Назад
Company hidden
6 дней назад

Director, Compliance

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Compliance (GRC and IT Controls): Building and operating Riot’s unified controls framework, testing program, remediation lifecycle, and GRC platform with an accent on ISO 27001, SOC 2, NIST CSF, and SOX ITGC alignment. Focus on administering the GRC platform, automating evidence collection, integrating AWS/Azure and operational systems, and ensuring audit-ready controls across IT, mining sites, and data centers.

Location: Remote - US

Company

hirify.global builds digital infrastructure and focuses on powering and developing infrastructure for digital networks and communities.

What you will do

  • Design and maintain a unified controls framework mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, NIST CSF, and SOX ITGC.
  • Own the ISO 27001:2022 controls implementation and evidence track.
  • Execute control testing for design adequacy and operating effectiveness and maintain a continuous testing calendar.
  • Select, implement, configure, integrate, and administer the GRC platform as the system of record for controls, risks, and evidence.
  • Manage control issues, audit findings, remediation ownership, progress tracking, escalation, and closure validation.
  • Automate evidence collection and monitoring while working with IT, Security Engineering, mining sites, and data center teams.

Requirements

  • 8–12+ years of progressive GRC, IT audit, controls design, or compliance program experience.
  • Hands-on GRC platform administration experience, including control library configuration, evidence mapping, workflows, and integrations.
  • ISO 27001 Lead Implementer or Lead Auditor certification required.
  • Experience designing multi-standard controls frameworks and executing audit-quality control testing.
  • Experience managing POA&M issues and remediation lifecycles across cross-functional owners.
  • Technical fluency with AWS and Azure security configurations, API-based integrations, and automated evidence pipelines; Python or SQL scripting is useful.

Nice to have

  • CISA certification.
  • Experience in critical infrastructure, data centers, or digital asset environments.
  • Experience preparing SOC 2 evidence and facilitating auditor walkthroughs.
  • AI-assisted automation experience.

Culture & Benefits

  • Fast-paced environment focused on technical excellence, efficiency, and execution.
  • Competitive base salary with a bonus and sign-on equity grant.
  • Eligibility for equity incentive programs.
  • 401(k) plan with a company match.
  • Medical plan options, including 100% company-paid plans, plus gym memberships, pet insurance, and childcare discounts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →