Director, GRC
Posted 1 day ago
Posted 1 day ago
This is a fully remote position, open to applicants in Arizona.
• Oversee and expand Nextpower’s enterprise Governance, Risk, and Compliance (GRC) program.
• Create a scalable GRC operating framework that encompasses governance, risk management, compliance, policy management, audit preparedness, evidence management, and corrective actions.
• Establish program governance, decision-making frameworks, steering committees, control ownership, and executive reporting structures.
• Develop and sustain program plans, budgets, resource needs, milestones, dependencies, and risk registers.
• Collaborate with Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, Human Resources, Internal Audit, and executive leadership teams.
• Oversee external implementation partners, auditors, and certification organizations.
• Set up metrics and reporting for compliance status, program health, organizational risk, and remediation progress.
• Convert regulatory and certification requirements into actionable operating processes.
• Ensure that governance and compliance processes remain viable post-initial certification.
• A bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a similar field.
• A minimum of ten years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or a comparable domain.
• At least five years of experience in leading complex, cross-functional security, compliance, audit, or certification initiatives.
• Proven experience in leading an ISO 27001 implementation, certification, or ongoing Information Security Management System (ISMS) program.
• Strong grasp of information security risk assessment, control design, control testing, audit readiness, corrective actions, and ongoing improvement.
• Experience interacting with external auditors, assessors, certification organizations, or regulatory bodies.
• Background in developing and governing cybersecurity policies, standards, procedures, and control frameworks.
• Excellent program and project management capabilities, including managing schedules, budgets, dependencies, risks, and executive reporting.
• Outstanding written and verbal communication skills, with the ability to convey complex risk and compliance issues to both executive and non-technical audiences.
• Proven ability to influence stakeholders and promote accountability without direct reporting authority.
• Capacity to work independently, handle competing priorities, and achieve results in a fast-paced, global setting.
• Preferred: Experience with IEC 62443-4-1, IEC 62443-4-2, industrial control systems, operational technology, or product security.
• Preferred: Familiarity with the EU Cyber Resilience Act or other product cybersecurity regulations.
• Preferred: Experience in establishing or managing a secure development lifecycle.
• Preferred: Background in renewable energy, manufacturing, industrial technology, critical infrastructure, hardware, embedded systems, or software products.
• Preferred: Experience with third-party risk management and supplier assurance initiatives.
• Preferred: Familiarity with GRC or compliance automation platforms such as Drata, Vanta, ServiceNow GRC, Archer, OneTrust, or similar tools.
• Preferred: Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 31000, or COBIT.
• Preferred: Professional certifications like CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
• Preferred: A master’s degree in a relevant field.
• Equal opportunity employer.
• Inclusive work environment dedicated to diversity.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.