Director of Cybersecurity & Governance, Risk, and Compliance
Form Energy · United States
About The Role
Join Form Energy, a company focused on revolutionizing energy storage. As the Director of Cybersecurity & Governance, Risk, and Compliance, you will lead the cybersecurity and IT governance, risk, and compliance programs. This is a CISO-track leadership role where you will set strategy, lead a team, and own the security program, policy and standards lifecycle, enterprise IT risk, and external-audit relationship. You will also mature an ISO 27001-aligned information security management system and design a control framework. Additionally, you will serve as the primary IT liaison to external auditors, mature incident response and disclosure governance, establish data classification, retention, and encryption standards, and report cybersecurity and compliance posture to leadership.
- Establecer la estrategia y liderar un equipo en la gestión de programas de ciberseguridad y gobernanza, riesgo y cumplimiento (GRC).
- Desarrollar y madurar un sistema de gestión de seguridad de la información alineado con ISO 27001 y un marco de control sinérgico.
- Actuar como el principal enlace de TI con auditores externos y asesores de preparación, impulsando la preparación para auditorías y apoyando el trabajo de campo.
- 10+ years in cybersecurity and/or IT GRC, including 5+ years in leadership (CISO-track)
- Breadth across the security program: IAM, EDR/MDR, vulnerability management, and incident response, with fluency in recognized frameworks (ISO 27001, SOC 2, NIST CSF / 800-53; NIST 800-171 / CMMC a plus)
- Strong people leadership and executive-grade communication, including board-quality reporting
- Deep ITGC experience — control design, operation, and audit — in a compliance-intensive or scaling-company setting, with the judgment to direct a GRC Manager and external advisors
- Experience as an external-audit liaison, plus policy authorship and lifecycle ownership
- Experience in manufacturing, energy, or critical-infrastructure sectors
- Certifications such as CISSP, CISA, CISM, or CRISC
- Experience standing up a first-time formal IT controls environment in a scaling company
- Familiarity with privacy regimes (GDPR / CCPA) and AI governance frameworks (Form Energy’s AI governance is led separately within the Chief Digital Officer organization; this role collaborates rather than owns it)
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring