
Director, Governance, Risk & Compliance
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in United States.
β’ Define and implement Doppel's long-term GRC strategy, operational model, and roadmap.
β’ Set priorities, allocate investments, and develop tooling and automation strategies, as well as KPIs and governance frameworks.
β’ Lead, develop, and expand the GRC team; define its structure, roles, responsibilities, and career advancement pathways.
β’ Hold strategy and executive responsibility for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and prospective frameworks.
β’ Ensure audit readiness, manage systems, control ownership, remediation, and relationships with auditors.
β’ Establish and enhance enterprise and security risk management, including risk appetite, assessment methodologies, escalation procedures, risk acceptance, and executive oversight.
β’ Formulate strategies for common controls and continuous assurance across ISO, SOC 2, NIST, privacy, and customer requirements.
β’ Oversee control testing, access risk, exceptions, corrective actions, evidence quality, and automation.
β’ Develop governance for vendor, partner, and AI-related risks, including tiering, due diligence, contracts, monitoring, and escalation.
β’ Manage customer security and privacy assurance, Trust Center content, security reviews, and RFP support.
β’ Collaborate with Sales and Customer Success to minimize security-related friction in enterprise transactions.
β’ Create scalable privacy and responsible AI governance in conjunction with Legal, Product, Engineering, and Security teams.
β’ Provide executive oversight for incident preparedness, business continuity, disaster recovery, and operational resilience.
β’ Deliver reports on enterprise risk, compliance posture, control effectiveness, third-party risk, and certification status to executives and the board.
β’ Represent Doppel in interactions with auditors, strategic clients, and external stakeholders.
β’ Over 10 years of experience in GRC, security risk, compliance, security audit, or related fields, with substantial experience leading teams and managing a GRC function or a similarly extensive program.
β’ Proven experience in building and scaling GRC programs and teams within a high-growth technology, SaaS, cybersecurity, or similarly complex environment.
β’ Demonstrated capability to advise senior executives and translate security, compliance, and regulatory risks into business decisions and priorities.
β’ Executive responsibility for SOC 2 Type II and ISO 27001 throughout multiple certification and surveillance cycles, including program strategy, scoping, auditor management, remediation, and management reviews.
β’ Preference for experience with ISO 27701, ISO 42001, or similar privacy and AI governance programs.
β’ In-depth knowledge of ISMS/PIMS/AIMS, Trust Services Criteria, common control frameworks, control assurance, and cloud-first evidence requirements.
β’ Expertise in designing and implementing enterprise risk management programs, including risk appetite, risk registers, governance forums, escalation processes, remediation, and formal risk acceptance.
β’ Experience in overseeing third-party risk, access governance, privacy, customer security assurance, and core GRC programs at scale.
β’ Proven ability to build high-performing teams, develop talent, establish ownership models, and adapt organizational structures.
β’ Experience in developing GRC tooling and automation strategies.
β’ Strong executive communication and influence skills, including the ability to present risk and compliance posture to executives, boards, auditors, and enterprise customers.
β’ Capability to operate effectively in ambiguous situations and prioritize competing business and risk requirements.
β’ Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, CIPP, or CIPM are advantageous.
β’ Competitive salary and performance-based bonuses.
β’ Comprehensive health, dental, and vision insurance plans.
β’ Flexible work arrangements and opportunities for remote work.
β’ Professional development and continuous learning opportunities.
β’ Collaborative and inclusive company culture.
biBerk Business Insurance
PingWind Inc. (SDVOSB)
The Standard
American Health Staffing Group
Get handpicked remote jobs straight to your inbox weekly.