before you apply.
Tailor my resume for this jobSimilar jobs
- Director of Security and Compliance — Swinerton (Swinerton External Career) · Concord CA | Raleigh NC | New York NY
- Head of Security & Compliance — Casca · San Francisco
- Director of Security — Nerostechnologies · Torrance, California, United States
- Director of Security — Eqtcorporation · Canonsburg, PA
- Director of Security — Loewshotels · AZ - Tucson - Loews Ventana Canyon
- Director of Security — Montage International · Healdsburg, CA
- Director of Security Operations — North America · United States
- Director of Compliance — Electronx · Chicago
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)