Manager, Governance, Risk & Compliance

atDoppelRemoteUS flagUnited StatesFull-timeComplianceSeniorLead$170k – $190k/year

Posted 11 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop and implement a multi-year Governance, Risk, and Compliance (GRC) strategy and roadmap; establish priorities, budget, tools, KPIs, and report on program health, risk posture, and audit readiness to the Chief Information Security Officer (CISO) and executive leadership.

• Recruit, manage, mentor, and cultivate a team of GRC analysts; set objectives and career trajectories, conduct performance evaluations, assign framework and workstream responsibilities, and foster a culture of rigor and continuous improvement.

• Act as the executive owner for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and prospective frameworks; guide audit scoping, readiness evaluations, remediation strategies, evidence collection, auditor relationships, and management review cycles.

• Oversee enterprise and security risk frameworks, risk appetite, risk registers, risk review forums, assessments, escalation processes, remediation efforts, and formal risk acceptance.

• Create a common control framework and continuous monitoring strategy that aligns with ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST; supervise testing, exceptions, and corrective actions.

• Manage access governance, encompassing access certifications, least-privilege standards, joiner/mover/leaver controls, and privileged access monitoring.

• Establish vendor risk strategies and tiering; supervise due diligence, contractual security and privacy obligations, and the oversight of critical suppliers, partners, and AI service providers.

• Direct customer trust initiatives including security and privacy questionnaires, RFP responses, Trust Center content, and customer-facing security assessments; collaborate with Sales on enterprise contracts.

• Oversee policy and standards lifecycle, security and privacy awareness training, role-based training, and privacy operations including Data Protection Impact Assessments (DPIAs), data mapping, and data subject requests.

• Champion incident response tabletop exercises and business continuity/disaster recovery testing; present executive and board-level dashboards.

• Guide responsible AI governance under ISO 42001 and emerging regulations like the EU AI Act, collaborating with Product and Engineering teams.


⛳️ Requirements

• Over 8 years of experience in GRC, security audit, or risk management, including a minimum of 1 year in a managerial role overseeing a GRC or compliance program from start to finish.

• Proven history of hiring, developing, and retaining top-tier GRC professionals, as well as scaling programs and teams through periods of rapid company growth.

• Executive-level accountability for SOC 2 Type II and ISO 27001 programs during multiple certification and surveillance cycles, including scoping, auditor selection, management, and remediation.

• Practical experience with ISO 27701 and ISO 42001 or similar privacy and AI governance frameworks.

• Extensive knowledge of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence adequacy in cloud-first environments (AWS/Azure/GCP, SaaS).

• Experience in designing and managing enterprise risk management, including risk appetite, risk registers, risk forums, and formal risk acceptance in collaboration with senior leadership.

• Demonstrated capability to conduct access certifications, third-party risk management, and customer security assessments at an enterprise level, along with selecting and implementing GRC tools and automation.

• Exceptional executive communication skills: adept at presenting risk and compliance status to leadership, boards, auditors, and enterprise clients, while translating technical details into business implications.

• Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM are advantageous.


🏝️ Benefits

• Competitive salary and performance-based bonuses.

• Comprehensive health, dental, and vision insurance.

• Generous paid time off and flexible working arrangements.

• Opportunities for professional development and certification reimbursement.

• Collaborative and inclusive company culture.

People also viewed

Freudenberg Group6 hours ago

Specialist, Transfer Pricing Compliance

RO flagRomania OnlyFull-timeCompliance
ApplyView job
Secfix7 hours ago

GRC Specialist, German-speaking

DE flagGermany, +4 more countriesFull-timeCompliance
ApplyView job
Mercor8 hours ago

Privacy, Regulatory Compliance Evaluator

US flagUnited States OnlyFreelanceCompliance$80 – $120/hour
ApplyView job
Lifelancer9 hours ago

Regulatory Labeling Associate Director

US flagMassachusetts OnlyFull-timeCompliance$161.6k – $242.4k/year
ApplyView job
Teleperformance12 hours ago

Compliance Analyst

US flagArizona, +5 more statesFull-timeCompliance$45k – $55k/year
ApplyView job
Maxwell13 hours ago

Contract Due Diligence Compliance Analyst

US flagUnited States OnlyFreelanceCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers