Enpal
Climate Tech
GRCManager(f/m/d)
Neural analysis suggests this role is
optimal for Manager candidates.
“GRC Manager (f/m/d) at Enpal. Skills: GRC, ISMS, Information Security, Risk management. Develop, maintain and continuously improve the ISMS. Coordinate security governance activities”
What You'll Achieve.
Ensure security governance; Ensure regulatory expectations; Ensure risk transparency; Ensure audit readiness
Industry & Context.
Analytical skills
What They're Looking For.
Must Have
Several years of professional experience in GRC, ISMS, Information Security, IT Risk, Audit or Compliance, Working knowledge of common frameworks and standards such as ISO 27001, NIST, SOC 2 or comparable control frameworks, Proven experience in policy development, risk management, audit preparation and evidence-based compliance work, Ability to work effectively in cross-functional, fast-paced and evolving business environments, Analytical, organizational and stakeholder management skills
Nice to Have
Excellent written and verbal communication skills in German is a advantage
What You'll Do.
maintain and continuously improve the ISMS
Coordinate security governance activities
Ensure alignment with internal requirements
regulatory obligations and
Perform information security risk assessments
Facilitate information security risk assessments
Perform control reviews
Facilitate control reviews
Prepare internal audits
Coordinate internal audits
Support internal audits
Prepare external audits
Coordinate external audits
Support external audits
Prepare compliance reviews
Coordinate compliance reviews
Support compliance reviews
Maintain risk registers
Maintain control documentation
Maintain evidence repositories
Maintain management reporting materials
Partner with stakeholders
Implement security requirements
Implement compliance requirements
Support third-party risk management activities
Coordinate third-party risk assessment
Review third-party documentation
Follow-up on third-party actions
Develop reporting for senior management
Develop reporting for the CISO
Drive awareness of governance requirements
Drive awareness of security requirements
Provide documentation
Provide cross-functional enablement
How You'll Work.
Team & Collaboration
Cross-functional teams; Technology stakeholders; Product stakeholders; Legal stakeholders; Compliance stakeholders; Data Protection stakeholders; Operations stakeholders; Business areas
Communication Scope
Written communication; Verbal communication
Full Job Description
Our goal is to have a solar system on every roof, a storage unit in every house, and an electric car in every garage. Enpal makes this possible with an integrated total solution for decentralized energy—from solar systems and battery storage to wall boxes, smart meters, and heat pumps. At the heart of it all is our AI-powered platform Enpal.One http://Enpal.One+, which intelligently connects thousands of systems and efficiently optimizes electricity procurement and feed-in on the energy market. Are you ready for solutions that are more than just a promise and bring real quality of life to thousands of households every day? What you create at Enpal will deliver clean electricity tomorrow and bring about lasting change in how we use energy. The GRC / ISMS Manager is responsible for the development, operational management and continuous improvement of the company’s governance, risk and compliance framework as well as the Information Security Management System (ISMS). The role acts as a key interface between Information Security and business functions, ensuring that security governance, regulatory expectations, risk transparency and audit readiness are embedded in a pragmatic and scalable way. This is an individual contributor manager role without disciplinary people management responsibility and with direct reporting to the CISO. What you'll do - Develop, maintain and continuously improve the ISMS, including policies, standards, procedures and control frameworks. - Coordinate security governance activities and ensure alignment with internal requirements, regulatory obligations and business priorities. - Perform and facilitate information security risk assessments, control reviews and remediation tracking. - Prepare, coordinate and support internal and external audits, certifications and compliance reviews. - Maintain risk registers, control documentation, evidence repositories and management reporting materials. - Partner with stakeholders across Technology, Product, L
Applying for this GRC Manager (f/m/d) role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Enpal?
Real rants from real employees. Read before you apply.