Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Doppel

Director, Governance, Risk & Compliance

Doppel

. Define and execute Doppel's multi-year GRC strategy, operating model, and roadmap .

Posted 9/26/2026full-timeRemote • United StatesLeadWebsite

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Define and execute Doppel's multi-year GRC strategy, operating model, and roadmap
  • Establish priorities, investments, tooling and automation strategy, KPIs, and governance mechanisms
  • Lead, develop, and grow the GRC team; define structure, roles, accountability, and career paths
  • Own strategy and executive accountability for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and future frameworks
  • Establish audit readiness, management systems, control ownership, remediation, and auditor relationships
  • Establish and evolve enterprise and security risk management, including risk appetite, assessment methodology, escalation, risk acceptance, and executive review
  • Set strategy for common controls and continuous assurance across ISO, SOC 2, NIST, privacy, and customer requirements
  • Govern control testing, access risk, exceptions, corrective actions, evidence quality, and automation
  • Establish vendor, partner, and AI-related risk governance, including tiering, due diligence, contracts, monitoring, and escalation
  • Own customer security and privacy assurance, Trust Center content, security reviews, and RFP support
  • Partner with Sales and Customer Success to reduce security-related friction in enterprise deals
  • Establish scalable privacy and responsible AI governance with Legal, Product, Engineering, and Security
  • Provide executive oversight of incident preparedness, business continuity, disaster recovery, and operational resilience
  • Deliver reporting on enterprise risk, compliance posture, control effectiveness, third-party risk, and certification status to executives and the board
  • Represent Doppel with auditors, strategic customers, and external stakeholders

Requirements

What you’ll need
  • 10+ years of experience across GRC, security risk, compliance, security audit, or related disciplines, including significant experience leading teams and owning a GRC function or similarly broad program
  • Experience building and scaling GRC programs and teams in a high-growth technology, SaaS, cybersecurity, or similarly complex environment
  • Demonstrated ability to advise senior executives and translate security, compliance, and regulatory risk into business decisions and priorities
  • Executive ownership of SOC 2 Type II and ISO 27001 through multiple certification and surveillance cycles, including program strategy, scoping, auditor management, remediation, and management review
  • Experience with ISO 27701, ISO 42001, or comparable privacy and AI governance programs strongly preferred
  • Deep understanding of ISMS/PIMS/AIMS, Trust Services Criteria, common control frameworks, control assurance, and cloud-first evidence requirements
  • Experience designing and operating enterprise risk management programs, including risk appetite, risk registers, governance forums, escalation, remediation, and formal risk acceptance
  • Experience overseeing third-party risk, access governance, privacy, customer security assurance, and core GRC programs at scale
  • Track record building high-performing teams, developing talent, establishing ownership models, and evolving organizational structure
  • Experience developing GRC tooling and automation strategies
  • Strong executive communication and influence skills, including presenting risk and compliance posture to executives, boards, auditors, and enterprise customers
  • Ability to operate effectively in ambiguity and prioritize competing business and risk requirements
  • Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, CIPP, or CIPM are a plus