Sr. GRC Analyst-Enterprise Cybersecurity
About Us
Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
Role Summary
As GRC Analyst, you will own the operational delivery of our information security certifications and enterprise cybersecurity risk program. This is a hands-on individual-contributor role: you will run certification cycles end to end, keep our ISMS evidence audit-ready year-round, operate the enterprise risk register, and coordinate a large group of internal control owners and external partners. You will not set strategy from a distance — you will do the work that earns and keeps our certifications and keeps risk visible and tracked.
Responsibilities
Certifications & Audits
Own TISAX follow-on certifications: take over subsequent waves and sites after the initial TISAX AL3 assessments (VDA ISA 6.0.3), and manage evidence maintenance, internal self-assessments, corrective-action tracking, re-assessment readiness, and the ongoing ISMS evidence infrastructure.
Own ISO/IEC 27001 certification: drive achievement and ongoing maintenance of certification, coordinate internal audits, maintain the Statement of Applicability and control evidence, and manage annual surveillance and recertification activities.
Support ISO 9001 efforts as they relate to infrastructure and IT.
Support CSMS compliance under UNECE R155 and software update management under UNECE R156 as they apply to enterprise/IT infrastructure — supporting the cybersecurity management system requirements in an automotive JV/supplier environment.
Track and drive corrective and preventive actions (CAPA) to closure across all frameworks, holding owners to due dates.
Risk Management
Operate the enterprise cybersecurity risk register end to end: risk intake, assessment, treatment tracking, and reporting.
Execute risk management processes in coordination with Legal and in accordance with documented standard operating procedures, including confidentiality classification steps.
Produce clear, prioritized risk reporting for the Sr. Manager, Enterprise Cybersecurity and other stakeholders, with named owners and remediation timelines.
Cross-Functional & Partner Management
Work across a large stakeholder group spanning two parent companies and the JV — IT, Legal, Facilities, Internal Audit, HR, and engineering teams — and coordinate with 15–30+ named control owners for evidence collection.
Manage external partners: certification bodies (accredited ISO/TISAX auditors), external consultants, and vendors — tracking written deliverables, due dates, and response SLAs.
Maintain accurate, audit-ready documentation and program tracking in the team's tooling (e.g., Jira, Confluence, Google Workspace).
Qualifications
5 years of experience in governance, risk, and compliance (GRC), IT/information security compliance, IT audit, or a closely related function.
Bachelor's degree or equivalent practical experience.
Working knowledge of ISO/IEC 27001/27002, TISAX and the NIST Cybersecurity Framework, including risk assessment and treatment concepts and control mapping.
Hands-on experience supporting or coordinating audits and certifications: evidence collection, control validation, and corrective-action tracking.
Experience operating or maintaining a risk register and driving remediation items to closure with accountable owners.
Strong documentation, organization, and project-tracking skills, with the ability to manage multiple concurrent deadlines.
Excellent written and verbal communication; able to work with both technical and non-technical stakeholders across a complex, multi-entity organization.
Ability and willingness to travel domestically and internationally up to a few weeks per quarter.
Preferred Qualifications:
Professional certification such as CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+.
Hands-on experience with GRC/compliance tooling such as ServiceNow GRC, OneTrust, Vanta, Drata, Archer, AuditBoard, or ZenGRC.
Automotive industry experience, especially TISAX/VDA ISA assessments, UNECE R155/R156, ISO/SAE 21434, or IATF 16949.
Experience coordinating external auditors, certification bodies, or consultancies and managing deliverables to SLAs.
Proficiency with Jira, Confluence, and Google Workspace.
Experience in a fast-paced, high-growth, or joint-venture/multi-entity environment.
Travel
Travel up to a few weeks each quarter to company sites in Southern California, Northern California, Vancouver (BC), and Belgrade (Serbia) to support on-site audits, physical security walkthroughs, evidence collection, and stakeholder coordination.
Peak travel aligns with audit windows; a valid passport and the ability to travel internationally are required.
Total Rewards
We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.
Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.
In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs.
External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (). If you are a current employee, please apply through our internal job board.
Equal Opportunity
Rivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.
Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com.
Candidate Data Privacy
Rivian and Volkswagen Group Technologies” may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian and Volkswagen Group Technologies may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) record keeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law.
Rivian and Volkswagen Group Technologies may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian and Volkswagen Group Technologies affiliates; and (iii) Rivian and Volkswagen Group Technologies’ service providers, including providers of background checks, staffing services, and cloud services.
Rivian and Volkswagen Group Technologies may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.
If you provide a mobile telephone number as part of your application or during the recruitment process, Rivian and Volkswagen Group Technologies may use that number to contact you via SMS text message for recruitment-related purposes, including scheduling, logistics, and status updates. Message and data rates may apply. You may opt out of SMS communications at any time by replying STOP to any text message you receive from us. Consent to receive SMS messages is not a condition of applying for or being considered for employment.
Please see our Candidate Data Privacy Notice (English) and Candidate Data Privacy Notice (Serbian) for more information.
--
Please note this job posting represents an open, active vacancy. Additionally, we are not currently accepting applications from third party application services.
As published by ashby
Name, Email, Resume, Location, Interview Recording Consent
- Preferred first name optional
- Phone
- LinkedIn URL optional
- Other website optional
- Current or most recent employer
- Are you currently authorized to work for any employer in the United States? choose one
- Have you ever worked for RV Tech and/or Rivian, in any capacity, including as a contractor/contingent worker, or as an RV Tech VW Group Partner? choose one
- I authorize the RV Tech Talent Acquisition team to consider me for other job opportunities within RV Tech in addition to the specific job I am applying for. choose one
- I certify the information provided in this application is true and correct to the best of my knowledge. I understand any false statements or omissions may result in disqualification from employment consideration or, if employed, termination. choose any
- I understand my application will be processed in accordance with RV Tech’s Candidate Privacy Policy. choose any