Назад
Company hidden
6 часов назад

Director, Risk Management (GRC)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Risk Management (GRC): Owning Riot's enterprise risk management, external audit relationships, SOC 1 and SOC 2 Type II audits, and ISO 27001 certification readiness with an accent on risk quantification, evidence pipelines, and remediation governance. Focus on building the enterprise risk register, coordinating SOX ITGC activities, developing executive KRI/KPI reporting, and maintaining continuous audit readiness across mining and data center operations.

Location: Remote - US

Company

hirify.global builds digital infrastructure and operates initiatives connected to mining sites and data centers.

What you will do

  • Own end-to-end SOC 1 and SOC 2 Type II audit execution, including scoping, walkthroughs, evidence collection, auditor liaison, management responses, and remediation tracking.
  • Lead ISO 27001:2022 audit readiness and certification activities, coordinating evidence and the certification audit relationship.
  • Coordinate SOX ITGC activities with Internal Audit by aligning control inventories, testing methodologies, walkthroughs, and remediation cadences.
  • Build and maintain the enterprise risk register, including the risk taxonomy, business-unit assessments, risk quantification, and quarterly updates across mining and data center operations.
  • Develop executive- and Board-level KRI/KPI reporting and run the POA&M program for audit findings and control gaps.
  • Build continuous audit-readiness infrastructure, including repeatable evidence pipelines and evidence-collection automation.

Requirements

  • 8–12+ years of progressive GRC, IT audit, or enterprise risk management experience.
  • Hands-on ownership of SOC 1 and/or SOC 2 Type II audits.
  • ISO 27001 Lead Implementer certification and credentialed implementation experience are required.
  • Working knowledge of SOX ITGC requirements at a publicly traded company and experience coordinating with Internal Audit.
  • Experience with enterprise risk registers, risk taxonomies, KRI/KPI reporting, external auditor relationships, and POA&M remediation lifecycles.
  • Familiarity with an additional security framework such as ISO 27001, NIST CSF, or NIST 800-53, plus strong executive and Board-level communication skills.

Nice to have

  • CISA or CRISC certification.
  • Experience in critical infrastructure, data centers, energy, or digital asset environments.
  • Exposure to OT/ICS risk environments.

Culture & Benefits

  • Remote work from the United States.
  • Base salary with bonus and sign-on equity grant.
  • Eligibility for equity incentive programs.
  • 401(k) retirement plan with company match.
  • Medical plan options, including 100% company-paid plans, plus gym memberships, pet insurance, and childcare discounts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →