Director, GRC

Next Power
Arizona
Workplace: RemoteFull timeFunction: Executive & General ManagementExperience: 10+ yearsEducation: bachelorsSkills: ["Leadership","Program and project management","Written and verbal communication","Stakeholder influence","Independent execution"]

Lead and scale the enterprise GRC program, establishing governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions. Serve as the central program leader coordinating cross-functional teams (Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, HR, Internal Audit, and executives), manage external partners and auditors, and define metrics and executive reporting to drive ongoing certification maintenance.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Next Power
Next Power
3 days ago

Director, GRC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Lead and scale the enterprise GRC program, establishing governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions. Serve as the central program leader coordinating cross-functional teams (Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, HR, Internal Audit, and executives), manage external partners and auditors, and define metrics and executive reporting to drive ongoing certification maintenance.
Location: Arizona
Workplace: Remote
Employment Type: Full time
Job Function: Executive & General Management
Seniority: Director level

Key Responsibilities

  • •Develop a scalable GRC operating model covering governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions.
  • •Define program governance, decision-making structures, steering committees, control ownership, and executive reporting.
  • •Build and maintain program plans, budgets, resource requirements, milestones, dependencies, and risk registers.
  • •Coordinate internal stakeholders and external implementation partners, auditors, and certification bodies.
  • •Establish metrics and reporting for leadership visibility into compliance status, program health, organizational risk, and remediation progress.

Key Requirements

  • •Bachelor’s degree in a related field such as Cybersecurity, Information Systems, Computer Science, Engineering, Business, or Risk Management.
  • •10+ years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or related work.
  • •5+ years leading complex, cross-functional security, compliance, audit, or certification programs.
  • •Demonstrated experience leading an ISO 27001 implementation, certification, or ongoing ISMS program.
  • •Strong understanding of information security risk assessment, control design/testing, audit readiness, corrective actions, and continual improvement.
Experience:10+ yearsEnterprise risk managementInformation securityGRCISO 27001ComplianceAudit readiness
Education:Bachelor's
Skills:LeadershipProgram and project managementWritten and verbal communicationStakeholder influenceIndependent execution
Certifications:CISSPCISMCISACRISCISO 27001 Lead ImplementerISO 27001 Lead Auditor
Languages:English
Tech Stack:ISO 27001IEC 62443-4-1IEC 62443-4-2NIST Cybersecurity FrameworkNIST SP 800-53CIS ControlsISO 31000COBITDrataVantaServiceNow GRCArcherOneTrust

Company Brief

Next Power
Develops, finances, and operates utility-scale renewable energy projects, focusing on solar photovoltaic and energy storage solutions to deliver clean power and grid services to commercial, industrial, and utility customers.
Industry: Renewable Energy
Website