Skip to main content

Director, Governance, Risk & Compliance

DoppelLegal & Compliance
Work mode
Remote
Full Time
Location
Experience
10+ yrs
Director

What you need

  • 10+ yrs GRC, security risk, compliance, audit experience
  • Built and scaled GRC programs in high-growth SaaS/cybersecurity
  • Strategic advisor to executives on security/compliance risk
  • Executive ownership of SOC 2 Type II, ISO 27001 certifications
  • Deep knowledge of ISMS/PIMS/AIMS, control frameworks, cloud environments

What you'll do

  • Define and execute multi-year GRC strategy and roadmap
  • Build and lead high-performing GRC team and organization
  • Own compliance certifications: SOC 2, ISO 27001, 27701, 42001
  • Lead enterprise risk governance and control assurance programs
  • Advise executives and board on risk and compliance posture

About the Role

Doppel is looking for a Director, Governance, Risk & Compliance to lead and scale our GRC function as the company grows. You will set the company-wide strategy, operating model, and multi-year roadmap for governance, risk, compliance, privacy, third-party risk, control assurance, and customer trust.

As the leader accountable for GRC at Doppel, you will ensure our security and compliance programs scale with the complexity of our business, customers, products, and regulatory environment. You will own the strategy for SOC 2, ISO 27001, ISO 27701, ISO 42001, and future frameworks while building the systems, team, and governance structure required to operate them efficiently at scale.

You will serve as a strategic advisor to the CISO and executive leadership on enterprise risk and compliance, provide visibility into material risks and control posture, and represent Doppel with auditors, strategic customers, and other external stakeholders. You will partner closely with Security, Engineering, Product, IT, Legal, People, Finance, and Sales to embed effective risk management into how the company operates without creating unnecessary friction.


What You'll Do

  • Set the GRC strategy: Define and execute Doppel's multi-year GRC strategy, operating model, and roadmap. Establish priorities, investment areas, tooling and automation strategy, KPIs, and governance mechanisms that allow the function to scale with the business.

  • Build and lead the GRC organization: Lead, develop, and grow a high-performing GRC team. Define organizational structure, roles, ownership, and career paths; hire and develop talent; establish clear accountability; and build future leaders as the function expands.

  • Own compliance and certification strategy: Maintain executive accountability for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and future frameworks required by the business. Establish the approach to audit readiness, management systems, control ownership, remediation, and external auditor relationships while ensuring the team can execute certification programs effectively.

  • Lead enterprise risk governance: Establish and evolve Doppel's enterprise and security risk management framework, including risk appetite, risk assessment methodology, escalation thresholds, risk acceptance, and executive review. Ensure material risks are clearly surfaced to senior leadership and that accountable owners drive remediation.

  • Scale control assurance and security governance: Set the strategy for Doppel's common control framework and continuous assurance program across ISO, SOC 2, NIST, privacy, and other regulatory or customer requirements. Establish governance for control testing, access risk, exceptions, corrective actions, and evidence quality while increasing automation and reducing manual compliance work.

  • Own third-party and emerging risk strategy: Establish the governance model for vendor, partner, and AI-related risk, including risk tiering, due diligence standards, contractual requirements, ongoing monitoring, and escalation. Ensure Doppel can adopt new technologies and vendors quickly while maintaining appropriate risk controls.

  • Lead customer trust strategy: Own the strategy and operating model for customer security and privacy assurance, including enterprise diligence, Trust Center content, security reviews, and RFP support. Serve as the senior security and risk counterpart for strategic customers and partner with Sales and Customer Success to reduce security-related friction in enterprise deals.

  • Shape privacy and AI governance: Partner with Legal, Product, Engineering, and Security to establish scalable privacy and responsible AI governance. Ensure programs such as privacy impact assessments, data governance, and ISO 42001 evolve alongside Doppel's products and emerging regulatory requirements.

  • Strengthen organizational resilience: Provide executive oversight of security governance related to incident preparedness, business continuity, disaster recovery, and other operational resilience programs. Ensure material findings and gaps have clear ownership and remediation plans.

  • Advise executives and the board: Deliver clear, decision-oriented reporting on enterprise risk, compliance posture, control effectiveness, third-party risk, and certification status. Translate technical and regulatory complexity into business impact and recommendations for senior leadership and the board.

What We're Looking For

  • 10+ years of experience across GRC, security risk, compliance, security audit, or related disciplines, including significant experience leading teams and owning a GRC function or similarly broad program.

  • Experience building and scaling GRC programs and teams in a high-growth technology, SaaS, cybersecurity, or similarly complex environment.

  • Demonstrated ability to operate as a strategic advisor to senior executives, translating security, compliance, and regulatory risk into clear business decisions and priorities.

  • Executive ownership of SOC 2 Type II and ISO 27001 through multiple certification and surveillance cycles, including program strategy, scoping, auditor management, remediation, and management review. Experience with ISO 27701, ISO 42001, or comparable privacy and AI governance programs is strongly preferred.

  • Deep understanding of management systems (ISMS/PIMS/AIMS), Trust Services Criteria, common control frameworks, control assurance, and evidence requirements within cloud-first environments.

  • Experience designing and operating enterprise risk management programs, including risk appetite, risk registers, governance forums, escalation, remediation, and formal risk acceptance.

  • Experience overseeing third-party risk, access governance, privacy, customer security assurance, and other core GRC programs at scale.

  • Track record building high-performing teams, developing talent, establishing clear ownership models, and determining how organizational structure should evolve as a company grows.

  • Experience developing GRC tooling and automation strategies that improve assurance while reducing manual work and operational friction.

  • Strong executive communication and influence skills, including experience presenting risk and compliance posture to executive leadership, boards, auditors, and enterprise customers.

  • Ability to operate effectively in ambiguity, prioritize across competing business and risk requirements, and build durable systems in a rapidly scaling environment.

  • Relevant certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, CIPP, or CIPM are a plus.

Why This Role Matters

Doppel's customers trust us to protect their brands, people, and data. As Doppel grows, the systems that demonstrate and govern that trust must scale with the company.

The Director of Governance, Risk & Compliance will build the organizational capability that enables Doppel to enter new markets, meet increasingly complex enterprise and regulatory requirements, and make informed decisions about risk without slowing the business down.

Your leadership will shape how Doppel approaches risk, compliance, privacy, customer trust, and responsible AI at scale. You will build the team and operating model behind these programs, give executives and the board clear visibility into material risk, and help ensure security and compliance remain an advantage as Doppel grows.


Join Doppel

Doppel is the first platform built to dismantle digital deception at scale. We scan over 150 billion entities daily and deploy continuously adaptive AI SOC agents, paired with expert human analysts, to uncover and disrupt the infrastructure behind phishing, impersonation, and online fraud before attacks can spread. Our Threat Grid turns every customer signal into shared intelligence, making each disruption smarter, faster, and more effective.


We’re not just another cybersecurity company. We’re defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and trusted by some of the world’s most recognized brands, Doppel is growing fast. If you’re driven to solve real-world problems with bold technology, we’d love to meet you.

Optimize your resume for this job

Get a match score and the keywords you're missing

Optimize resume

About Doppel

In the era of AI, knowing what’s real is harder than ever. Social engineering threats lurk in your inbox, on social channels, hiding in the places you least expect. They pose as people and brands you trust, using advanced AI tech to deceive and defraud. Doppel is the social engineering defense platform using AI to fight AI. Built to outpace and overpower your would-be attackers, our defenses work double time: proactively safeguarding every channel, while leveraging simulations and security training to strengthen your team’s resilience. With unbeatable speed and compounding intelligence, our AI-forensics crush threats before they ever gain momentum. We work relentlessly to defend your brand, people, and future from whatever comes next in social engineering. Backed by Bessemer Venture Partners, a16z, George Kurtz - CEO, CrowdStrike, South Park Commons, Strategic Cyber Ventures, Aurum Partners, a group of athlete investors led by WNBA players Nneka Ogwumike, Breanna Stewart, and Kelsey Plum, who joined the round through the a16z Cultural Leadership Fund, Script Capital, 9Yards Capital, Sozo Ventures, NTT DOCOMO Ventures, and SVAngel.

Similar Legal & Compliance roles

Director, Governance, Risk & Compliance
Doppel
Apply