- Location
- Arizona - Remote - USA, United States of America
- Workplace
- Remote
- Type
- Full-time
- Seniority
- Director
- Source
- Workday
Description
Job Description:
Position Summary
Nextpower is seeking an experienced Director, GRC to lead, and scale the company’s enterprise GRC program. This role will be responsible for the governance, risk management, compliance, and assurance capabilities required to support Nextpower’s business objectives, customer commitments, regulatory obligations, and product security requirements.
The Director, GRC will serve as the central program leader, coordinating work across Cybersecurity, IT, Product, Engineering, Quality, Legal, Procurement, Human Resources, Internal Audit, and executive leadership. The role will manage external implementation partners, auditors, and certification bodies while ensuring that governance and compliance processes remain sustainable after initial certification.
The ideal candidate is a hands-on leader who can translate regulatory and certification requirements into practical operating processes, establish clear ownership across the organization, and drive complex cross-functional programs from discovery through certification and ongoing maintenance.
Key Responsibilities
- Develop a scalable GRC operating model covering governance, risk management, compliance, policy management, audit readiness, evidence management, and corrective actions.
- Define program governance, decision-making structures, steering committees, control ownership, and executive reporting.
- Develop and maintain program plans, budgets, resource requirements, milestones, dependencies, and risk registers.
- Coordinate internal stakeholders, external consultants, auditors, and certification bodies.
- Establish metrics and reporting that provide leadership with visibility into compliance status, program health, organizational risk, and remediation progress.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field.
- Ten or more years of progressive experience in governance, risk and compliance, information security, audit, enterprise risk management, or a related discipline.
- Five or more years of experience leading complex, cross-functional security, compliance, audit, or certification programs.
- Demonstrated experience leading an ISO 27001 implementation, certification, or ongoing ISMS program.
- Strong understanding of information security risk assessment, control design, control testing, audit readiness, corrective actions, and continual improvement.
- Experience working with external auditors, assessors, certification bodies, or regulators.
- Experience developing and governing cybersecurity policies, standards, procedures, and control frameworks.
- Strong program and project management skills, including experience managing schedules, budgets, dependencies, risks, and executive reporting.
- Excellent written and verbal communication skills, including the ability to present complex risk and compliance matters to executive and non-technical audiences.
- Demonstrated ability to influence stakeholders and drive accountability without direct reporting authority.
- Ability to operate independently, manage competing priorities, and deliver results in a fast-paced, global environment.
Preferred Qualifications
- Experience with IEC 62443-4-1, IEC 62443-4-2, industrial control systems, operational technology, or product security.
- Experience with the EU Cyber Resilience Act or other product cybersecurity regulations.
- Experience establishing or operating a secure development lifecycle.
- Experience in renewable energy, manufacturing, industrial technology, critical infrastructure, hardware, embedded systems, or software products.
- Experience with third-party risk management and supplier assurance programs.
- Experience with GRC or compliance automation platforms such as Drata, Vanta, ServiceNow GRC, Archer, OneTrust, or similar tools.
- Familiarity with frameworks such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 31000, or COBIT.
- Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
- Master’s degree in a relevant field.
At Nextpower, we are driving the global energy transition with an integrated clean energy technology platform that combines intelligent structural, electrical, and digital solutions for utility-scale power plants. Our comprehensive portfolio enables faster project delivery, higher performance, and greater reliability, helping our customers capture the full value of solar power. Our talented worldwide teams are redefining how solar power plants are designed, built, and operated every day with smart technology, data-driven insights, and advanced automation. Together, we’re building the foundation for the world’s next generation of clean energy infrastructure.
Nextpower is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.