Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Rivian and Volkswagen Group Technologies

Senior GRC Analyst – Enterprise Cybersecurity

Rivian and Volkswagen Group Technologies

. Own TISAX follow-on certifications, including subsequent waves and sites after initial TISAX AL3 assessments .

Posted 9/21/2026full-timePalo Alto • California • United StatesSenior💰 $117,200 - $161,150 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in governance, risk, and compliance (GRC) with a strong focus on ISO/IEC 27001, TISAX, and risk management processes. Proven ability to manage audits, maintain compliance documentation, and coordinate with diverse stakeholders across multiple entities.

Highest-signal resume keywords
ISO/IEC 27001 Certification ManagementTISAX Compliance ManagementGovernance, Risk, And Compliance (GRC)Risk Register ManagementAudit Coordination And Evidence Collection

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Governance, Risk, And Compliance (GRC)ISO/IEC 27001/27002TISAXNIST Cybersecurity FrameworkRisk Assessment And TreatmentCorrective-Action TrackingAudit CoordinationDocumentation ManagementProject TrackingEvidence Collection
Soft Skills
Excellent Written And Verbal CommunicationStrong Documentation SkillsOrganizational SkillsAbility To Manage Multiple Deadlines
Tools & Technologies
ServiceNow GRCOneTrustVantaDrataArcherAuditBoardZenGRCJiraConfluenceGoogle Workspace
Certifications & Qualifications
CISACRISCISO 27001 Lead ImplementerISO 27001 Lead AuditorCompTIA Security+
Industry Keywords
Automotive IndustryTISAX/VDA ISA AssessmentsUNECE R155/R156ISO/SAE 21434IATF 16949

Tech Stack

Tools & technologies
Cyber SecurityServiceNow

About the role

Key responsibilities & impact
  • Own TISAX follow-on certifications, including subsequent waves and sites after initial TISAX AL3 assessments
  • Manage evidence maintenance, internal self-assessments, corrective-action tracking, re-assessment readiness, and ongoing ISMS evidence infrastructure
  • Drive achievement and ongoing maintenance of ISO/IEC 27001 certification
  • Coordinate internal audits and maintain the Statement of Applicability and control evidence
  • Manage annual surveillance and recertification activities
  • Support ISO 9001 efforts related to infrastructure and IT
  • Support CSMS compliance under UNECE R155 and software update management under UNECE R156 for enterprise/IT infrastructure
  • Track and drive corrective and preventive actions (CAPA) to closure across all frameworks
  • Operate the enterprise cybersecurity risk register from intake through assessment, treatment tracking, and reporting
  • Execute risk management processes with Legal and follow documented standard operating procedures, including confidentiality classification steps
  • Produce prioritized risk reporting for the Sr. Manager, Enterprise Cybersecurity and other stakeholders
  • Coordinate internal control owners across IT, Legal, Facilities, Internal Audit, HR, and engineering teams
  • Coordinate evidence collection with 15–30+ named control owners
  • Manage certification bodies, external consultants, and vendors, tracking deliverables, due dates, and response SLAs
  • Maintain audit-ready documentation and program tracking in Jira, Confluence, and Google Workspace
  • Travel to company sites in Southern California, Northern California, Vancouver (BC), and Belgrade (Serbia) for on-site audits, physical security walkthroughs, evidence collection, and stakeholder coordination

Requirements

What you’ll need
  • 5 years of experience in governance, risk, and compliance (GRC), IT/information security compliance, IT audit, or a closely related function
  • Bachelor's degree or equivalent practical experience
  • Working knowledge of ISO/IEC 27001/27002, TISAX and the NIST Cybersecurity Framework, including risk assessment and treatment concepts and control mapping
  • Hands-on experience supporting or coordinating audits and certifications: evidence collection, control validation, and corrective-action tracking
  • Experience operating or maintaining a risk register and driving remediation items to closure with accountable owners
  • Strong documentation, organization, and project-tracking skills
  • Ability to manage multiple concurrent deadlines
  • Excellent written and verbal communication; able to work with technical and non-technical stakeholders across a complex, multi-entity organization
  • Ability and willingness to travel domestically and internationally up to a few weeks per quarter
  • Professional certification such as CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+ (preferred)
  • Hands-on experience with GRC/compliance tooling such as ServiceNow GRC, OneTrust, Vanta, Drata, Archer, AuditBoard, or ZenGRC (preferred)
  • Automotive industry experience, especially TISAX/VDA ISA assessments, UNECE R155/R156, ISO/SAE 21434, or IATF 16949 (preferred)
  • Experience coordinating external auditors, certification bodies, or consultancies and managing deliverables to SLAs (preferred)
  • Proficiency with Jira, Confluence, and Google Workspace (preferred)
  • Experience in a fast-paced, high-growth, or joint-venture/multi-entity environment (preferred)
  • Valid passport and ability to travel internationally

Benefits

Comp & perks
  • Annual company performance bonus program; annual bonus target of 10%
  • Equity in the form of Restricted Stock Units (RSUs)
  • Health coverage
  • Retirement savings
  • Time off
  • Family planning programs
  • Travel support for company-site audits and stakeholder coordination