Director, GRC

Job not on LinkedIn

🔥 0 minutes ago

🌵 Arizona – Remote

infoinfo

⏰ Full Time

🔴 Lead

🚔 Compliance

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Nextracker Inc.

Nextracker Inc.

1001 - 5000 employees

Founded 2013

💼 Consulting

📦 Logistics

🏭 Manufacturing

Consulting • Logistics • Manufacturing

Nextracker Inc. is a provider of solar energy solutions that designs, supplies, and supports utility-scale solar projects from design through operations. The company delivers specialized solar tracking hardware, installation logistics, training, and ongoing operations support, and pairs field-proven equipment with data-driven “solar intelligence” to improve yield, speed deployments, and ensure reliable performance in challenging environments worldwide.

📋 Description

• Lead and scale Nextpower’s enterprise GRC program • Develop a scalable GRC operating model covering governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions • Define program governance, decision-making structures, steering committees, control ownership, and executive reporting • Develop and maintain program plans, budgets, resource requirements, milestones, dependencies, and risk registers • Coordinate Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, Human Resources, Internal Audit, and executive leadership • Manage external implementation partners, auditors, and certification bodies • Establish metrics and reporting on compliance status, program health, organizational risk, and remediation progress • Translate regulatory and certification requirements into practical operating processes • Ensure governance and compliance processes remain sustainable after initial certification

🎯 Requirements

• Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field • Ten or more years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or a related discipline • Five or more years of experience leading complex, cross-functional security, compliance, audit, or certification programs • Demonstrated experience leading an ISO 27001 implementation, certification, or ongoing ISMS program • Strong understanding of information security risk assessment, control design, control testing, audit readiness, corrective actions, and continual improvement • Experience working with external auditors, assessors, certification bodies, or regulators • Experience developing and governing cybersecurity policies, standards, procedures, and control frameworks • Strong program and project management skills, including experience managing schedules, budgets, dependencies, risks, and executive reporting • Excellent written and verbal communication skills, including the ability to present complex risk and compliance matters to executive and non-technical audiences • Demonstrated ability to influence stakeholders and drive accountability without direct reporting authority • Ability to operate independently, manage competing priorities, and deliver results in a fast-paced, global environment • Preferred: Experience with IEC 62443-4-1, IEC 62443-4-2, industrial control systems, operational technology, or product security • Preferred: Experience with the EU Cyber Resilience Act or other product cybersecurity regulations • Preferred: Experience establishing or operating a secure development lifecycle • Preferred: Experience in renewable energy, manufacturing, industrial technology, critical infrastructure, hardware, embedded systems, or software products • Preferred: Experience with third-party risk management and supplier assurance programs • Preferred: Experience with GRC or compliance automation platforms such as Drata, Vanta, ServiceNow GRC, Archer, OneTrust, or similar tools • Preferred: Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 31000, or COBIT • Preferred: Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor • Preferred: Master’s degree in a relevant field

🏖️ Benefits

• Equal opportunity employer • Inclusive work environment committed to diversity

Apply Now

Similar Jobs

🔥 1 hour ago

Ultragenyx

501 - 1000

🏥 Healthcare

💼 Consulting

📦 Logistics

Executive Director leading global pharmacovigilance operations, quality, and compliance at rare-disease biopharma Ultragenyx. Ensuring inspection-ready systems support clinical development, approvals, commercialization, and expansion.

🔥 5 hours ago

Mariner

1001 - 5000

💼 Consulting

🛡️ Insurance

💸 Finance

Director of Cyber GRC protecting Mariner’s financial services organization through governance, vendor risk, and AI oversight. Leading compliance, awareness, and quantified cyber-risk reporting.

🕒 Yesterday

InnovAge

1001 - 5000

🏥 Healthcare

⚕️ Healthcare Insurance

VP of Compliance overseeing healthcare audits, regulatory oversight, and corrective actions for InnovAge’s PACE/LIFE senior-care programs. Managing compliance teams and translating clinical mandates into operational workflows.

🕒 Yesterday

Cardinal Health

10,000+ employees

📦 Logistics

🏭 Manufacturing

🏥 Healthcare

Regulatory Affairs Manager leading global medical-device labeling, packaging, and digital-asset compliance for Cardinal Health, a healthcare products and data solutions provider. Driving UDI, environmental labeling, regulatory strategy, and cross-functional quality processes across worldwide markets.

🕒 Yesterday

Chamber

1 - 10

🏥 Healthcare

⚕️ Healthcare Insurance

☁️ SaaS

Head of Compliance building healthcare, clinical, government-program, and security compliance for Chamber’s cardiology platform. Creating audits, controls, and risk frameworks as the company expands.