GRC Leader
Remote, US
Goodleap
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more.
About GoodLeap:GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $27 billion in financing for sustainable solutions since 2018. GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary The GoodLeap security team is responsible for both business enablement and safeguarding the organization’s information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap’s customers, partners, and employees’ information.
As the lead for the GRC (Governance, Risk, and Compliance) team, this is a great opportunity to shape the security vision for compliance, governance, and privacy for the organization and drive innovation throughout relevant processes, technology solutions, and people. You will work with interesting and challenging use cases, technologies, and processes, define and implement predictive compliance controls, drive automation/efficiencies in privacy processes, 3rd party risk management, and regulatory, industry, and partner compliance activities. You will wear many hats, from advisor to doer, and everything in‐between.
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
Position Summary The GoodLeap security team is responsible for both business enablement and safeguarding the organization’s information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap’s customers, partners, and employees’ information.
As the lead for the GRC (Governance, Risk, and Compliance) team, this is a great opportunity to shape the security vision for compliance, governance, and privacy for the organization and drive innovation throughout relevant processes, technology solutions, and people. You will work with interesting and challenging use cases, technologies, and processes, define and implement predictive compliance controls, drive automation/efficiencies in privacy processes, 3rd party risk management, and regulatory, industry, and partner compliance activities. You will wear many hats, from advisor to doer, and everything in‐between.
Essential Job Duties & Responsibilities
- Execute, maintain and improve the technology governance and complianceprogram, with a focus on automation, control right‐sizing, and proactive compliance monitoring/enforcement, e.g., lead, rather than lag compliance controls.
- Own compliance processes for cyber security and privacy (e.g., SOC2, CCRA, GDPR, ISO27001, SOX‐404) and drive compliance activities, such as SOC2 control operations and testing, 3rd party risk assessments, etc.
- Partner with the finance and audit team to define and implement effective, yet practical ITGCs for in‐scope environments.
- Lead and/or coordinate partner and internal/external audits across all functional areas/GoodLeap business units.
- Partner with the legal team to implement and streamline privacy processes and controls.
- Build and lead a GRC team.
- Select, implement, and manage GRC solutions for the organization.
Required Skills, Knowledge & Abilities
- Strong communicator that can lead both technical and operational/business discussions and help drive technical, governance, and compliance decisions
- At least 8 years of proven experience in the GRC, internal audit, security, and/or privacy space, with significant experience in performing, running, and executing audits, certification programs, and control assessments, including but not limited to, scope planning, defining control procedures based on requirements, policies and standards, control testing, and mapping issues to risks and socializing results.
- Ability to establish credibility and build trust across the organization, particularly with engineers, product managers, and G&A functions; you are confident, without being arrogant
- Hands‐on experience with technology control frameworks, from NIST to SSAE18, HITRUST, privacy regulations, e.g., GLBA, CCPA, GDPR, and understanding the operational concerns and opportunities associated with these frameworks and regulations.
- A non‐dogmatic mindset
- Excellent understanding of cloud‐based B2B, B2C, and B2B2C environments and the associated technologies and security controls
- Passionate about learning new things – while you’re not expected to know everything you will face, it is expected that you will learn new things when appropriate
- Desire and/or ability to write automation scripts to increase operational efficiency and effectiveness of compliance and privacy controls.
- Ability to see the big picture, yet recognize the importance of details and make sure t’s are crossed and i's dotted
- Broad industry experience, inclusive of Big 4 and in‐house compliance/oversight roles is a significant plus
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: Audits Automation Business Intelligence CCPA Cloud Compliance Finance GDPR GLBA Governance HITRUST ISO 27001 Monitoring NIST Nonprofit Privacy Risk assessment Risk management SOC 2 SOX Windows
Perks/benefits: Career development Team events
Regions:
Remote/Anywhere
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsInformation System Security Officer jobsInformation Security Manager jobsSenior Cloud Security Engineer jobsInformation Security Officer jobsSenior Cybersecurity Engineer jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsSenior Information Security Analyst jobsSystems Engineer jobsSystems Administrator jobsSecurity Consultant jobsSecurity Specialist jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Penetration Tester jobsThreat Intelligence Analyst jobsStaff Security Engineer jobsSecurity Operations Analyst jobsSenior Information Security Engineer jobsSenior Product Security Engineer jobs
Java jobsTop Secret jobsMalware jobsGDPR jobsSplunk jobsEDR jobsSaaS jobsForensics jobsRMF jobsIDS jobsSDLC jobsBash jobsSQL jobsIPS jobsDoDD 8570 jobsIntrusion detection jobsThreat detection jobsActive Directory jobsFinance jobsCompTIA jobsGIAC jobsCRISC jobsITIL jobsTerraform jobsDocker jobs
OWASP jobsClearance Required jobsSANS jobsHIPAA jobsIndustrial jobsSOC 2 jobsOSCP jobsCCSP jobsUNIX jobsPolygraph jobsVPN jobsBanking jobsAnsible jobsTCP/IP jobsJavaScript jobsData Analytics jobsDNS jobsSOX jobsSAP jobsIT infrastructure jobsNIST 800-53 jobsSOAR jobsCISO jobsJira jobsMachine Learning jobs