Manager, Governance, Risk & Compliance

🔥 13 hours ago

🇺🇸 United States – Remote

💵 $170k - $190k / year

⏰ Full Time

🟠 Senior

🔴 Lead

🚔 Compliance

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Doppel

Doppel

201 - 500 employees

Founded 2022

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Cybersecurity • Artificial Intelligence • SaaS

Doppel is an AI-native social engineering defense platform that protects organizations from AI-powered impersonation, phishing, deepfakes and multi-channel social engineering attacks. The platform unifies Digital Risk Protection, Human Risk Management (simulation and security awareness training), and Email Security to detect, correlate (via a Threat Graph), and remediate attacker infrastructure across domains, social media, ad networks, telco, marketplaces and dark channels. Doppel emphasizes agentic AI automation for detection, takedowns, phishing triage and scalable SOC workflows, and targets enterprise customers across industries such as financial services, healthcare, technology, retail and manufacturing.

📋 Description

• Define and execute the multi-year GRC strategy and roadmap; set priorities, budget, tooling, KPIs, and report program health, risk posture, and audit readiness to the CISO and executive leadership. • Hire, manage, coach, and develop a team of GRC analysts; set goals and career paths, run performance reviews, delegate framework and workstream ownership, and build a culture of rigor and continuous improvement. • Serve as executive owner for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and future frameworks; direct audit scoping, readiness assessments, remediation, evidence strategy, auditor relationships, and management review cycles. • Own enterprise and security risk frameworks, risk appetite, risk registers, risk review forums, assessments, escalation, remediation, and formal risk acceptance. • Design the common control framework and continuous-monitoring approach mapping ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST; oversee testing, exceptions, and corrective actions. • Own access governance, including access certifications, least-privilege standards, joiner/mover/leaver controls, and privileged access monitoring. • Set vendor risk strategy and tiering; oversee due diligence, contractual security and privacy requirements, and monitoring of critical suppliers, partners, and AI service providers. • Lead customer trust activities including security and privacy questionnaires, RFP responses, Trust Center content, and customer-facing security reviews; partner with Sales on enterprise deals. • Own policy and standards lifecycle, security and privacy awareness and role-based training, and privacy operations including DPIAs, data mapping, and data subject requests. • Sponsor incident response tabletop exercises and business continuity/disaster recovery testing; deliver executive and board-level dashboards. • Lead responsible AI governance under ISO 42001 and emerging regulation such as the EU AI Act, partnering with Product and Engineering.

🎯 Requirements

• 8+ years in GRC, security audit, or risk management, with at least 1 year managing people and owning a GRC or compliance program end to end. • Track record hiring, developing, and retaining high-performing GRC professionals, and of scaling a program and team through rapid company growth. • Executive-level ownership of SOC 2 Type II and ISO 27001 programs through multiple certification and surveillance cycles, including scoping, auditor selection and management, and remediation. • Hands-on experience with ISO 27701 and ISO 42001 or equivalent privacy and AI governance programs. • Deep command of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence sufficiency in cloud-first environments (AWS/Azure/GCP, SaaS). • Experience designing and operating enterprise risk management, including risk appetite, risk registers, risk forums, and formal risk acceptance with senior leadership. • Proven ability to run access certifications, third-party risk management, and customer security reviews at enterprise scale, and to select and implement GRC tooling and automation. • Strong executive communication skills: comfortable presenting risk and compliance posture to leadership, boards, auditors, and enterprise customers, and translating technical detail into business impact. • Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM are a plus.

Apply Now

Similar Jobs

🔥 14 hours ago

Teleperformance

10,000+ employees

📣 Marketing

📦 Logistics

🏥 Healthcare

Compliance Analyst supporting TP, a global digital business services provider, through compliance monitoring, audits, reporting, and controls testing. Improving compliance workflows with Google Workspace automation and dashboards.

🔥 17 hours ago

Solventum

10,000+ employees

🏥 Healthcare

📦 Logistics

💼 Consulting

Solventum healthcare compliance director leading global ethics monitoring, reporting, and risk programs. Advising executives and managing enterprise-wide compliance teams, technology, and assessments.

🔥 21 hours ago

Lonza

10,000+ employees

🧬 Biotechnology

💊 Pharmaceuticals

🏭 Manufacturing

Senior Director leading Lonza’s global quality regulatory intelligence, advocacy, and external engagement. Translating regulatory developments into compliant quality-system actions across life sciences operations.

🇺🇸 United States – Remote

💵 $200k - $243k / year

💰 $444.8M Post-IPO Debt - Lonza on 2023-11

⏰ Full Time

🟠 Senior

🚔 Compliance

🕒 Yesterday

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Security/compliance SME advancing Department of the Air Force ICAM capabilities for Koniag Government Services. Aligning Zero Trust architectures, ATO processes, and governance studies with DoD policy.

🕒 Yesterday

Stord

1001 - 5000

🍽️ Food & Beverage

💼 Consulting

📣 Marketing

Regional HSS and loss prevention manager executing safety, compliance, and asset-protection programs. Supporting Stord’s fulfillment and warehouse operations across a regional network.