Overview
We are designing the grid of the future!
The Technology Risk & Compliance Lead is responsible for developing, implementing, and maintaining the organization’s technology risk and compliance program across all business units. This includes oversight of IT and security compliance, technology risk management, audit readiness, control governance, vendor risk management, and various compliance frameworks such as SOC 2, ISO 27001, and other relevant standards. The role requires collaboration across departments to ensure adherence to laws, regulations, and industry standards, while also fostering a strong culture of compliance and risk management.
Responsibilities
How you can make an impact:
Compliance Program Management
- Develop, implement, and manage various company-wide compliance programs.
- Monitor compliance with applicable laws, regulations, and industry standards.
- Partner with business, IT, Security, Legal, HR, Software, and Finance teams to develop, document, implement, and maintain compliance policies, procedures, controls, and supporting workflows.
- Conduct internal compliance audits, control testing, and evidence reviews; track findings through remediation and closure partnering with our business.
- Evaluate, implement, and manage compliance, risk, or audit management software, including related workflows, reporting, and evidence repositories.
- Maintain the organization’s technology control framework, control library, policy inventory, evidence repository, and compliance calendar.
- Map compliance obligations, customer commitments, audit requirements, vendor obligations, and internal controls to reduce duplication and improve consistency across compliance activities.
- Manage technology risk and compliance projects from initiation through closure, including scope definition, planning, scheduling, stakeholder coordination, execution tracking, risk and issue management, and status reporting.
- Develop and maintain project plans, milestones, dependencies, action items, decision logs, and executive-level project updates for audits, certifications, remediation initiatives, vendor risk activities, customer assurance efforts, and compliance improvement projects.
- Coordinate cross-functional workstreams involving IT, Security, Legal, HR, Finance, and software teams to ensure deliverables are completed on time and aligned with compliance and risk objectives.
- Track project risks, blockers, resource constraints, and dependency conflicts; escalate issues appropriately and drive resolution with accountable owners.
- Facilitate working sessions, readiness reviews, remediation meetings, audit preparation meetings, vendor review meetings, and stakeholder updates.
- Apply structured project management practices to improve predictability, accountability, documentation quality, and timely completion of compliance and risk initiatives.
- Support the implementation and ongoing improvement of GRC, audit management, vendor risk, and compliance automation tools, including requirements gathering, workflow design, user acceptance testing, rollout planning, adoption tracking, and post-implementation optimization.
- Prepare clear, concise project reporting for leadership, including progress against milestones, overdue items, risk trends, key decisions, and required executive action.
IT & Security Compliance
- Support and help drive efforts to achieve and maintain certifications such as SOC 2, ISO 27001, and other relevant frameworks, in partnership with IT, Security, Legal, HR, Software, and business stakeholders.
- Partner with IT and Security teams to ensure compliance requirements are built into technology processes.
- Coordinate audit evidence collection across departments, ensuring documentation is complete, accurate, timely, and audit-ready.
- Manage risk assessments, gap analyses, and remediation plans for IT compliance.
- Coordinate external audits and act as primary liaison with auditors and certification bodies.
- Work with control owners to define control intent, evidence expectations, testing procedures, and remediation requirements.
- Support internal and external audits by coordinating requests, preparing evidence, tracking auditor inquiries, and maintaining audit status reporting.
- Document control gaps, audit findings, and process deficiencies; assign accountable owners and track corrective actions through closure.
Risk & Governance
- Conduct enterprise technology and compliance risk assessments, and track treatment plans through closure.
- Collaborate with executive leadership to ensure compliance risk is included in corporate strategy.
- Monitor regulatory changes, industry trends, and compliance best practices; recommend updates to policies, controls, training, and governance processes as appropriate.
- Maintain regulatory and compliance risk register.
- Maintain mappings between control frameworks, audit requirements, and internal controls.
- Provide compliance reporting and metrics to senior management and the Board of Directors.
Third Party Risk Management
- Partner with Procurement, Legal, Security, IT, and business owners on third-party risk management and vendor compliance reviews.
- Support vendor risk assessments, due diligence reviews, security questionnaires, evidence reviews, and contract-related compliance obligations.
- Document vendor risks, control gaps, compensating controls, risk decisions, and required follow-up actions.
- Track vendor remediation commitments, reassessments, and ongoing monitoring activities based on vendor criticality and risk.
- Support customer security and compliance inquiries, including questionnaires, evidence requests, and contract-related control commitments.
- Track customer security and compliance commitments to ensure they are reviewed, approved, mapped to internal controls, and monitored for ongoing compliance.
Governance Training & Awareness
- Support governance processes for technology policies, standards, control ownership, risk acceptance, policy exceptions, audit findings, and remediation tracking.
- Work with the Learning and Development department to design and deliver compliance and ethics training across the organization.
- Develop guidance for control owners on evidence quality, audit expectations, compliance workflows, and remediation responsibilities.
- Promote awareness of relevant compliance requirements and best practices.
- Serve as a trusted advisor on technology risk, compliance, audit readiness, vendor risk, and customer assurance matters for leadership and employees.
Qualifications
Bring your passion, here's what’s needed:
Education
- Bachelor’s degree in Business, Law, Information Security, or related field
- Master’s preferred in Business, Information Systems, or related field
- Compliance-related certifications (e.g., CISA, CISM, CISSP, CCEP, ISO 27001 Lead Implementer/Auditor) are highly desirable.
- Project management-related certifications (CAPM, PMP, PMI-ACP) or equivalent project/program management experience preferred.
Experience
- 5+ years of technology compliance, risk management, GRC program management, or IT audit experience.
- Demonstrated experience managing SOC 2, NIST, ISO 27001, or other IT compliance frameworks.
- Strong knowledge of technology corporate governance, regulatory compliance, and risk management principles.
- Experience working cross-functionally with IT, Legal, HR, and business leadership.
- Experience supporting vendor risk management, third-party due diligence, or customer security questionnaires.
Skills
- Strong project management and organizational skills.
- Excellent written and verbal communication skills.
- Ability to interpret complex regulations and translate them into actionable business requirements.
- Proven ability to manage external auditors and regulatory bodies.
- High integrity, discretion, and ability to handle confidential information.
Key Performance Indicators (KPIs)
- Successful completion of compliance audits (SOC 2, ISO 27001, etc.).
- Timely remediation of identified compliance gaps.
- Reduction of compliance-related risks and incidents.
- Positive feedback from internal stakeholders and external auditors.
Lead the Change!
Be a part of an innovative team shaping the grid of the future through advanced energy intelligence. For more than half a century, Electric Power Engineers (EPE) has partnered with power and energy clients across the globe, providing consulting expertise and energy intelligence software solutions for complex engineering and grid modeling challenges. As leaders in the renewables space, we are focused on building a modern, secure, and resilient grid. Join us in making an impact on the communities we serve and the environment in which we live. Together we can transform the future of energy.
How we support you:
- Comprehensive health and wellness benefits including medical, dental, and vision with 100% premium coverage for you
- Generous PTO and paid holidays
- MyShare Employee Ownership Program
- Work with industry leaders
- 401K, up to a 4% match (100% vested from day 1)
Location: This position will be remote US
Travel: Occasional travel may be needed (10% or less)
EPE is an equal opportunity/AA/Disability/Veteran employer. The EEO is the Law poster, and its supplement are available using the following links: EEOC is the Law Poster
Third-Party Recruiting Notification
EPE does not accept unsolicited resumes from third-party recruiters. Any unsolicited third-party resumes forwarded by recruiters to EPE via our career page or to any of our managers or employees will be considered public information, may be treated as a direct application from the person identified in the resume, and will not be eligible for placement fee payment to the agency. EPE will not pay a fee to a third-party recruiter or agency without a previously signed third-party agreement and has not coordinated their recruiting activity with the appropriate member of the Talent Acquisition team.