Manager, Governance, Risk & Compliance
Posted 12hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior GRC leader scaling Doppel’s security, privacy, compliance, and AI governance program. Owning certifications, enterprise risk, controls, customer trust, and a growing GRC team.
Responsibilities:
- Define and execute the multi-year GRC strategy and roadmap; set priorities, budget, tooling, KPIs, and report program health, risk posture, and audit readiness to the CISO and executive leadership.
- Hire, manage, coach, and develop a team of GRC analysts; set goals and career paths, run performance reviews, delegate framework and workstream ownership, and build a culture of rigor and continuous improvement.
- Serve as executive owner for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and future frameworks; direct audit scoping, readiness assessments, remediation, evidence strategy, auditor relationships, and management review cycles.
- Own enterprise and security risk frameworks, risk appetite, risk registers, risk review forums, assessments, escalation, remediation, and formal risk acceptance.
- Design the common control framework and continuous-monitoring approach mapping ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST; oversee testing, exceptions, and corrective actions.
- Own access governance, including access certifications, least-privilege standards, joiner/mover/leaver controls, and privileged access monitoring.
- Set vendor risk strategy and tiering; oversee due diligence, contractual security and privacy requirements, and monitoring of critical suppliers, partners, and AI service providers.
- Lead customer trust activities including security and privacy questionnaires, RFP responses, Trust Center content, and customer-facing security reviews; partner with Sales on enterprise deals.
- Own policy and standards lifecycle, security and privacy awareness and role-based training, and privacy operations including DPIAs, data mapping, and data subject requests.
- Sponsor incident response tabletop exercises and business continuity/disaster recovery testing; deliver executive and board-level dashboards.
- Lead responsible AI governance under ISO 42001 and emerging regulation such as the EU AI Act, partnering with Product and Engineering.
Requirements:
- 8+ years in GRC, security audit, or risk management, with at least 1 year managing people and owning a GRC or compliance program end to end.
- Track record hiring, developing, and retaining high-performing GRC professionals, and of scaling a program and team through rapid company growth.
- Executive-level ownership of SOC 2 Type II and ISO 27001 programs through multiple certification and surveillance cycles, including scoping, auditor selection and management, and remediation.
- Hands-on experience with ISO 27701 and ISO 42001 or equivalent privacy and AI governance programs.
- Deep command of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence sufficiency in cloud-first environments (AWS/Azure/GCP, SaaS).
- Experience designing and operating enterprise risk management, including risk appetite, risk registers, risk forums, and formal risk acceptance with senior leadership.
- Proven ability to run access certifications, third-party risk management, and customer security reviews at enterprise scale, and to select and implement GRC tooling and automation.
- Strong executive communication skills: comfortable presenting risk and compliance posture to leadership, boards, auditors, and enterprise customers, and translating technical detail into business impact.
- Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM are a plus.

















