Director, GRC
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Director, GRC scaling enterprise governance, risk, and compliance for Nextpower’s utility-scale solar technology platform. Leading ISO 27001 programs, audits, controls, and cross-functional certification efforts.
Responsibilities:
- Lead and scale Nextpower’s enterprise GRC program
- Develop a scalable GRC operating model covering governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions
- Define program governance, decision-making structures, steering committees, control ownership, and executive reporting
- Develop and maintain program plans, budgets, resource requirements, milestones, dependencies, and risk registers
- Coordinate Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, Human Resources, Internal Audit, and executive leadership
- Manage external implementation partners, auditors, and certification bodies
- Establish metrics and reporting on compliance status, program health, organizational risk, and remediation progress
- Translate regulatory and certification requirements into practical operating processes
- Ensure governance and compliance processes remain sustainable after initial certification
Requirements:
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field
- Ten or more years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or a related discipline
- Five or more years of experience leading complex, cross-functional security, compliance, audit, or certification programs
- Demonstrated experience leading an ISO 27001 implementation, certification, or ongoing ISMS program
- Strong understanding of information security risk assessment, control design, control testing, audit readiness, corrective actions, and continual improvement
- Experience working with external auditors, assessors, certification bodies, or regulators
- Experience developing and governing cybersecurity policies, standards, procedures, and control frameworks
- Strong program and project management skills, including experience managing schedules, budgets, dependencies, risks, and executive reporting
- Excellent written and verbal communication skills, including the ability to present complex risk and compliance matters to executive and non-technical audiences
- Demonstrated ability to influence stakeholders and drive accountability without direct reporting authority
- Ability to operate independently, manage competing priorities, and deliver results in a fast-paced, global environment
- Preferred: Experience with IEC 62443-4-1, IEC 62443-4-2, industrial control systems, operational technology, or product security
- Preferred: Experience with the EU Cyber Resilience Act or other product cybersecurity regulations
- Preferred: Experience establishing or operating a secure development lifecycle
- Preferred: Experience in renewable energy, manufacturing, industrial technology, critical infrastructure, hardware, embedded systems, or software products
- Preferred: Experience with third-party risk management and supplier assurance programs
- Preferred: Experience with GRC or compliance automation platforms such as Drata, Vanta, ServiceNow GRC, Archer, OneTrust, or similar tools
- Preferred: Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 31000, or COBIT
- Preferred: Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor
- Preferred: Master’s degree in a relevant field
Benefits:
- Equal opportunity employer
- Inclusive work environment committed to diversity


















