治理、风险与合规经理
Manager, Governance, Risk & Compliance
职位描述
Doppel 正在寻找一位治理、风险与合规经理,负责从头到尾建立和扩展我们的 GRC 项目。你将领导一支 GRC 分析师团队,并为认证、风险管理、控制保证、第三方风险、隐私和客户信任等方面制定战略、路线图和运营模式。
作为 Doppel 的 GRC 负责人,你需要确保 SOC 2、ISO 27001、ISO 27701 和 ISO 42001 达到客户对安全公司的期望标准,同时构建系统和团队,使我们能够在不增加摩擦的情况下添加新框架并拓展新市场。你将是向高管层、审计方、企业客户以及安全、工程、IT、法务、人力资源、财务和销售等跨职能合作伙伴传达 GRC 声音的主要负责人。
你将负责的工作包括
- 管理 GRC 项目:制定并执行多年的 GRC 战略和路线图。设定项目优先级、预算和工具;建立 KPI;并向 CISO 和高管层汇报项目健康状况、风险态势和审计准备情况。
- 领导并发展团队:招聘、管理、指导和发展 GRC 分析师团队。设定明确的目标和职业路径,进行绩效评估,分配框架和工作流的职责,打造严谨、有责任感和持续改进的文化。
- 推动认证与审计:作为 SOC 2 Type II、ISO 27001、ISO 27701 和 ISO 42001 的负责人,以及根据业务需求新增的其他框架。主导审计范围界定、准备评估、整改计划、证据策略和审计方关系;负责 ISMS、PIMS 和 AIMS 及其管理评审周期。
- 领导企业风险管理:负责企业及安全风险框架、风险偏好和风险登记册。主持风险评审会议,推动系统、供应商和 AI 风险评估,并与高级利益相关者共同处理风险升级、整改和正式风险接受。
- 推动控制保证:设计通用控制框架和持续监控方法,将 ISO、SOC 2、NIST、GDPR/CPRA、PCI 和 HIPAA/HITRUST 映射为一套统一的控制措施。监督控制测试、异常管理和纠正措施直至关闭。
- 管理访问权限:负责访问治理项目,包括定期访问认证、最小权限标准、入职/调动/离职控制和特权访问监控,与 IT 和工程团队合作。
- 领导第三方风险管理:制定...
查看英文原文
About the Role
Doppel is looking for a Manager, Governance, Risk & Compliance to own and scale our GRC program end to end. You will lead a team of GRC analysts and set the strategy, roadmap, and operating model for certifications, risk management, control assurance, third-party risk, privacy, and customer trust across the company.
As the accountable owner of GRC at Doppel, you will hold SOC 2, ISO 27001, ISO 27701, and ISO 42001 to the standard our customers expect of a security company, while building the systems and team that let us add frameworks and scale into new markets without adding friction. You will be the primary GRC voice to executive leadership, auditors, enterprise customers, and cross-functional partners in Security, Engineering, IT, Legal, People, Finance, and Sales.
What You'll Do
- Own the GRC program: Define and execute the multi-year GRC strategy and roadmap. Set program priorities, budget, and tooling; establish KPIs; and report on program health, risk posture, and audit readiness to the CISO and executive leadership.
- Lead and grow the team: Hire, manage, coach, and develop a team of GRC analysts. Set clear goals and career paths, run performance reviews, delegate ownership of frameworks and workstreams, and build a culture of rigor, ownership, and continuous improvement.
- Run certifications & audits: Serve as the executive owner for SOC 2 Type II, ISO 27001, ISO 27701, and ISO 42001, plus future frameworks as the business requires. Direct audit scoping, readiness assessments, remediation planning, evidence strategy, and auditor relationships; own the ISMS, PIMS, and AIMS and their management review cycles.
- Lead enterprise risk management: Own the enterprise and security risk framework, risk appetite, and risk register. Chair risk review forums, drive system, vendor, and AI risk assessments, and manage escalation, remediation, and formal risk acceptance with senior stakeholders.
- Drive control assurance: Design the common control framework and continuous-monitoring approach that maps ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST into a single set of controls. Oversee control testing, exception management, and corrective action through to closure.
- Govern access: Own the access governance program, including periodic access certifications, least-privilege standards, joiner/mover/leaver controls, and privileged access monitoring, in partnership with IT and Engineering.
- Lead third-party risk management: Set the vendor risk strategy and tiering model; oversee due diligence, contractual security and privacy requirements, and ongoing monitoring of critical suppliers, partners, and AI service providers.
- Own customer trust: Lead the customer trust function: security and privacy questionnaires, RFP responses, Trust Center content, and customer-facing security reviews. Act as an executive-level security counterpart for strategic customers and partner with Sales to accelerate enterprise deals.
- Advance governance & privacy: Own the policy and standards lifecycle, security and privacy awareness and role-based training, and privacy operations (DPIAs, data mapping, data subject requests) in partnership with Legal.
- Strengthen resilience & reporting: Sponsor incident response tabletop exercises and business continuity and disaster recovery testing. Deliver executive and board-level dashboards on risks, controls, access, vendor posture, and certification status.
- Shape AI governance: Lead Doppel's approach to responsible AI governance under ISO 42001 and emerging regulation (for example, the EU AI Act), partnering with Product and Engineering to embed controls into how we build and operate AI systems.
What We're Looking For
- 8+ years in GRC, security audit, or risk management, with at least 1 year managing people and owning a GRC or compliance program end to end.
- Track record hiring, developing, and retaining high-performing GRC professionals, and of scaling a program and team through rapid company growth.
- Executive-level ownership of SOC 2 Type II and ISO 27001 programs through multiple certification and surveillance cycles, including scoping, auditor selection and management, and remediation. Hands-on experience with ISO 27701 and ISO 42001 or equivalent privacy and AI governance programs.
- Deep command of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence sufficiency in cloud-first environments (AWS/Azure/GCP, SaaS).
- Experience designing and operating enterprise risk management, including risk appetite, risk registers, risk forums, and formal risk acceptance with senior leadership.
- Proven ability to run access certifications, third-party risk management, and customer security reviews at enterprise scale, and to select and implement GRC tooling and automation.
- Strong executive communication skills: comfortable presenting risk and compliance posture to leadership, boards, auditors, and enterprise customers, and translating technical detail into business impact.
- Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM are a plus.
Why This Role Matters
Doppel's customers trust us to protect their brands, people, and data. This role makes that trust demonstrable. As the leader of Doppel's GRC program, you will turn security, privacy, and compliance into a durable competitive advantage: maintaining the certifications our customers require, embedding risk management into how we operate, and building a team that keeps pace with the company.
Your leadership will enable Doppel to scale responsibly, accelerate enterprise deals, reduce operational and regulatory risk, and earn lasting confidence from customers, partners, auditors, and regulators in how we protect data and run our business.
Salary Range
$170,000—$190,000 USD
Originally posted on Himalayas