Form Energy

Form Energy

Director, Cybersecurity & GRC

Berkeley, CA · Director · Full-time

Sponsorship not specified$171k-$800kDetected 22 days ago
CybersecurityDetection EngineeringIncident ResponseComplianceLeadershipCommunication

About the role

  • As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs.

Responsibilities

  • Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response
  • manage security vendors and the managed SOC.
  • Own IT governance, risk, and compliance - directing a GRC Manager who owns ITGC design, operation, and evidence end-to-end
  • Partner on the IT/OT security boundary and with product security, without owning operational technology or on-product (battery) cybersecurity.
  • Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response; manage security vendors and the managed SOC.
  • Own IT governance, risk, and compliance - directing a GRC Manager who owns ITGC design, operation, and evidence end-to-end; the policy and standards lifecycle within an ISO 27001-aligned ISMS; the enterprise IT risk register; control mapping; and exception/issue tracking.
  • Lead, coach, and develop the cybersecurity and GRC team; hire selectively against clear capability gaps.
  • Deep ITGC experience - control design, operation, and audit - in a compliance-intensive or scaling-company setting, with the judgment to direct a GRC Manager and external advisors.
  • Are you ready to build America's energy future?
  • We're revolutionizing energy storage with cost-effective, multi-day technology designed to keep the electric grid secure and reliable, even during extended periods of stress.

Requirements

  • Design a control framework synergistic across ITGC, SOC 2, ISO 27001, and NIST 800-171 / CMMC scopes as required by the business and customer contracts.

Nice to have

  • Experience in manufacturing, energy, or critical-infrastructure sectors.
  • Experience standing up a first-time formal IT controls environment in a scaling company.
  • Certifications such as CISSP, CISA, CISM, or CRISC.
  • Familiarity with privacy regimes (GDPR / CCPA) and AI governance frameworks (Form Energy's AI governance is led separately within the Chief Digital Officer organization
  • This starts from day one.
  • Requests for accommodations will be treated with discretion.
  • Form Energy is committed to maintaining the privacy of our applicants.
  • Please be aware that we will never solicit sensitive personal information such as Social Security numbers or bank account details during the recruiting or hiring process.

Compensation

  • Humanity is a cornerstone of Form Energy's culture, and we make sure our compensation and benefits reflect that.

Company info

  • you will set strategy and lead a team - a GRC Manager who owns IT general controls end-to-end, a Staff Security Engineer, and a Senior Security Engineer - while owning the security program, the policy and standards lifecycle, enterprise IT risk, and the external-audit relationship.
  • You will mature an ISO 27001-aligned information security management system and the controls a maturing, compliance-intensive company depends on, backstopped by an external advisor.
  • This is a hybrid role, which will require working onsite from one of our office locations 3+ days per week.
  • Relocation assistance is available.
  • We are making rapid progress on our mission of delivering energy storage for a better world, and our team is growing just as rapidly to meet demand.

This listing is sourced directly from Form Energy's careers page and normalized into a canonical job model.