Manager, Governance, Risk & Compliance
About the Role
Doppel is looking for a Senior Manager, Governance, Risk & Compliance to own and scale our GRC program end to end. You will lead a team of GRC analysts and set the strategy, roadmap, and operating model for certifications, risk management, control assurance, third-party risk, privacy, and customer trust across the company.
As the accountable owner of GRC at Doppel, you will hold SOC 2, ISO 27001, ISO 27701, and ISO 42001 to the standard our customers expect of a security company, while building the systems and team that let us add frameworks and scale into new markets without adding friction. You will be the primary GRC voice to executive leadership, auditors, enterprise customers, and cross-functional partners in Security, Engineering, IT, Legal, People, Finance, and Sales.
What You'll Do
- Own the GRC program: Define and execute the multi-year GRC strategy and roadmap. Set program priorities, budget, and tooling; establish KPIs; and report on program health, risk posture, and audit readiness to the CISO and executive leadership.
- Lead and grow the team: Hire, manage, coach, and develop a team of GRC analysts. Set clear goals and career paths, run performance reviews, delegate ownership of frameworks and workstreams, and build a culture of rigor, ownership, and continuous improvement.
- Run certifications & audits: Serve as the executive owner for SOC 2 Type II, ISO 27001, ISO 27701, and ISO 42001, plus future frameworks as the business requires. Direct audit scoping, readiness assessments, remediation planning, evidence strategy, and auditor relationships; own the ISMS, PIMS, and AIMS and their management review cycles.
- Lead enterprise risk management: Own the enterprise and security risk framework, risk appetite, and risk register. Chair risk review forums, drive system, vendor, and AI risk assessments, and manage escalation, remediation, and formal risk acceptance with senior stakeholders.
- Drive control assurance: Design the common control framework and continuous-monitoring approach that maps ISO, SOC 2, NIST, GDPR/CPRA, PCI, and HIPAA/HITRUST into a single set of controls. Oversee control testing, exception management, and corrective action through to closure.
- Govern access: Own the access governance program, including periodic access certifications, least-privilege standards, joiner/mover/leaver controls, and privileged access monitoring, in partnership with IT and Engineering.
- Lead third-party risk management: Set the vendor risk strategy and tiering model; oversee due diligence, contractual security and privacy requirements, and ongoing monitoring of critical suppliers, partners, and AI service providers.
- Own customer trust: Lead the customer trust function: security and privacy questionnaires, RFP responses, Trust Center content, and customer-facing security reviews. Act as an executive-level security counterpart for strategic customers and partner with Sales to accelerate enterprise deals.
- Advance governance & privacy: Own the policy and standards lifecycle, security and privacy awareness and role-based training, and privacy operations (DPIAs, data mapping, data subject requests) in partnership with Legal.
- Strengthen resilience & reporting: Sponsor incident response tabletop exercises and business continuity and disaster recovery testing. Deliver executive and board-level dashboards on risks, controls, access, vendor posture, and certification status.
- Shape AI governance: Lead Doppel's approach to responsible AI governance under ISO 42001 and emerging regulation (for example, the EU AI Act), partnering with Product and Engineering to embed controls into how we build and operate AI systems.
What We're Looking For
- 8+ years in GRC, security audit, or risk management, with at least 1 year managing people and owning a GRC or compliance program end to end.
- Track record hiring, developing, and retaining high-performing GRC professionals, and of scaling a program and team through rapid company growth.
- Executive-level ownership of SOC 2 Type II and ISO 27001 programs through multiple certification and surveillance cycles, including scoping, auditor selection and management, and remediation. Hands-on experience with ISO 27701 and ISO 42001 or equivalent privacy and AI governance programs.
- Deep command of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control testing, sampling, and evidence sufficiency in cloud-first environments (AWS/Azure/GCP, SaaS).
- Experience designing and operating enterprise risk management, including risk appetite, risk registers, risk forums, and formal risk acceptance with senior leadership.
- Proven ability to run access certifications, third-party risk management, and customer security reviews at enterprise scale, and to select and implement GRC tooling and automation.
- Strong executive communication skills: comfortable presenting risk and compliance posture to leadership, boards, auditors, and enterprise customers, and translating technical detail into business impact.
- Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or CIPP/CIPM are a plus.
Why This Role Matters
Doppel's customers trust us to protect their brands, people, and data. This role makes that trust demonstrable. As the leader of Doppel's GRC program, you will turn security, privacy, and compliance into a durable competitive advantage: maintaining the certifications our customers require, embedding risk management into how we operate, and building a team that keeps pace with the company.
Your leadership will enable Doppel to scale responsibly, accelerate enterprise deals, reduce operational and regulatory risk, and earn lasting confidence from customers, partners, auditors, and regulators in how we protect data and run our business.