We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Director of Security Compliance

Blue Yonder
flex time, 401(k)
United States, Arizona, Scottsdale
14400 North 87th Street (Show on map)
Aug 18, 2026

Reports to: Senior Director of GRC

Location: Scottsdale, AZ / Dallas, TX / Remote (US)

Synonymous Business Title (s): Security & Compliance Director

About Blue Yonder and the Team:

Blue Yonder is a world leader in digital supply chain transformation. Retailers, manufacturers, and logistics providers across the globe rely on our AI-driven platform to plan, execute, and optimize the flow of goods from source to consumer. Our softwaretouches onthe operations of some of the most recognizable brands in the world, which means the trust our customers place in the security, resilience, and integrity of our services is central to everything we do.

TheBlue Yonder Governance,Risk,& Compliance (GRC)teamprotects that trust. We build and operate the programs that keep Blue Yonder secure, compliant, and audit-ready across a broad portfolio of SaaS products and the cloud platforms that run them. This is a role for a leader who wants their work to be visible to customers, regulators, and executives alike - and who sees compliance not as a checkbox exercise, but as a durable business enabler.

TheGRCteam sits within Blue Yonder's Global Cyber Security, Risk & Compliance organization. We are the group that turns Blue Yonder's security posture intoevidencethe world can trust - the certifications customers require, the attestations regulators expect, and the controls that keep our platform resilient. We partner closely with Engineering, Product, Privacy, Internal Audit, Legal, and Customer Trust, and our work directly enables revenue, shortens sales cycles, and protects the company's reputation. We value clear thinking, durable process, and using automation to do more meaningful work with less manual toil.

Overview:

TheDirectorofSecurity Compliance leads the team responsible for planning, executing, and sustaining Blue Yonder's portfolio of information security and IT compliance certifications and attestations. Reporting to theSenior Directorof GRC, you will own the end-to-end auditand compliancelifecycle - scoping, evidence, control operation, auditor management, and reporting - across a multi-product, multi-cloud environment.

You will lead a team of compliance professionals delivering ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, and Sarbanes-Oxley / IT General Controls (ITGC) audits, alongside other information security-based assessments across the Blue Yonder portfolio of services. Just as importantly, you will mature how we operate these programs - replacing point-in-time scrambles with continuous, evidence-backed control operation, shared control frameworks, and automation that lets the team spend more time on judgment and less on collection.

Scope/Responsibilities:

  • Lead the compliance teamresponsible for delivering Blue Yonder's information security certifications and attestations, including ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, and SOX / ITGC - setting direction, priorities, and operating cadence.
  • Own the end-to-end audit lifecycleacross the portfolio: scoping, control mapping, evidence collection, control operation, auditor coordination, issue remediation, and final reporting.
  • Manage external auditors and certification bodiesas the primary point of accountability - negotiating scope, timelines, and sampling, and driving clean, defensible outcomes.
  • Rationalize the control environmentby building and maintaining a shared, cross-framework control set that lets a single control satisfy multiple obligations, reducing duplicate evidence and audit fatigue.
  • Mature SOX / ITGC compliancein partnership with Internal Audit, Finance, and control owners - ensuring IT general controls over financially relevant systems are designed, operating, and evidenced effectively.
  • Stand up and scale emerging frameworksincluding ISO 42001 for AI management systems, aligning Blue Yonder's AI governance and responsible-AI practices with certification requirements.
  • Drive continuous complianceby championing automation, evidence pipelines,process improvements,and GRC tooling that shift the program from periodic firefighting toward always-audit-ready operation.
  • Partneracross the businesswith Engineering, Product, Cloud Platform, Privacy, Legal, Internal Audit, and Customer Trust to embed control requirements into how services are built and run.
  • Translate compliance into business valueby preparing clear reporting for executives, customers, and regulators,maturing support model for customer audits,and by enabling Sales and Customer Trust with current, accurate attestations and evidence.
  • Develop the teamthrough coaching, clear ownership, and career growth - building bench strength across frameworks and cloud platforms.

What You'll Do:

  • Proven leadershipof a security compliance, IT audit, or GRC function in a complex, multi-product SaaS or technology environment, including direct management of a team of compliance professionals.
  • Deep, hands-on expertisedelivering the audits central to this role - ISO 27001, SOC 1, and SOC 2 - with demonstrable experience managing certification bodies and audit firms end to end.
  • Working knowledge across the broader framework portfolioincluding ISO 27701 (privacy), ISO 22301 (business continuity), ISO 42001 (AI management systems), and Sarbanes-Oxley / ITGC.
  • Cloud fluencyacross the platforms that run our services - Microsoft Azure (preferred), with familiarity across AWS, GCP, and OCI, and an understanding of how cloud shared-responsibility models shape control scope and evidence.
  • Practical commandandcontrol frameworksand the ability to map many overlapping requirements to a single, coherent control environment rather than running each audit as a silo.
  • A continuous-compliance mindsetwith real experience applying automation, evidence pipelines, and GRC platforms to scale audit readiness.
  • Strong cross-functional influence- able to work credibly with Engineering and Product on technical controls while communicating clearly with executives, auditors, and customers.
  • Sound judgment on riskbalancing rigor withpragmatism andknowing when a control gap is afinding to remediateversus a risk to accept and document.

What We're Looking For:

Required Qualifications:

  • Minimum 10+ yearsof experience insecurity compliance, audit, or information security within an enterprise SaaS environment.
  • Deep expertiseof Securityand IT complianceframeworks (SOC2, ISO 27001, ISO 22301,SOX ITGCs,etc.).
  • Experiencedeveloping, maturing,or transformingcompliance programs in a cloud and/or SaaS environment.
  • Strong collaborator, working with technical and non-technical stakeholdersat variouslevels of leadership.
  • Strong organizational and project management skills.

Preferred Qualifications:

  • Experience with GDPR and other data privacy frameworks, and the ability to operationalize privacy obligations into auditable controls (e.g., via ISO 27701).
  • Familiarity with FedRAMP and U.S. public-sector security requirements, and experience preparing environments for government-grade authorization.
  • Strong grounding in the NIST family of standards, including NIST SP 800-53 and the NIST Cybersecurity Framework, and experience mapping across frameworks.
  • Familiarity withcompliance automation and GRC platforms.
  • Experience leading a geographically distributed compliance team
  • Relevant certifications such as CISA, CISM, CISSP, CIPP, ISO 27001 Lead Auditor / Lead Implementer, or equivalent.
  • Experience in supply chain, logistics, and/or enterprise SaaS, operating in a fast-moving, AI-driven product organization.

#LI-MH1

-------------------------------------------

The annual salary range for this position is $167,075.96 - $216,924.03

The salary range information provided, reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual salary will be commensurate with skills, experience, certifications or licenses and other relevant factors. In addition, this role will be eligible to participate in either the annual performance bonus or commission program, determined by the nature of the position.

At Blue Yonder, we care about the wellbeing of our employees and those most important to them. This is reflected in our robust benefits package and options that includes:

  • Comprehensive Medical, Dental and Vision

  • 401K with Matching

  • Flexible Time Off

  • Corporate Fitness Program

  • A variety of voluntary benefits such as; Legal Plans, Accident and Hospital Indemnity, Pet Insurance and much more

At Blue Yonder, we are committed to a workplace that genuinely fosters inclusion and belonging in which everyone can share their unique voices and talents in a safe space. We continue to be guided by our core values and are proud of our diverse culture as an equal opportunity employer. We understand that your career search may look different than others, and embrace the professional, personal, educational, and volunteer opportunities through which people gain experience.

Our Values

If you want to know the heart of a company, take a look at their values. Ours unite us. They are what drive our success - and the success of our customers. Does your heart beat like ours? Find out here: Core Values

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Applied = 0

(web-77cf7d65c7-j8d9g)