Director, GRC

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Director, GRC scaling enterprise governance, risk, and compliance for Nextpower’s utility-scale solar technology platform. Leading ISO 27001 programs, audits, controls, and cross-functional certification efforts.

Responsibilities:

  • Lead and scale Nextpower’s enterprise GRC program
  • Develop a scalable GRC operating model covering governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions
  • Define program governance, decision-making structures, steering committees, control ownership, and executive reporting
  • Develop and maintain program plans, budgets, resource requirements, milestones, dependencies, and risk registers
  • Coordinate Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, Human Resources, Internal Audit, and executive leadership
  • Manage external implementation partners, auditors, and certification bodies
  • Establish metrics and reporting on compliance status, program health, organizational risk, and remediation progress
  • Translate regulatory and certification requirements into practical operating processes
  • Ensure governance and compliance processes remain sustainable after initial certification

Requirements:

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field
  • Ten or more years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or a related discipline
  • Five or more years of experience leading complex, cross-functional security, compliance, audit, or certification programs
  • Demonstrated experience leading an ISO 27001 implementation, certification, or ongoing ISMS program
  • Strong understanding of information security risk assessment, control design, control testing, audit readiness, corrective actions, and continual improvement
  • Experience working with external auditors, assessors, certification bodies, or regulators
  • Experience developing and governing cybersecurity policies, standards, procedures, and control frameworks
  • Strong program and project management skills, including experience managing schedules, budgets, dependencies, risks, and executive reporting
  • Excellent written and verbal communication skills, including the ability to present complex risk and compliance matters to executive and non-technical audiences
  • Demonstrated ability to influence stakeholders and drive accountability without direct reporting authority
  • Ability to operate independently, manage competing priorities, and deliver results in a fast-paced, global environment
  • Preferred: Experience with IEC 62443-4-1, IEC 62443-4-2, industrial control systems, operational technology, or product security
  • Preferred: Experience with the EU Cyber Resilience Act or other product cybersecurity regulations
  • Preferred: Experience establishing or operating a secure development lifecycle
  • Preferred: Experience in renewable energy, manufacturing, industrial technology, critical infrastructure, hardware, embedded systems, or software products
  • Preferred: Experience with third-party risk management and supplier assurance programs
  • Preferred: Experience with GRC or compliance automation platforms such as Drata, Vanta, ServiceNow GRC, Archer, OneTrust, or similar tools
  • Preferred: Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 31000, or COBIT
  • Preferred: Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor
  • Preferred: Master’s degree in a relevant field

Benefits:

  • Equal opportunity employer
  • Inclusive work environment committed to diversity