Dow

Governance, Risk, and Compliance and Data Privacy Office Director

Midland MI USAFull timeDirectorPosted 6 days ago
Apply on Dow →

Sign into see who you know at Dow.

At Dow, we believe in putting people first and we’re passionate about delivering integrity, respect and safety to our customers, our employees and the planet.   Our people are at the heart of our solutions. They reflect the communities we live in and the world where we do business. Their diversity is our strength. We’re a community of relentless problem solvers that offers the daily opportunity to contribute with your perspective, transform industries and shape the future. Our purpose is simple - to deliver a sustainable future for the world through science and collaboration. If you’re looking for a challenge and meaningful role, you’re in the right place.About this roleDow has an exciting opportunity for a Governance, Risk, and Compliance and Data Privacy Director located in Midland, MI or Houston, TX.In this role, you will lead and direct multiple teams (typically through other people leaders) and apply in-depth knowledge of your area of responsibility. You will lead cyber governance, risk, compliance, data privacy, and develop and implement an evergreen enterprise-wide cyber awareness program to ensure effective risk oversight, regulatory adherence, and develop a strong cybersecurity culture.Responsibilities – Duties, projects, tasks, and activities you would be responsible for in this roleOwn cyber security governance effectiveness – establish clear, enforceable policies, standards and control frameworks with unambiguous ownership and consistent applicationOwn cyber and data privacy risk identification and visibility – ensure internal and external risks are clearly defined in central risk register, quantified and reported. Actively challenge and escalate unacceptable riskOwn regulatory compliance and audit outcomes – ensure compliance is sustainable and audit-ready by design, with no reliance on reactive audit preparation and no recurring findingsOwn external cyber assessments and certification to enable the business (e.g. customer cyber assessment, ISO 270001, NIST CSF, etc)Own security culture and behavior change outcomes – drive measurable improvements in workforce cyber and data privacy behaviors  Key requirementsRisk-first mindset (non-negotiable) – uses compliance frameworks as tools, not goals; prioritizes exposure, control effectiveness and business impactAbility to challenge the business with credibility – pushes back on weak controls and unclear risk acceptance; forces clarity on ownership and impactTranslates risks into business language – converts regulatory and control concepts into exposure, financial risk and operational impactGovernance builder (not just operator) – designs governance forums, decision rights and escalation paths that enforce accountability and consistencyCulture shaper – drives measurable shifts in how the organization thinks about and manages riskSkillsLeadership: Demonstrates the ability to lead global teams, influence stakeholders, establish accountability, and drive enterprise-w...