Staff Information Security Risk And Compliance

ChargePoint Logo

ChargePoint

πŸ“Remote - India

Summary

Join ChargePoint, a leader in the EV charging industry, and contribute to shaping the future of electric mobility. As a Security Risk and Compliance Manager, you will lead and enhance our security risk and compliance program. You will provide governance and risk management oversight, establish and manage our security policy framework, and ensure compliance with various security regulations. This role requires proven program and project management experience, a strong understanding of cloud environments, and excellent communication skills. You will collaborate with cross-functional teams and independently lead risk and compliance initiatives. The position offers the opportunity to make a significant impact on a rapidly growing company in a dynamic industry.

Requirements

  • Minimum 7 years of professional experience leading GRC activities or programs
  • Experience setting up and scaling a BC/ DR program and practical experience with BC/ DR standards (ISO 22301, NIST SP 800-34, BCI Good Practice Guidelines)
  • Strong interpersonal skills with an emphasis on building long-term relationships across geographies and functions
  • Detail-oriented and self-motivated, with the ability to meet deadlines in a fast-paced environment
  • Experience with security policy, standards, and controls definition across multiple compliance frameworks (PCI, SOC2, ISO, NIST etc.)
  • Proficiency with GRC platforms and reporting tools, and experience presenting compliance reports to senior management
  • Experience implementing security training and awareness initiatives
  • Ability to maintain a common controls framework aligned with security standards and regulations
  • Strong understanding of frameworks such as NIST Cybersecurity, NIST SP 800-53, CIS/SANS Top 20, COSO, and leading business practices
  • Proven program and project management experience with tools such as Jira, Confluence, SharePoint, and GRC platforms
  • Strong understanding of cloud environments and technologies (AWS, Linux, etc.)
  • Exceptional judgement, ethics, and professionalism
  • Excellent written and verbal communication skills, with the ability to understand complex business and technology environments

Responsibilities

  • Independently leading risk and compliance initiatives within the Information Security team
  • Developing, managing and maturing the enterprise resiliency program, including business impact analysis, BC/ DR planning, and BCP testing
  • Driving program execution for audits, compliance checks, and external assessments (ISO 27001 v2022, PCI v4.0, SOC2, and NIST 800-53)
  • Enhancing and automating our risk and compliance management program
  • Collaborating with cross-functional teams (Engineering, IT, HR, etc.) to gather artifacts and perform ongoing audits
  • Assessing and determining the design effectiveness of internal controls
  • Introducing innovative cybersecurity capabilities to enhance competitive advantage and align risk strategies with business priorities

Preferred Qualifications

  • Strong understanding of risk management principles and practices (ISO 31000, COSO ERM, NIST SP 800-30)
  • Knowledge of incident management and crisis response principles (NIMS, ICS, ISO 22320)
  • Experience with various cloud and infrastructure security tools (CSPM, DSPM, ASM, FIM, etc)
  • Security and audit certifications (CISA, CISSP, etc.) are a plus

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.