Jobs and Careers
SC

Senior Specialist, Information Security Governance, Risk, and Compliance

Scout Motors
United Statesfull_timeVerifiedPosted 9 Sept 2024
💰 $160,000/yr($140,000/yr$160,000/yr)

About the role

Scout Motors   

Here at Scout Motors, we're carrying forward the heritage of one of the most iconic American vehicles in history. A vehicle dating back to 1960. One that forged the path for future generations of rugged SUVs and will do so once again.

But Scout is more than just a brand, it’s a legacy steeped in a culture of exploration, caretaking, and hard work.

Scout is all about respect.  Respect for the environment by developing electric vehicles with the capability to get you to any location.  Respect for the past and the future by taking an iconic American brand that hasn’t been around for a while, electrifying it, digitizing it, and loading it with American innovation.  Respect for communities by creating a company that stands for its people and its customers.  And respect for both work and play, with vehicles that are equally at home at a camp site, a job site, or on a Tuesday commute. 

At Scout Motors, we empower our talented, inclusive, and entrepreneurial teams to innovate. What makes a Scout? Someone who is a visionary and a leader, who seeks new paths and shares lessons learned. A knowledgeable doer who collaborates across the company to build better. A go-getter with unrivaled passion. 

Join us at Scout Motors and be part of shaping the future of transportation. If you're ready to drive change and make history, apply now!

Scout Motors Inc. (Scout) is hiring an Information Security Governance, Risk, and Compliance Senior Specialist that will be responsible for leading and driving the development and management of various elements of security governance, risk, and compliance, along with customer trust and privacy. This role will need to build functions/programs from scratch with limited oversight or direction to meet the objectives of the Information and Vehicle Security Team. Our ideal candidate for this role will be someone who has multiple years of experience in the GRC, customer trust, and data privacy space and wants to use that experience to build these functions for an excited EV automotive start backed by VW Group. Additionally, th to be analytical, data driven, and forward thinking to ensure the privacy, trust, or GRC functions are built to scale the business. This role will be an individual contributor (IC) role with potential for advancement and people management as the company grows. 

Why join us? Our Information Security GRC Team at Scout is helping to build the next generation of electric trucks and rugged SUVs for American drivers. You will be building and then owning security functions within the security organization. You will have the opportunity to engage with stakeholders and control owners across the organization as you work to build out the necessary pieces of GRC, customer trust, privacy, etc. You will provide real impact in moving the ball forward to support Scout’s aggressive growth strategy and vision.

What you’ll do

  • Manage the development, annual review, and off-cycle requests for security policies and standards. 
  • Manage the execution of cyber risk assessments for business processes, technology, and products and driving risk treatment activities with risk owners.
  • Build functions for the engagement of privacy, trust and GRC programs with customers, employees, and stakeholders to enable “Security-as-a-service” principles and goals. 
  • Assist in the buildout and management of the GRC tooling and associated data to include the GRC platform, TPRM application, Microsoft Purview DLP & Insider Threat, LMS, etc. 
  • Manage external audits by the VW Group and certification bodies through the audit lifecycle. 
  • Direct internal security IT audits to include evidence lifecycle management, control walkthrough scheduling and execution, and the documentation and management of control corrective action plans. 
  • Own and manage the development of security compliance programs for industry security frameworks (SOX ITGCs, AICPA TSC [SOC 2], ISO 27001//27701/21434, TISAX, GDPR, CPRA, NIST CSF, etc.). 
  • Work with engineering teams to drive the implementation of security requirements and controls across colocation infrastructure, multiple cloud environments (Azure/AWS), and dozens of third-party SaaS solutions. 
  • Make recommendations to management regarding programs, processes, etc. to streamline and improve the way Scout executes its security objectives and goals.  
  • Provide support and mentor other members on the team, sharing insights, knowledge, and experience. 
  • Engage in team-building events, community engagement, team off-sites, peer-review & performance review cycles and activities.
  • Take ownership for assigned tasks, document actions and status, and report during team stand-ups.

Location & Travel Expectations: The responsibilities of this role require

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Scout Motors

View company profile →