NIKE, Inc. 팀의 일원이 되세요

NIKE, Inc.는 세계 최고 운동선수들의 복장을 책임지는 것 그 이상의 일을 합니다. NIKE, Inc.는 잠재력을 탐구하고, 장벽을 허물고, 가능성의 경계를 확장해 나가는 곳입니다. NIKE, Inc.는 성장하고, 생각하고, 꿈꾸고, 창조할 수 있는 인재를 찾습니다. NIKE, Inc.의 문화는 다양성을 포용하고 상상력을 장려하며 더욱 발전해갑니다. 우리 브랜드는 성취자, 리더, 선구자를 찾고 있습니다. NIKE, Inc.에서는 모두가 끊임없이 진화하는 도전적인 경기에 자신의 기술과 열정을 불어넣습니다.

WHO YOU WILL WORK WITH

 

The Director of Governance, Risk and Compliance (GRC) extends Nike’s Global GRC team and is accountable for GRC leadership spanning the India Technology Center and global enterprise priorities. This is a critical leadership role responsible for strengthening compliance (with emphasis on SOX and 

cybersecurity regulations), risk management (with emphasis on third-party cyber risk and cybersecurity risk assessments), governance (including risk lifecycle management and the risk register in ServiceNow GRC), and technical recovery management—while helping mature global standards, tooling, assurance, and reporting in partnership with Global GRC, Global Technology, and cross-functional leaders across finance, audit, legal, procurement, and security/risk forums as applicable.

 

WHO WE ARE LOOKING FOR

The candidate needs to have large-scale, enterprise GRC experience in highly matrixed, multinational technology organizations with sustained impact across the domains above. The candidate needs to be both deeply experienced in global GRC practice and platforms (notably ServiceNow GRC) and highly skilled in people leadership, including multiple years managing a large team of direct reports (typically 15+) with a proven record of building highly functional teams, developing talent, and driving trust-based teamwork and cross-functional collaboration with peers and senior leaders.

  • People leadership at scale (direct reports) — 5+ years people management with accountability for a large team of direct reports (typically 15+), including hiring, performance management, coaching, and organizational design that scales quality and speed.
  • Leadership & technical depth — 12+ years in technology risk, cybersecurity risk, IT audit, and/or GRC, with sustained impact on complex, global technology and risk agendas.
  • Building highly functional teams — Proven track record building highly functional teams: clear roles, operating rhythm, quality bar, and sustainable ways of working across time zones.
  • Talent development & culture — Demonstrated success developing talent (coaching, progression, succession depth) and fostering a positive team culture grounded in trust, teamwork, and cross-functional collaboration.
  • Matrixed leadership & partnerships — Extensive experience leading and influencing in a highly matrixed environment; proven ability to build strong relationships and partnerships with peers and senior leaders across technology, finance, legal, procurement, audit, and global GRC—while maintaining clarity and accountability for direct reports.
  • Global + regional operating model — Demonstrated success balancing global consistency (policy, platform, metrics) with India delivery realities and effective partnership across geographies.
  • GRC program execution — Proven experience running components of a global GRC program (policies, standards, exceptions, metrics, governance forums) with accountability for outcomes beyond a single site.
  • Compliance — Strong command of SOX IT/general controls and evidence practices; familiarity with cybersecurity regulations and assurance expectations for multinational technology organizations.
  • Cybersecurity frameworks & control standards — Deep knowledge of cybersecurity control and compliance frameworks (for example, NIST CSF and ISO 27001) and practical experience applying them to enterprise control environments, risk prioritization, and assurance.
  • Third-party cyber risk — Deep experience in global third-party cyber risk programs (tiering, diligence, contractual security requirements, issue management, reporting), including offshore/nearshore delivery contexts.
  • Cybersecurity risk assessments — Experience leading, governing, or quality-reviewing cyber and technology risk assessments for global platforms and initiatives, aligned to enterprise risk appetite.
  • Technical recovery / resilience — Experience governing technical recovery alignment across critical services and regions (DR/BCP expectations, testing governance, RTO/RPO discipline, coordination with incident/resilience teams).
  • Governance & risk lifecycle — Expertise in end-to-end risk lifecycle management and risk register quality (ownership, scoring, treatment plans, monitoring, closure) at enterprise scale.
  • ServiceNow GRC — Strong hands-on experience with ServiceNow GRC (or comparable platforms), including workflow improvement, libraries, attestations, dashboards, and adoption across distributed owners globally.
  • Education — Bachelor’s degree required; advanced degree or certifications a plus (e.g., CISSP, CISM, CRISC, CISA, GRCP).

 

WHAT YOU WILL WORK ON

 

Lead a large direct-report GRC team for Nike’s India Technology Center in support of global priorities in a highly matrixed model. Drive compliance, third-party cyber risk, assessments, technical recovery, ServiceNow GRC governance, global partnership, and KPIs across the enterprise.

  • Direct-report leadership (scale + culture) — Lead, organize, and develop a large team of direct reports (15+), including operating rhythm, quality expectations, and career growth; role-model trust, collaboration, and inclusive teamwork while investing in talent development and a healthy team culture.
  • Dual-scope leadership — Deliver GRC outcomes for the India Technology Center while contributing materially to global GRC priorities (standards, governance cadence, escalations, cross-region coordination).
  • Matrix partnership — Operate effectively across a highly matrixed model by aligning priorities, clarifying decision paths, and sustaining strong partnerships with peers and senior leaders globally.
  • Cybersecurity training & awareness (ITC) — Extend global cybersecurity training and awareness capabilities, programs, and stakeholder engagements to the India Technology Center (ITC), driving adoption, relevance for local audiences, and sustained participation while staying aligned to enterprise standards, campaigns, and reporting expectations.
  • Compliance (SOX & cybersecurity regulations) — Support SOX and applicable cybersecurity regulatory obligations with a global lens: sustainable control operation, testing readiness, issue remediation, and coordination with Finance, Internal Audit, Legal, and Global GRC.
  • Third-party cyber risk — Advance Nike’s third-party cyber risk model across engagements relevant to India and global technology delivery, with consistent global rigor and clear remediation ownership.
  • Cybersecurity risk assessments — Govern and/or sponsor cybersecurity risk assessments for high-impact global initiatives and platforms; ensure outputs are prioritized, actionable, and aligned to global risk appetite.
  • Technical recovery management — Govern technical recovery alignment for critical services across global and India-supported footprints: standards adherence, testing governance, evidence expectations, and remediation of resilience gaps.
  • Governance & risk lifecycle — Ensure disciplined risk lifecycle management and credible enterprise risk register posture for priorities owned or heavily supported from India; drive accountability with global and regional risk and control owners.
  • ServiceNow GRC — Partner across Global GRC and technology teams to strengthen ServiceNow GRC usage: workflows, libraries, attestations, reporting, and data quality in support of risk lifecycle, assurance, and audit readiness.
  • Global partnership & representation — Serve as a trusted bridge between India technology leadership and Global GRC—surfacing themes early, aligning priorities, and enabling timely enterprise risk decisions.
  • Metrics — Define and socialize global-relevant GRC KPIs/KRIs focused on risk reduction, control effectiveness, and remediation closure where India contributes materially; reinforce pragmatic controls and early risk engagement in engineering and vendor workflows worldwide.

 

 

 

기대할 수 있는 사항

채용 계획

01 지원

나이키 팀은 다양한 기술과 지식, 의견, 아이디어, 배경을 가진 사람들로 구성되어 있습니다. 직무 소개서와 부서, 팀을 살펴보며 내게 맞는 역할을 찾아보세요. 적합한 직무를 찾을 수 있기를 바랍니다.

02 채용 담당자와의 만남 또는 평가 진행

본사 직무에 선발되면 면접 과정을 시작하고자 채용 담당자가 연락을 드립니다. 해당 과정을 진행하는 동안 이 담당자와 주로 연락하게 됩니다. 리테일 직무의 경우 채팅과 퀴즈 등 양방향 평가가 진행되며, 완료하는 데는 약 10~20분이 소요됩니다. 어떤 직무에 지원하시든, 나이키는 여러분에 관한 모든 정보를 듣고 싶습니다. 그러니 여러분이 어떻게 세계 최고 수준의 서비스를 제공할 것인지, 여러분만의 특별함은 무엇인지 주저하지 말고 보여주시길 바랍니다.

03 면접

이 단계를 자신 있게 시작하기 위해 필요한 정보를 조사하고 나이키가 추구하는 요소를 파악해 보세요. 또 여러분과 여러분의 배경에 관해 자세히 알기 위해 고안된 질문에 답할 준비를 갖추세요.

야외 환경에서 웃고 포옹하는 두 사람