6 часов назад
Director, Risk Management (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director, Risk Management (GRC): Owning Riot's enterprise risk management, external audit relationships, SOC 1 and SOC 2 Type II audits, and ISO 27001 certification readiness with an accent on risk quantification, evidence pipelines, and remediation governance. Focus on building the enterprise risk register, coordinating SOX ITGC activities, developing executive KRI/KPI reporting, and maintaining continuous audit readiness across mining and data center operations.
Location: Remote - US
Company
builds digital infrastructure and operates initiatives connected to mining sites and data centers.
What you will do
- Own end-to-end SOC 1 and SOC 2 Type II audit execution, including scoping, walkthroughs, evidence collection, auditor liaison, management responses, and remediation tracking.
- Lead ISO 27001:2022 audit readiness and certification activities, coordinating evidence and the certification audit relationship.
- Coordinate SOX ITGC activities with Internal Audit by aligning control inventories, testing methodologies, walkthroughs, and remediation cadences.
- Build and maintain the enterprise risk register, including the risk taxonomy, business-unit assessments, risk quantification, and quarterly updates across mining and data center operations.
- Develop executive- and Board-level KRI/KPI reporting and run the POA&M program for audit findings and control gaps.
- Build continuous audit-readiness infrastructure, including repeatable evidence pipelines and evidence-collection automation.
Requirements
- 8–12+ years of progressive GRC, IT audit, or enterprise risk management experience.
- Hands-on ownership of SOC 1 and/or SOC 2 Type II audits.
- ISO 27001 Lead Implementer certification and credentialed implementation experience are required.
- Working knowledge of SOX ITGC requirements at a publicly traded company and experience coordinating with Internal Audit.
- Experience with enterprise risk registers, risk taxonomies, KRI/KPI reporting, external auditor relationships, and POA&M remediation lifecycles.
- Familiarity with an additional security framework such as ISO 27001, NIST CSF, or NIST 800-53, plus strong executive and Board-level communication skills.
Nice to have
- CISA or CRISC certification.
- Experience in critical infrastructure, data centers, energy, or digital asset environments.
- Exposure to OT/ICS risk environments.
Culture & Benefits
- Remote work from the United States.
- Base salary with bonus and sign-on equity grant.
- Eligibility for equity incentive programs.
- 401(k) retirement plan with company match.
- Medical plan options, including 100% company-paid plans, plus gym memberships, pet insurance, and childcare discounts.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 часов назад
Sr. Staff Risk Management Analyst (Cybersecurity)
2 дня назад
Senior GRC Manager (Cybersecurity)
2 дня назад
Senior GRC Content Engineer (Cybersecurity)
4 дня назад
Staff Security Engineer, GRC
245 916 - 286 902$
1 день назад
Compliance Engineering Lead (Security)
6 дней назад
InfoSec Analyst II, Trust (AI Governance)
96 000 - 160 000$