671,804open jobs
39,060companies
102,874added this week
Browse all
Location
In office
Seniority
Staff · 5+ years exp
Overview
Company
Impact
Profile match
A leader in grid reliability and resiliency, Electric Power Engineers (EPE) has partnered with power and energy clients across the globe for over 50 years. EPE's client-centric approach delivers unmatched expertise throughout the project lifecycle, with a platform of comprehensive services and proprietary solutions spanning utility engineering, grid and resource integration, reliability and compliance, digitalization, and grid analytics, as well as innovative software partnership with its sister company ENER-I.AI, Inc. Committed to designing and developing the grid of the future, EPE's highly experienced team of detail-oriented consultants are passionate about helping clients address complex engineering and grid modeling challenges, bridge gaps, and gain visibility into the evolving complexities of the grid.

Overview

We are designing the grid of the future!

The Technology Risk & Compliance Lead is responsible for developing, implementing, and maintaining the organization’s technology risk and compliance program across all business units. This includes oversight of IT and security compliance, technology risk management, audit readiness, control governance, vendor risk management, and various compliance frameworks such as SOC 2, ISO 27001, and other relevant standards. The role requires collaboration across departments to ensure adherence to laws, regulations, and industry standards, while also fostering a strong culture of compliance and risk management.

Responsibilities

How you can make an impact:

Compliance Program Management

  • Develop, implement, and manage various company-wide compliance programs.
  • Monitor compliance with applicable laws, regulations, and industry standards.
  • Partner with business, IT, Security, Legal, HR, Software, and Finance teams to develop, document, implement, and maintain compliance policies, procedures, controls, and supporting workflows.
  • Conduct internal compliance audits, control testing, and evidence reviews; track findings through remediation and closure partnering with our business.
  • Evaluate, implement, and manage compliance, risk, or audit management software, including related workflows, reporting, and evidence repositories.
  • Maintain the organization’s technology control framework, control library, policy inventory, evidence repository, and compliance calendar.
  • Map compliance obligations, customer commitments, audit requirements, vendor obligations, and internal controls to reduce duplication and improve consistency across compliance activities.
  • Manage technology risk and compliance projects from initiation through closure, including scope definition, planning, scheduling, stakeholder coordination, execution tracking, risk and issue management, and status reporting.
  • Develop and maintain project plans, milestones, dependencies, action items, decision logs, and executive-level project updates for audits, certifications, remediation initiatives, vendor risk activities, customer assurance efforts, and compliance improvement projects.
  • Coordinate cross-functional workstreams involving IT, Security, Legal, HR, Finance, and software teams to ensure deliverables are completed on time and aligned with compliance and risk objectives.
  • Track project risks, blockers, resource constraints, and dependency conflicts; escalate issues appropriately and drive resolution with accountable owners.
  • Facilitate working sessions, readiness reviews, remediation meetings, audit preparation meetings, vendor review meetings, and stakeholder updates.
  • Apply structured project management practices to improve predictability, accountability, documentation quality, and timely completion of compliance and risk initiatives.
  • Support the implementation and ongoing improvement of GRC, audit management, vendor risk, and compliance automation tools, including requirements gathering, workflow design, user acceptance testing, rollout planning, adoption tracking, and post-implementation optimization.
  • Prepare clear, concise project reporting for leadership, including progress against milestones, overdue items, risk trends, key decisions, and required executive action.

IT & Security Compliance

  • Support and help drive efforts to achieve and maintain certifications such as SOC 2, ISO 27001, and other relevant frameworks, in partnership with IT, Security, Legal, HR, Software, and business stakeholders.
  • Partner with IT and Security teams to ensure compliance requirements are built into technology processes.
  • Coordinate audit evidence collection across departments, ensuring documentation is complete, accurate, timely, and audit-ready.
  • Manage risk assessments, gap analyses, and remediation plans for IT compliance.
  • Coordinate external audits and act as primary liaison with auditors and certification bodies.
  • Work with control owners to define control intent, evidence expectations, testing procedures, and remediation requirements.
  • Support internal and external audits by coordinating requests, preparing evidence, tracking auditor inquiries, and maintaining audit status reporting.
  • Document control gaps, audit findings, and process deficiencies; assign accountable owners and track corrective actions through closure.

Risk & Governance

  • Conduct enterprise technology and compliance risk assessments, and track treatment plans through closure.
  • Collaborate with executive leadership to ensure compliance risk is included in corporate strategy.
  • Monitor regulatory changes, industry trends, and compliance best practices; recommend updates to policies, controls, training, and governance processes as appropriate.
  • Maintain regulatory and compliance risk register.
  • Maintain mappings between control frameworks, audit requirements, and internal controls.
  • Provide compliance reporting and metrics to senior management and the Board of Directors.

Third Party Risk Management

  • Partner with Procurement, Legal, Security, IT, and business owners on third-party risk management and vendor compliance reviews.
  • Support vendor risk assessments, due diligence reviews, security questionnaires, evidence reviews, and contract-related compliance obligations.
  • Document vendor risks, control gaps, compensating controls, risk decisions, and required follow-up actions.
  • Track vendor remediation commitments, reassessments, and ongoing monitoring activities based on vendor criticality and risk.
  • Support customer security and compliance inquiries, including questionnaires, evidence requests, and contract-related control commitments.
  • Track customer security and compliance commitments to ensure they are reviewed, approved, mapped to internal controls, and monitored for ongoing compliance.

Governance Training & Awareness

  • Support governance processes for technology policies, standards, control ownership, risk acceptance, policy exceptions, audit findings, and remediation tracking.
  • Work with the Learning and Development department to design and deliver compliance and ethics training across the organization.
  • Develop guidance for control owners on evidence quality, audit expectations, compliance workflows, and remediation responsibilities.
  • Promote awareness of relevant compliance requirements and best practices.
  • Serve as a trusted advisor on technology risk, compliance, audit readiness, vendor risk, and customer assurance matters for leadership and employees.

Qualifications

Bring your passion, here's what’s needed:

Education

  • Bachelor’s degree in Business, Law, Information Security, or related field
  • Master’s preferred in Business, Information Systems, or related field
  • Compliance-related certifications (e.g., CISA, CISM, CISSP, CCEP, ISO 27001 Lead Implementer/Auditor) are highly desirable.
  • Project management-related certifications (CAPM, PMP, PMI-ACP) or equivalent project/program management experience preferred.

Experience

  • 5+ years of technology compliance, risk management, GRC program management, or IT audit experience.
  • Demonstrated experience managing SOC 2, NIST, ISO 27001, or other IT compliance frameworks.
  • Strong knowledge of technology corporate governance, regulatory compliance, and risk management principles.
  • Experience working cross-functionally with IT, Legal, HR, and business leadership.
  • Experience supporting vendor risk management, third-party due diligence, or customer security questionnaires.

Skills

  • Strong project management and organizational skills.
  • Excellent written and verbal communication skills.
  • Ability to interpret complex regulations and translate them into actionable business requirements.
  • Proven ability to manage external auditors and regulatory bodies.
  • High integrity, discretion, and ability to handle confidential information.

Key Performance Indicators (KPIs)

  • Successful completion of compliance audits (SOC 2, ISO 27001, etc.).
  • Timely remediation of identified compliance gaps.
  • Reduction of compliance-related risks and incidents.
  • Positive feedback from internal stakeholders and external auditors.

Lead the Change!

Be a part of an innovative team shaping the grid of the future through advanced energy intelligence. For more than half a century, Electric Power Engineers (EPE) has partnered with power and energy clients across the globe, providing consulting expertise and energy intelligence software solutions for complex engineering and grid modeling challenges. As leaders in the renewables space, we are focused on building a modern, secure, and resilient grid. Join us in making an impact on the communities we serve and the environment in which we live. Together we can transform the future of energy.

How we support you:

  • Comprehensive health and wellness benefits including medical, dental, and vision with 100% premium coverage for you
  • Generous PTO and paid holidays
  • MyShare Employee Ownership Program
  • Work with industry leaders
  • 401K, up to a 4% match (100% vested from day 1)

Location: This position will be remote US

Travel: Occasional travel may be needed (10% or less)

EPE is an equal opportunity/AA/Disability/Veteran employer. The EEO is the Law poster, and its supplement are available using the following links: EEOC is the Law Poster

Third-Party Recruiting Notification

EPE does not accept unsolicited resumes from third-party recruiters. Any unsolicited third-party resumes forwarded by recruiters to EPE via our career page or to any of our managers or employees will be considered public information, may be treated as a direct application from the person identified in the resume, and will not be eligible for placement fee payment to the agency. EPE will not pay a fee to a third-party recruiter or agency without a previously signed third-party agreement and has not coordinated their recruiting activity with the appropriate member of the Talent Acquisition team.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
671,804 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$37k – $58k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bratislava • Prague • Budapest • Warsaw
Cybersecurity
ISO 27001
SOC 2
GDPR
NIST 800-53
Threat Modeling
Apply
$100k per year • Remote/Hybrid • Full-Time • New York
Cybersecurity
ISO 27001
SOC 2
HIPAA
Marketing
Salesforce
LinkedIn
Apply
DevOps, Senior 6 hours ago
$108k – $209k per year (Estimated) • In office • Austin
Python
PowerShell
DevOps
Terraform
GitHub Actions
VMWare
Azure
CI/CD
Windows Server
AWS
Kubernetes
Configuration Management
TeamCity
GitHub
IAM
Cybersecurity
ISO 27001
SOC 2
Microsoft Entra ID
Apply
$30k – $49k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Rueil-Malmaison
Cybersecurity
Zscaler
ISO 27001
Management
ServiceNow
Apply
$41k – $101k per year (Estimated) • Remote • Full-Time
Python
Go
Python
FastAPI
Databases
PostgreSQL
Redis
ClickHouse
ElasticSearch
Apache Kafka
AI/ML
Claude Code
vLLM
Langfuse
LiteLLM
AWS Bedrock
LLM
DevOps
Terraform
GCP
GitHub Actions
OpenTelemetry
GitLab CI
Azure
CI/CD
AWS
Kubernetes
Amazon EKS
AWS Fargate
AWS Lambda
FinOps
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Cybersecurity
SOC 2
GDPR
HIPAA
Least Privilege
Apply
$69k – $172k per year (Estimated) • Remote/Hybrid • Bachelor's Degree • Austin
Design
AutoCAD
Apply
Project Coordinator 4 hours ago
Remote/Hybrid
Apply
In office • 5+ years exp
Apply
DevSecOps Engineer 3 days ago
In office • 3+ years exp
Python
Go
Bash
DevOps
Terraform
GitHub Actions
GitLab CI
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Docker
Kubernetes
Platform Engineering
Amazon EKS
AWS Lambda
Amazon EC2
Amazon S3
IAM
Amazon CloudWatch
Cybersecurity
ISO 27001
Open Policy Agent
NIST CSF
CIS Benchmarks
PCI DSS
SOC 2
NIST 800-53
Defense in Depth
Least Privilege
Threat Modeling
SBOM
SLSA
Sigstore
Cosign
Kyverno
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree
PowerShell
DevOps
Azure
Windows Server
Incident Management
Cybersecurity
ISO 27001
Microsoft Defender
SOC 2
Microsoft Entra ID
Management
SharePoint
Apply
See all jobs
This is one of many
671,804 more open roles from verified company boards, updated every day.