Назад
Company hidden
10 дней назад

Director, Governance, Risk & Compliance (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Governance, Risk & Compliance (Cybersecurity): Building and scaling Doppel’s governance, risk, compliance, privacy, third-party risk, control assurance, and customer trust programs with an accent on SOC 2, ISO certifications, enterprise risk governance, and responsible AI. Focus on leading the GRC organization, strengthening continuous control assurance, advising executives and the board, and managing complex regulatory and customer security requirements.

Location: US Remote

Company

hirify.global is a cybersecurity platform that uses adaptive AI SOC agents and expert analysts to detect and disrupt phishing, impersonation, and online fraud infrastructure at scale.

What you will do

  • Define and execute the multi-year GRC strategy, operating model, roadmap, tooling strategy, KPIs, and governance mechanisms.
  • Build, lead, and scale a high-performing GRC organization with clear ownership, career paths, and accountability.
  • Own compliance and certification programs for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and future frameworks.
  • Establish enterprise risk governance, including risk appetite, assessments, escalation thresholds, risk acceptance, and executive review.
  • Scale common control frameworks, continuous assurance, control testing, access risk governance, remediation, and evidence quality.
  • Lead third-party risk, customer security assurance, privacy and responsible AI governance, organizational resilience, and executive and board reporting.

Requirements

  • 10+ years of experience across GRC, security risk, compliance, security audit, or related disciplines, including significant team leadership.
  • Experience building and scaling GRC programs and teams in a high-growth technology, SaaS, cybersecurity, or similarly complex environment.
  • Executive ownership of SOC 2 Type II and ISO 27001 through multiple certification and surveillance cycles.
  • Deep understanding of ISMS, PIMS, AIMS, Trust Services Criteria, common control frameworks, control assurance, and cloud-first evidence requirements.
  • Experience with enterprise risk management, third-party risk, access governance, privacy, customer security assurance, and GRC automation.
  • Strong communication and influence skills with executives, boards, auditors, and enterprise customers; relevant certifications are a plus.

Culture & Benefits

  • Remote work arrangement for the US.
  • Cross-functional collaboration with Security, Engineering, Product, IT, Legal, People, Finance, Sales, and Customer Success.
  • Opportunity to shape risk, compliance, privacy, customer trust, and responsible AI programs as the company scales.
  • Work on technology designed to protect brands, people, and data from digital deception and online fraud.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →