GRC Manager
TLDR
Manage GRC processes and lead a team to ensure compliance and effective risk management in a dynamic clean energy tech environment.
- Leadership: Leads the GRC program and a team of security professionals.
- Governance: Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements. Map requirements to controls and manage the company’s execution of the controls.
- Risk Management: Conduct regular enterprise-wide risk assessments, maintain a risk register, and develop mitigation strategies for identified threats. Co-lead Risk Management committees.
- Compliance: Lead audits and manage compliance efforts for frameworks such as SOC 2, ISO 27001, PCI-DSS, NERC-CIP, and privacy principles. Manage CAPAs for non-compliance.
- Third-Party Risk: Manage vendor risk management processes, including vendor assessments and contract reviews.
- Sales-cycle Support: Manage security and privacy responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
- Business Continuity: Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
- Awareness & Training: Oversee rollout of cybersecurity and privacy awareness campaigns and required annual training and policy attestations. Monitor participation, ensure compliance, and support content preparation aligned with company and regulatory requirements.
- Metrics: Build and manage security and privacy metrics program
- Technology & Reporting: Select and manage GRC software tools to automate processes, monitor controls, and provide reports to executives.
- Collaboration: Collaborate with IT, Security, Legal, and People teams to drive risk-informed decision-making and build a culture of compliance.
- Experience: Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
- Framework Knowledge: Proficiency in frameworks like SOC2, NIST CSF, ISO 27001, and NERC-CIP.
- Analytical Skills: Strong ability to analyze risk data and translate complex regulations into actionable controls.
- Communication: Excellent communication skills to interact with stakeholders and lead team efforts.
- Experience with 3rd party/vendor risk management processes
- Experience in working with sales teams to complete Requests for Proposals and security questionnaires
- Understanding of GRC processes such as policy management, risk assessment, and IT audits
- Exposure to public cloud and cloud security concepts in environments like AWS, Azure or GCP
- Exceptional verbal and written communication skills
- GRC or Privacy certifications (e.g. CISA, CIPP, etc)
- Make a Meaningful Impact: Your work directly impacts our mission of decarbonization and building a more sustainable future.
- Grow Your Career: We offer ample advancement opportunities, robust learning and development programs, and a supportive team environment that fosters collaboration and innovation.
- Thrive: We offer comprehensive benefits, including flexible time off, generous parental leave, a wellness stipend, and work flexibility to help you thrive both personally and professionally.
- Belong to an Inclusive Community: We celebrate diversity and foster an inclusive workplace where everyone feels respected, empowered, and heard. Our Employee Resource Groups offer opportunities to connect with colleagues who share your interests and backgrounds.
- Be Part of a Growing Movement: Join a team of dedicated individuals who are passionate about creating a more sustainable future. We offer a collaborative environment where your ideas are valued and your contributions recognized. Together, we can build a brighter tomorrow.
Benefits
Paid Parental Leave
generous parental leave
Paid Time Off
flexible time off
Remote-Friendly
work flexibility
Wellness Stipend
TENDRIL builds software to manage energy resources in homes and businesses, integrating smart technologies like thermostats, electric vehicles, and solar panels. Our platform helps users generate, shift, or save energy, optimizing efficiency and enhancing grid reliability. We're focused on delivering solutions that support the transition to clean energy while reducing costs for consumers.