Director, Enterprise Risk

AppFolio, Inc

  • Santa Barbara, CA
  • 2 days ago
  • $184,000–$230,000 Per Year
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • CISA - Certified Information Systems Auditorunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cadenceunmatched
  • Certified Public Accountant (CPA)unmatched
  • Committee of Sponsoring Organizations of the Treadway Commission (COSO)unmatched
  • Communication Skillsunmatched
  • Congestive Heart Failureunmatched
  • Cross-Functionalunmatched
  • External Auditunmatched
  • Internal Auditunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Metricsunmatched
  • Problem Solving Skillsunmatched
  • Product Engineeringunmatched
  • Real Estateunmatched
  • Reporting Skillsunmatched
  • Research & Development (R&D)unmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Succession Planningunmatched
  • Talent Managementunmatched
  • Team Lead/Managerunmatched

Description

 

AppFolio is more than a company. We’re a community of dreamers, big thinkers, problem solvers, active listeners, and multipliers. At every opportunity, we set the pace while delivering innovation built to carry real estate into the future. One in which every experience feels effortless, yet meaningful. Where customers are empowered to take on any opportunity. We show up as one team, connected by our values to be a force for good. Because together, we have the power to create extraordinary outcomes for our customers, our communities, and ourselves.

 

The Director, Enterprise Risk will mature and integrate AppFolio’s Enterprise Risk Management (ERM) framework, lead the Technology Compliance function, and build a new Risk Analysis capability — while partnering with first-line teams so that risk management accelerates fast, well-informed decisions rather than constraining them.

 

Your impact 

  • Mature and integrate AppFolio’s ERM framework and program in partnership with senior leaders and cross-functional stakeholders, and support the Enterprise Risk Committee (ERC) that administers the program.

  • Build a new Risk Analysis capability for coordinating risk identification, assessment, and monitoring activities across the business.

  • Lead the Technology Compliance team — owning compliance policies, ongoing monitoring, and audit readiness across SOX and SOC reviews, and supporting a Common Controls Framework (CCF).

  • Stand up a continuous, rolling risk-identification cadence that surfaces and escalates emerging risks in real time, complementing the annual enterprise risk assessment and the quarterly ERC and RCOC cycles.

  • Partner with and enable first-line functions — including R&D (Product and Engineering) — embedding risk-informed decision-making into their workflows so risk is a natural, owned part of moving quickly.

  • Assist management with risk-related reporting to the Board, and communicate ERM program updates to the Risk & Compliance Oversight Committee (RCOC).

  • Advance the three-lines-of-defense model and the broader GRC strategy, aligning ERM activity, cadence, and Top Risks with the company’s operating model and OKRs.

 

Qualifications 

  • Extensive experience in enterprise risk management, GRC, internal audit, or a closely related second-line function, including maturing or scaling an ERM program.

  • A track record of building and leading teams, developing talent through individual development plans (IDPs), and planning succession for key roles.

  • Strong command of enterprise risk frameworks and the three-lines-of-defense model (e.g., COSO ERM), plus working knowledge of technology compliance domains such as SOX ITGCs and SOC 1 / SOC 2.

  • Demonstrated ability to influence senior leaders and to communicate risk clearly to executive and Board-level audiences, including audit or risk committees.

  • Experience partnering with first-line functions — ideally R&D, Product, or Engineering — to embed risk-informed decision-making without slowing the business.

  • A data-driven approach to risk monitoring, including defining risk metrics and enhancing monitoring and reporting capabilities.

  • Relevant professional certifications are a plus (e.g., CRISC, CRMA, CISA, CPA, or CISSP).

 

Must have

  • 5+ years of progressive experience in enterprise risk management, internal audit, GRC, or technology compliance, including direct people-leadership experience.

  • Deep, hands-on understanding of enterprise risk frameworks and the three-lines-of-defense model, with experience operating or maturing an ERM program.

  • Proven ownership of technology compliance and audit readiness (SOX and/or SOC), including serving as a primary liaison to internal and external auditors.

  • Excellent executive communication and stakeholder-management skills, with experience reporting to senior leadership and/or a Board committee.

 

Location

This position is based in our San Diego, CA, or our Santa Barbara office. Find out more about our locations by visiting our site

All late-stage candidates complete an in-person meeting with an AppFolian as part of our hiring process.

 

Compensation & Benefits

The compensation that we reasonably expect to pay for this role is: $184,000 - $230,000 base pay. The actual compensation for this role will be determined by a variety of factors, including but not limited to the candidate’s skills, education, experience, and internal equity.

Please note that compensation is just one aspect of a comprehensive Total Rewards package. The compensation range listed here does not include additional benefits or any discretionary bonuses you may be eligible for based on your role and/or employment type.

Regular full-time employees are eligible for benefits - see here.

#LI-KB1

Numbers & Facts

LocationSanta Barbara, CA
Salary$184,000–$230,000 Per Year

Similar Jobs

See more jobs