ISO Risk Management Director
Posted yesterday
virtual vocationsDenver (CO)
Compliance ManagersOther Management Consulting Services
SENIORITY
Manager
About the role
Owning the execution of critical governance, risk, and compliance initiatives, the full-time salaried ISO 27001 Risk Management Director will manage external auditor relationships, oversee SOC 1 and SOC 2 audits, and lead ISO 27001 certification efforts in a remote environment.
Key responsibilities
Own end-to-end execution of SOC 1 and SOC 2 Type II audits, including scoping, evidence collection, and remediation tracking
Lead the ISO 27001:2022 audit readiness and certification process, managing relationships and coordinating evidence
Build and operate the enterprise risk register, conducting assessments and maintaining updates across business units
Required qualifications
8-12+ years of experience in GRC, IT audit, or enterprise risk management with direct ownership of SOC 1/SOC 2 audits
ISO 27001 Lead Implementer certification with credentialed implementation experience
Working knowledge of SOX ITGC requirements in a publicly traded company
Experience building an enterprise risk register and KRI/KPI reporting framework for executive audiences
Strong management of POA&M and remediation lifecycle across cross-functional teams
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
