Corporate Compliance Lead
Austin, TX - USA
Job Summary
We are designing the grid of the future!
The Technology Risk & Compliance Lead is responsible for developing implementing and maintaining the organizations technology risk and compliance program across all business units. This includes oversight of IT and security compliance technology risk management audit readiness control governance vendor risk management and various compliance frameworks such as SOC 2 ISO 27001 and other relevant standards. The role requires collaboration across departments to ensure adherence to laws regulations and industry standards while also fostering a strong culture of compliance and risk management.
Howyou can make an impact:
Compliance Program Management
- Develop implement and manage various company-wide compliance programs.
- Monitor compliance with applicable laws regulations and industry standards.
- Partner with business IT Security Legal HR Software and Finance teams to develop document implement and maintain compliance policies procedures controls and supporting workflows.
- Conduct internal compliance audits control testing and evidence reviews; track findings through remediation and closure partnering with our business.
- Evaluate implement and manage compliance risk or audit management software including related workflows reporting and evidence repositories.
- Maintain the organizations technology control framework control library policy inventory evidence repository and compliance calendar.
- Map compliance obligations customer commitments audit requirements vendor obligations and internal controls to reduce duplication and improve consistency across compliance activities.
- Manage technology risk and compliance projects from initiation through closure including scope definition planning scheduling stakeholder coordination execution tracking risk and issue management and status reporting.
- Develop and maintain project plans milestones dependencies action items decision logs and executive-level project updates for audits certifications remediation initiatives vendor risk activities customer assurance efforts and compliance improvement projects.
- Coordinate cross-functional workstreams involving IT Security Legal HR Finance and software teams to ensure deliverables are completed on time and aligned with compliance and risk objectives.
- Track project risks blockers resource constraints and dependency conflicts; escalate issues appropriately and drive resolution with accountable owners.
- Facilitate working sessions readiness reviews remediation meetings audit preparation meetings vendor review meetings and stakeholder updates.
- Apply structured project management practices to improve predictability accountability documentation quality and timely completion of compliance and risk initiatives.
- Support the implementation and ongoing improvement of GRC audit management vendor risk and compliance automation tools including requirements gathering workflow design user acceptance testing rollout planning adoption tracking and post-implementation optimization.
- Prepare clear concise project reporting for leadership including progress against milestones overdue items risk trends key decisions and required executive action.
IT & Security Compliance
- Support and help drive efforts to achieve and maintain certifications such as SOC 2 ISO 27001 and other relevant frameworks in partnership with IT Security Legal HR Software and business stakeholders.
- Partner with IT and Security teams to ensure compliance requirements are built into technology processes.
- Coordinate audit evidence collection across departments ensuring documentation is complete accurate timely and audit-ready.
- Manage risk assessments gap analyses and remediation plans for IT compliance.
- Coordinate external audits and act as primary liaison with auditors and certification bodies.
- Work with control owners to define control intent evidence expectations testing procedures and remediation requirements.
- Support internal and external audits by coordinating requests preparing evidence tracking auditor inquiries and maintaining audit status reporting.
- Document control gaps audit findings and process deficiencies; assign accountable owners and track corrective actions through closure.
Risk & Governance
- Conduct enterprise technology and compliance risk assessments and track treatment plans through closure.
- Collaborate with executive leadership to ensure compliance risk is included in corporate strategy.
- Monitor regulatory changes industry trends and compliance best practices; recommend updates to policies controls training and governance processes as appropriate.
- Maintain regulatory and compliance risk register.
- Maintain mappings between control frameworks audit requirements and internal controls.
- Provide compliance reporting and metrics to senior management and the Board of Directors.
Third Party Risk Management
- Partner with Procurement Legal Security IT and business owners on third-party risk management and vendor compliance reviews.
- Support vendor risk assessments due diligence reviews security questionnaires evidence reviews and contract-related compliance obligations.
- Document vendor risks control gaps compensating controls risk decisions and required follow-up actions.
- Track vendor remediation commitments reassessments and ongoing monitoring activities based on vendor criticality and risk.
- Support customer security and compliance inquiries including questionnaires evidence requests and contract-related control commitments.
- Track customer security and compliance commitments to ensure they are reviewed approved mapped to internal controls and monitored for ongoing compliance.
Governance Training & Awareness
- Support governance processes for technology policies standards control ownership risk acceptance policy exceptions audit findings and remediation tracking.
- Work with the Learning and Development department to design and deliver compliance and ethics training across the organization.
- Develop guidance for control owners on evidence quality audit expectations compliance workflows and remediation responsibilities.
- Promote awareness of relevant compliance requirements and best practices.
- Serve as a trusted advisor on technology risk compliance audit readiness vendor risk and customer assurance matters for leadership and employees.
Bring your passion heres whats needed:
Education
- Bachelors degree in Business Law Information Security or related field
- Masters preferred in Business Information Systems or related field
- Compliance-related certifications (e.g. CISA CISM CISSP CCEP ISO 27001 Lead Implementer/Auditor) are highly desirable.
- Project management-related certifications (CAPM PMP PMI-ACP) or equivalent project/program management experience preferred.
Experience
- 5 years of technology compliance risk management GRC program management or IT audit experience.
- Demonstrated experience managing SOC 2 NIST ISO 27001 or other IT compliance frameworks.
- Strong knowledge of technology corporate governance regulatory compliance and risk management principles.
- Experience working cross-functionally with IT Legal HR and business leadership.
- Experience supporting vendor risk management third-party due diligence or customer security questionnaires.
Skills
- Strong project management and organizational skills.
- Excellent written and verbal communication skills.
- Ability to interpret complex regulations and translate them into actionable business requirements.
- Proven ability to manage external auditors and regulatory bodies.
- High integrity discretion and ability to handle confidential information.
Key Performance Indicators (KPIs)
- Successful completion of compliance audits (SOC 2 ISO 27001 etc.).
- Timely remediation of identified compliance gaps.
- Reduction of compliance-related risks and incidents.
- Positive feedback from internal stakeholders and external auditors.
Lead the Change!
Be a part of an innovative team shaping the grid of the future through advanced energy intelligence. For more than half a century Electric Power Engineers (EPE) has partnered with power and energy clients across the globe providing consulting expertise and energy intelligence software solutions for complex engineering and grid modeling challenges. As leaders in the renewables space we are focused on building a modern secure and resilient grid. Join us in making an impact on the communities we serve and the environment in which we live. Together we can transform the future of energy.
How we support you:
- Comprehensive health and wellness benefits including medical dental and vision with 100% premium coverage foryou
- Generous PTO and paid holidays
- MyShare Employee Ownership Program
- Work with industry leaders
- 401K up to a 4% match (100% vested from day 1)
Location: This position will be remote US
Travel: Occasional travel may be needed (10% or less)
EPE is an equal opportunity/AA/Disability/Veteran employer. The EEO is the Law poster and its supplement are available using the following links:EEOC is the Law Poster
Third-Party Recruiting Notification
EPE does not accept unsolicited resumes fromthird-party recruiters. Any unsolicited third-party resumes forwarded by recruiters to EPE via our career page or to any of our managers or employees will be considered public information may be treated as a direct application from the person identified in the resume and will not be eligible for placement fee payment to the will not pay a fee to a third-party recruiter or agencywithout a previously signed third-party agreementand has not coordinated their recruiting activity with the appropriate member of the Talent Acquisition team.