Senior Director, Governance, Risk & Compliance
The Opportunity: This role reports to the Chief Information Security Officer
Nutanix is maturing its security organization to stay ahead of an evolving digital landscape. We are seeking a pragmatic, strategic, and highly credible Head of Enterprise Security to lead our Governance, Risk, and Compliance (GRC), and Data Security with a clear focus on AI Security and Governance.
This role operates in a highly collaborative partnership model. Working in lockstep with our Head of Security Engineering, you will own the strategic "what and why" - defining the company's risk appetite, compliance requirements, AI policies, and data guardrails. You will rely on your engineering partners to deliver the architectural "how," ensuring that technical designs map directly to your risk and compliance mandates.
The successful candidate will be a master translator: capable of turning complex regulatory and cyber risk concepts into actionable requirements for engineering teams, while simultaneously explaining technical risk posture to executive leadership and the board.
About the Team:
This team is responsible for leading and continuously optimizing a centralized GRC, Data, and AI Security function that defines the enterprise risk landscape, sets the guardrails for secure innovation, and partners seamlessly with Security Engineering to ensure technology architectures meet those standards without slowing delivery.
Your Role:
Optimize and Enhance the GRC and Data Security Function
Refine and maintain the enterprise security charter, operating model, risk appetite, and annual priorities for GRC and data protection.
Maintain and enforce enterprise security principles, acceptable use policies, and technology guardrails, specifically tailored for GenAI and large-scale data environments.
Enhance our transparent, centralized view of enterprise risk, compliance gaps, and data repositories through workflow improvements and automation.
Lead and develop an established, high-performing centralized global team, continually refining the engagement model between Risk/GRC and technical execution teams.
Drive the Security Partnership Model
Act as the ongoing primary business partner to the Head of Security Engineering, translating strategic priorities, risk tolerances, and compliance frameworks into clear requirements for technical architecture.
Review and approve enterprise architecture designs from a risk and compliance perspective, ensuring Security Engineering's blueprints seamlessly align with global data protection mandates.
Collaborate with engineering leadership to evolve our multi-year security roadmap, maintaining the separation of policy definition (your team) from technical implementation (engineering).
Optimize Effective Governance and Decision Rights
Streamline and manage the existing security and risk review process, ensuring it remains rigorous, lightweight, focused on business outcomes, and increasingly automated.
Strengthen executive sponsorship and organizational adoption of GRC as a highly efficient, vital business enablement process, rather than merely an IT compliance checkpoint.
Facilitate our empowered Security Review Board (SRB) to maintain clear membership, decision rights, escalation paths, and operating cadence.
Optimize and automate mechanisms to identify and manage cyber risk, compliance debt, third-party vendor risk, and deviations from established security standards.
Modernize, Automate, and Secure the Enterprise
Evolve the strategic approach to Data and AI security to continually support trusted data flows, responsible AI adoption, interoperability, and scale.
Accelerate the direction for compliance automation, working closely with engineering to systematically reduce the manual burden of audits while maintaining continuous compliance.
Ensure security and governance requirements leverage automation to support engineering delivery velocity rather than becoming a barrier to innovation.
Lead Through Influence and Partnership
Build strong relationships with IT leadership, privacy, legal, and data teams.
Partner with Finance, Procurement, and Internal Audit to embed security into planning and vendor control processes.
Communicate complex cyber risks and AI security trade-offs in clear business language to create alignment among stakeholders with competing priorities.
First 12–18 Months: What Success Looks Like
The established GRC and Data/AI Security practice is operating with optimized, highly automated workflows for its charter, principles, standards, and exception processes.
A seamless operating rhythm exists between GRC and Security Engineering, with clear handoffs between policy definition and architectural execution.
Executive leaders have a continually updated, shared view of the enterprise risk profile and a sequenced compliance and security investment roadmap.
AI guardrails are refined and actively enabling the business to securely build and deploy AI solutions at scale.
The empowered risk decision-making body (SRB) operates with streamlined, efficient cadences and increasingly automated decision support.
Stakeholders experience security as a source of clarity, speed, and safety—the "Department of How" rather than the "Department of No."
What You Will Bring:
Leadership
You are a strategic thinker who excels at defining boundaries and building frameworks. You know that effective security requires specialized focus, and you excel at setting the standard while empowering technical experts to build the solution. You move fluidly between enterprise risk strategy and board-level reporting, ask incisive questions, and make recommendations grounded in value, risk, and feasibility. You know when to enforce strict standards, when to allow compensating controls, and when to accept risk with imperfect information. You earn influence through clarity, consistency, and a deeply collaborative approach to problem-solving.
15+ years of experience leading information security, GRC, or data protection in a complex, global, high-tech organization (> 3000 FTEs).
Demonstrated success building or materially maturing a GRC and Data Security function, including governance, operating models, and global talent.
Deep expertise in navigating modern compliance frameworks and translating them into technical controls.
Strong fluency in Data Security (classification, DLP, privacy frameworks) and AI Security (acceptable use, NIST AI RMF, algorithmic risk).
Experience operating in a matrixed environment, effectively separating risk/requirements from technical execution while maintaining strong alignment with engineering teams.
Executive presence and the ability to influence senior leaders, legal partners, engineers, and architects with equal credibility.
Excellent written, verbal, and visual communication skills, including the ability to explain complex cyber risks simply.
BS/Masters degree or relevant experience.
Work Arrangement:
This role is Hybrid or based in San Jose, CA. Should the role be within 50 miles of a Nutanix office, it will require coming into an office a minimum of 3 days per week. Additional team-specific guidance and norms will be provided by your manager.
Pay Transparency:
The pay range for this position at commencement of employment is expected to be between USD $308,000 and USD $462,000 per year. However, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. The total compensation package for this position may also include other elements, including a sign-on bonus, restricted stock units, and discretionary awards in addition to a full range of medical, financial, and/or other benefits (including 401(k) eligibility and various paid time off benefits such as vacation, sick time, and parental leave), dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
--
Nutanix is an equal opportunity employer.
Nutanix is an Equal Employment Opportunity and (in the U.S.) an Affirmative Action employer. Qualified applicants are considered for employment opportunities without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, protected veteran status, disability status or any other category protected by applicable law. We hire and promote individuals solely on the basis of qualifications for the job to be filled. We strive to foster an inclusive working environment that enables all our Nutants to be themselves and to do great work in a safe and welcoming environment, free of unlawful discrimination, intimidation or harassment. As part of this commitment, we will ensure that persons with disabilities are provided reasonable accommodations. If you need a reasonable accommodation, please let us know by contacting [email protected].