Form Energy
Director, Cybersecurity & GRC
Berkeley, CA · Director · Full-time
Sponsorship not specified$171k-$800kDetected 22 days ago
CybersecurityDetection EngineeringIncident ResponseComplianceLeadershipCommunication
About the role
- As Form Energy matures and scales, the Director of Cybersecurity & GRC builds and leads our cybersecurity and IT governance, risk, and compliance programs.
Responsibilities
- Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response
- manage security vendors and the managed SOC.
- Own IT governance, risk, and compliance - directing a GRC Manager who owns ITGC design, operation, and evidence end-to-end
- Partner on the IT/OT security boundary and with product security, without owning operational technology or on-product (battery) cybersecurity.
- Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response; manage security vendors and the managed SOC.
- Own IT governance, risk, and compliance - directing a GRC Manager who owns ITGC design, operation, and evidence end-to-end; the policy and standards lifecycle within an ISO 27001-aligned ISMS; the enterprise IT risk register; control mapping; and exception/issue tracking.
- Lead, coach, and develop the cybersecurity and GRC team; hire selectively against clear capability gaps.
- Deep ITGC experience - control design, operation, and audit - in a compliance-intensive or scaling-company setting, with the judgment to direct a GRC Manager and external advisors.
- Are you ready to build America's energy future?
- We're revolutionizing energy storage with cost-effective, multi-day technology designed to keep the electric grid secure and reliable, even during extended periods of stress.
Requirements
- Design a control framework synergistic across ITGC, SOC 2, ISO 27001, and NIST 800-171 / CMMC scopes as required by the business and customer contracts.
Nice to have
- Experience in manufacturing, energy, or critical-infrastructure sectors.
- Experience standing up a first-time formal IT controls environment in a scaling company.
- Certifications such as CISSP, CISA, CISM, or CRISC.
- Familiarity with privacy regimes (GDPR / CCPA) and AI governance frameworks (Form Energy's AI governance is led separately within the Chief Digital Officer organization
- This starts from day one.
- Requests for accommodations will be treated with discretion.
- Form Energy is committed to maintaining the privacy of our applicants.
- Please be aware that we will never solicit sensitive personal information such as Social Security numbers or bank account details during the recruiting or hiring process.
Compensation
- Humanity is a cornerstone of Form Energy's culture, and we make sure our compensation and benefits reflect that.
Company info
- you will set strategy and lead a team - a GRC Manager who owns IT general controls end-to-end, a Staff Security Engineer, and a Senior Security Engineer - while owning the security program, the policy and standards lifecycle, enterprise IT risk, and the external-audit relationship.
- You will mature an ISO 27001-aligned information security management system and the controls a maturing, compliance-intensive company depends on, backstopped by an external advisor.
- This is a hybrid role, which will require working onsite from one of our office locations 3+ days per week.
- Relocation assistance is available.
- We are making rapid progress on our mission of delivering energy storage for a better world, and our team is growing just as rapidly to meet demand.
Apply directly at Form Energy →Create a free account for alerts like thisView Form Energy immigration profile
This listing is sourced directly from Form Energy's careers page and normalized into a canonical job model.