5 часов назад
Director, GRC (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director, GRC (Cybersecurity): Building and scaling an enterprise GRC program covering governance, risk management, compliance, audit readiness, and assurance with an accent on ISO 27001, control ownership, and cross-functional accountability. Focus on coordinating certification programs, managing auditors and external partners, and developing executive reporting for organizational risk and remediation progress.
Location: Arizona, USA — Remote
Company
develops integrated clean energy technology combining structural, electrical, and digital solutions for utility-scale solar power plants.
What you will do
- Develop and scale the enterprise GRC operating model across governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions.
- Define program governance, decision-making structures, steering committees, control ownership, and executive reporting.
- Manage program plans, budgets, resources, milestones, dependencies, risk registers, metrics, and remediation reporting.
- Coordinate Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, Human Resources, Internal Audit, executive stakeholders, consultants, auditors, and certification bodies.
- Lead GRC work from discovery through certification and ongoing maintenance, ensuring that compliance processes remain sustainable.
Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field.
- 10+ years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or a related discipline.
- 5+ years leading complex, cross-functional security, compliance, audit, or certification programs.
- Demonstrated experience leading an ISO 27001 implementation, certification, or ongoing ISMS program.
- Experience with information security risk assessment, control design and testing, audit readiness, corrective actions, cybersecurity policies, standards, and control frameworks.
- Experience working with external auditors, assessors, certification bodies, or regulators, plus strong program management, executive communication, and stakeholder-influence skills.
Nice to have
- Experience with IEC 62443, industrial control systems, operational technology, product security, or the EU Cyber Resilience Act.
- Experience establishing a secure development lifecycle or working in renewable energy, manufacturing, industrial technology, critical infrastructure, hardware, embedded systems, or software products.
- Experience with third-party risk management, supplier assurance, or GRC platforms such as Drata, Vanta, ServiceNow GRC, Archer, or OneTrust.
- Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 31000, or COBIT.
- Certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor, or a relevant master’s degree.
Culture & Benefits
- Remote work arrangement based in Arizona, USA.
- Work within global teams focused on clean energy infrastructure and the energy transition.
- Equal opportunity and commitment to an inclusive workplace.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →