GRC Manager (f/m/d)
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Responsibilities
- Develop, maintain and continuously improve the ISMS, including policies, standards, procedures and control frameworks.
- Coordinate security governance activities and ensure alignment with internal requirements, regulatory obligations and business priorities.
- Perform and facilitate information security risk assessments, control reviews and remediation tracking.
- Prepare, coordinate and support internal and external audits, certifications and compliance reviews.
- Maintain risk registers, control documentation, evidence repositories and management reporting materials.
- Partner with stakeholders across Technology, Product, Legal, Compliance, Data Protection, Operations and other business areas to implement security and compliance requirements.
- Support third-party risk management activities, including assessment coordination, documentation review and follow-up actions.
- Develop reporting for senior management and the CISO, including KPIs, KRIs, control status and risk exposure updates.
- Drive awareness of governance and security requirements through documentation, guidance and cross-functional enablement.
Requirements
- Several years of professional experience in GRC, ISMS, Information Security, IT Risk, Audit or Compliance.
- Strong working knowledge of common frameworks and standards such as ISO 27001, NIST, SOC 2 or comparable control frameworks.
- Proven experience in policy development, risk management, audit preparation and evidence-based compliance work.
- Ability to work effectively in cross-functional, fast-paced and evolving business environments.
- Strong analytical, organizational and stakeholder management skills.
- Excellent written and verbal communication skills in English; German is a strong advantage.
- Success Profile
- Structured and detail-oriented, while able to balance governance quality with business pragmatism.
- Confident working with both technical and non-technical stakeholders.
- Comfortable taking ownership in a fast-scaling environment with short decision paths and high visibility.
Benefits
Additional Information
Our goal is to have a solar system on every roof, a storage unit in every house, and an electric car in every garage. Enpal makes this possible with an integrated total solution for decentralized energy-from solar systems and battery storage to wall boxes, smart meters, and heat pumps. At the heart of it all is our AI-powered platform Enpal.One +, which intelligently connects thousands of systems and efficiently optimizes electricity procurement and feed-in on the energy market. Are you ready for solutions that are more than just a promise and bring real quality of life to thousands of households every day? What you create at Enpal will deliver clean electricity tomorrow and bring about lasting change in how we use energy. The GRC / ISMS Manager is responsible for the development, operational management and continuous improvement of the company's governance, risk and compliance framework as well as the Information Security Management System (ISMS). The role acts as a key interface between Information Security and business functions, ensuring that security governance, regulatory expectations, risk transparency and audit readiness are embedded in a pragmatic and scalable way. This is an individual contributor manager role without disciplinary people management responsibility and with direct reporting to the CISO.
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at Enpal? Share your experience