Jobgether
Principal Security GRC Analyst
engineeringfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Accountabilities:
- Drive the continued maturity of a comprehensive security governance, risk, and compliance program across multiple regulatory and security frameworks.
- Own complex compliance initiatives end-to-end, from requirements analysis and control design through implementation, evidence collection, audit readiness, and external assessment.
- Manage large, multi-month or multi-year compliance projects, ensuring milestones, dependencies, stakeholders, and deliverables remain on track.
- Work directly with auditors, government officials, and other external stakeholders across frameworks including NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related standards.
- Partner with security, IT, engineering, product, platform, and other teams to gather audit evidence and validate control effectiveness.
- Translate compliance and regulatory requirements into practical, implementable controls that balance security, privacy, compliance, and business innovation.
- Identify opportunities to harmonize controls and evidence across multiple frameworks, reducing duplication and improving the efficiency of the overall compliance program.
- Leverage AI and automation to improve compliance operations, including processes for policy management, evidence collection, knowledge dissemination, and control monitoring.
- Develop, maintain, and improve security, compliance, and privacy policies, procedures, plans, and supporting documentation.
- Represent the compliance function in customer-facing discussions, security questionnaires, due diligence processes, and other external assessments.
- Identify emerging compliance requirements and help determine how new frameworks or regulatory changes should be incorporated into existing governance processes.
- Collaborate with leadership to resolve complex compliance challenges and continuously improve the organization’s security and risk posture.
- Remain adaptable as the scope of the role evolves, taking on broader security, privacy, risk, or compliance responsibilities as organizational needs develop.
- 8+ years of experience working with multiple security, risk, and compliance frameworks, including both small and large-scale audits and complex implementation programs.
- Deep expertise in at least one major security or compliance framework, such as SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series standards.
- Demonstrated ability to lead compliance initiatives through changing requirements, complex implementations, and evolving technology environments.
- Practical experience with audit preparation, control implementation, evidence management, assessment activities, and auditor or regulator engagement.
- Exposure to additional frameworks and regulations such as GDPR, ITAR, EAR, NISPOM, CMMC, or similar requirements is highly valued.
- Strong understanding of security governance, risk management, control frameworks, compliance operations, and security/privacy principles.
- Excellent project management and organizational skills, with the ability to independently manage initiatives spanning multiple months, quarters, or years.
- Strong communication and stakeholder-management skills, with the ability to work effectively with technical teams, executives, auditors, government stakeholders, and customers.
- Ability to translate complex regulatory and compliance requirements into clear, actionable guidance for engineering and business teams.
- Strong analytical and problem-solving capabilities, with exceptional attention to detail and the ability to identify practical solutions to novel compliance challenges.
- Self-directed and comfortable operating with a high degree of autonomy in a fast-moving technology environment.
- Curiosity and willingness to use AI and automation to improve traditional compliance processes and enable scalable governance.
- Relevant certifications such as CISM, GSLC, Security+ CE, CISSP, or comparable credentials are advantageous.
- U.S. citizenship is required due to the nature of the work.
- Successful completion of a comprehensive background check is required as part of employment.
- Opportunity to work on complex, high-impact security and compliance challenges within a cloud-based technology environment.
- High-autonomy role with significant ownership over strategic, multi-framework compliance initiatives.
- Exposure to major frameworks and regulatory environments including FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, and NIST.
- Collaboration with security, engineering, product, platform, IT, audit, government, and customer stakeholders.
- Opportunity to apply AI and automation to modernize security governance and compliance operations.
- Supportive, collaborative, and mission-driven team environment.
- Opportunities to expand responsibilities across security, privacy, risk, and compliance as the organization evolves.
- Equal opportunity workplace committed to considering qualified candidates regardless of race, sex, disability, religion or belief, sexual orientation, or age.
Requirements:
Benefits:
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply