The role involves leading and managing the company's Information Security Governance, Risk, and Compliance programs to ensure industry standards are met, supporting audit readiness, policy development, risk assessments, and security awareness initiatives in a fast-growing organization focused on sustainable technology.
Key Responsibilities
Design and execute the strategic vision for the Information Security GRC program
Develop and maintain policies, procedures, and organizational capabilities for Information Security Governance, Risk, and Compliance
Drive cross-functional collaboration to implement secure, consistent patterns and expand observability
Identify and prioritize opportunities to improve organizational risk posture
Manage compliance documentation, including reports, risk registers, and policies
Coordinate audit evidence gathering and oversee user access reviews
Develop and manage the compliance program and related processes
Conduct risk assessments and implement mitigation strategies
Oversee operational capabilities of GRC tools and platforms
Represent Information Security in internal and third-party partnerships
Develop and maintain reporting frameworks on risks, compliance status, and program progress
Requirements
7 years of hands-on experience in Information Security Governance, Risk, and Compliance programs developing risk-centric solutions, leveraging industry standard controls frameworks and implementations.
At least 5 years of direct ownership in at least 3 of the following areas: Compliance Program Management, Audit Evidence Gathering, User Access Reviews, Policy and Process Development, Change Management, Risk Assessment and Mitigation, Security Awareness and Training Programs.
Proficiency with 4 or more industry-standard compliance programs such as ISO 27001, CISv8.1, NIST 800-53 88 171, CMMC, TISAX, SOC 2, Sarbanes-Oxley.
Extensive experience overseeing IT compliance initiatives in mixed on-premises and cloud-based environments such as AWS, GCP, Azure, Entra, Active Directory, ensuring adherence to industry standards and regulatory requirements.
Advanced knowledge of Governance, Risk, and Compliance frameworks and best practices, with demonstrable experience in developing and implementing IT security policies and procedures, conducting risk assessments, managing risk mitigation initiatives, and preparing for and managing internal and external IT audits.
Experience leading security awareness and training programs.
Experience in Third Party Risk Management Evaluations.
Strong understanding of regulatory requirements and industry standards.
Familiarity with GRC tools and technologies.
Relevant professional certifications such as PMP, CISSP, CIPM, CIPT, CISM, CISA, CRISC, CGEIT, GSEC, GSNA, or GCCC.
Excellent communication and interpersonal skills, including the ability to influence and collaborate with stakeholders at all levels, strong presentation and report-writing skills, and effective leadership and mentoring abilities.
Demonstrated experience in managing complex programs and projects, including developing project plans, and leading cross-functional teams to deliver results on time and within scope.
Benefits & Perks
Compensation will be commensurate with experience
Full-time position
Work in office setting, manufacturing floor, outdoor job site, or remote work
Exposure to loud noise, extreme heat or cold, dust, fumes, or hazardous chemicals
Ability to work weekends, evenings, on-call shifts, or extended hours
Occasional or frequent travel for meetings, site visits, or events
Ready to Apply?
Join Redwood Materials and make an impact in renewable energy