Director, Enterprise Risk
AppFolio - San Diego, CA
Hiring: Director, Enterprise Risk Company: AppFolio Location: San Diego, CA Job Posted Time: 2026-09-02 20:45:45 Target Skills & Keywords : Compliance, R, SOC, SOC 2 About the job Experience: •5+ years of progressive experience in enterprise risk management, internal audit, GRC, or technology compliance, including direct people-leadership experience. Required Skills: •The Director, Enterprise Risk will mature and integrate AppFolio’s Enterprise Risk Management (ERM) framework, lead the Technology Compliance function, and build a new Risk Analysis capability — while partnering with first-line teams so that risk management accelerates fast, well-informed decisions rather than constraining them. •Mature and integrate AppFolio’s ERM framework and program in partnership with senior leaders and cross-functional stakeholders, and support the Enterprise Risk Committee (ERC) that administers the program. •Build a new Risk Analysis capability for coordinating risk identification, assessment, and monitoring activities across the business. •Lead the Technology Compliance team — owning compliance policies, ongoing monitoring, and audit readiness across SOX and SOC reviews, and supporting a Common Controls Framework (CCF). •Stand up a continuous, rolling risk-identification cadence that surfaces and escalates emerging risks in real time, complementing the annual enterprise risk assessment and the quarterly ERC and RCOC cycles. •Partner with and enable first-line functions — including R&D (Product and Engineering) — embedding risk-informed decision-making into their workflows so risk is a natural, owned part of moving quickly. Qualifications: •Extensive experience in enterprise risk management, GRC, internal audit, or a closely related second-line function, including maturing or scaling an ERM program. •A track record of building and leading teams, developing talent through individual development plans (IDPs), and planning succession for key roles. •Strong command of enterprise risk frameworks and the three-lines-of-defense model (e.g., COSO ERM), plus working knowledge of technology compliance domains such as SOX ITGCs and SOC 1 / SOC 2. •Demonstrated ability to influence senior leaders and to communicate risk clearly to executive and Board-level audiences, including audit or risk committees. •Experience partnering with first-line functions — ideally R&D, Product, or Engineering — to embed risk-informed decision-making without slowing the business. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!