SlipstreamJobsFresh Startup & VC-Backed Jobs

Director, Governance, Risk & Compliance

Doppel - Remote - Remote - posted 2026-09-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Doppel is seeking a Director of Governance, Risk & Compliance to lead and scale the GRC function as the company grows. You will set company-wide strategy, operating model, and multi-year roadmap for governance, risk, compliance, privacy, third-party risk, control assurance, and customer trust. As the leader accountable for GRC, you will ensure security and compliance programs scale with business complexity, customers, products, and regulatory environment. You will own strategy for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and future frameworks while building systems, team, and governance structure to operate them efficiently at scale. You will serve as strategic advisor to the CISO and executive leadership on enterprise risk and compliance, provide visibility into material risks and control posture, and represent Doppel with auditors, strategic customers, and external stakeholders. You will partner with Security, Engineering, Product, IT, Legal, People, Finance, and Sales to embed effective risk management into company operations. Key responsibilities include: defining and executing multi-year GRC strategy and operating model; building and leading a high-performing GRC team with clear structure, roles, and career paths; maintaining executive accountability for compliance certifications; establishing enterprise and security risk management framework; scaling control assurance and security governance; owning third-party and emerging risk strategy; leading customer trust and security assurance strategy; shaping privacy and AI governance; providing executive oversight of security governance and organizational resilience; and delivering clear risk reporting to executives and board. Doppel is the first platform built to dismantle digital deception at scale, scanning over 150 billion entities daily and deploying continuously adaptive AI SOC agents paired with expert human analysts to uncover and disrupt infrastructure behind phishing, impersonation, and online fraud. The company is backed by top-tier investors and trusted by recognized brands. REQUIREMENTS: - 10+ years of experience across GRC, security risk, compliance, security audit, or related disciplines, including significant experience leading teams and owning a GRC function or similarly broad program - Experience building and scaling GRC programs and teams in high-growth technology, SaaS, cybersecurity, or similarly complex environments - Demonstrated ability to operate as strategic advisor to senior executives, translating security, compliance, and regulatory risk into clear business decisions - Executive ownership of SOC 2 Type II and ISO 27001 through multiple certification and surveillance cycles, including program strategy, scoping, auditor management, remediation, and management review - Experience with ISO 27701, ISO 42001, or comparable privacy and AI governance programs (strongly preferred) - Deep understanding of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control assurance, and evidence requirements within cloud-first environments - Experience designing and operating enterprise risk management programs, including risk appetite, risk registers, governance forums, escalation, remediation, and formal risk acceptance - Experience overseeing third-party risk, access governance, privacy, customer security assurance, and other core GRC programs at scale - Track record building high-performing teams, developing talent, establishing clear ownership models, and determining organizational structure evolution - Experience developing GRC tooling and automation strategies that improve assurance while reducing manual work - Strong executive communication and influence skills, including experience presenting to executive leadership, boards, auditors, and enterprise customers - Ability to operate effectively in ambiguity, prioritize across competing business and risk requirements, and build durable systems in rapidly scaling environment - Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, CIPP, or CIPM (a plus)

Similar roles