Jobgether
Jobgether

Principal Security GRC Analyst

engineeringfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

Accountabilities:

    • Drive the continued maturity of a comprehensive security governance, risk, and compliance program across multiple regulatory and security frameworks.
    • Own complex compliance initiatives end-to-end, from requirements analysis and control design through implementation, evidence collection, audit readiness, and external assessment.
    • Manage large, multi-month or multi-year compliance projects, ensuring milestones, dependencies, stakeholders, and deliverables remain on track.
    • Work directly with auditors, government officials, and other external stakeholders across frameworks including NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related standards.
    • Partner with security, IT, engineering, product, platform, and other teams to gather audit evidence and validate control effectiveness.
    • Translate compliance and regulatory requirements into practical, implementable controls that balance security, privacy, compliance, and business innovation.
    • Identify opportunities to harmonize controls and evidence across multiple frameworks, reducing duplication and improving the efficiency of the overall compliance program.
    • Leverage AI and automation to improve compliance operations, including processes for policy management, evidence collection, knowledge dissemination, and control monitoring.
    • Develop, maintain, and improve security, compliance, and privacy policies, procedures, plans, and supporting documentation.
    • Represent the compliance function in customer-facing discussions, security questionnaires, due diligence processes, and other external assessments.
    • Identify emerging compliance requirements and help determine how new frameworks or regulatory changes should be incorporated into existing governance processes.
    • Collaborate with leadership to resolve complex compliance challenges and continuously improve the organization’s security and risk posture.
    • Remain adaptable as the scope of the role evolves, taking on broader security, privacy, risk, or compliance responsibilities as organizational needs develop.
    • Requirements:

      • 8+ years of experience working with multiple security, risk, and compliance frameworks, including both small and large-scale audits and complex implementation programs.
      • Deep expertise in at least one major security or compliance framework, such as SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series standards.
      • Demonstrated ability to lead compliance initiatives through changing requirements, complex implementations, and evolving technology environments.
      • Practical experience with audit preparation, control implementation, evidence management, assessment activities, and auditor or regulator engagement.
      • Exposure to additional frameworks and regulations such as GDPR, ITAR, EAR, NISPOM, CMMC, or similar requirements is highly valued.
      • Strong understanding of security governance, risk management, control frameworks, compliance operations, and security/privacy principles.
      • Excellent project management and organizational skills, with the ability to independently manage initiatives spanning multiple months, quarters, or years.
      • Strong communication and stakeholder-management skills, with the ability to work effectively with technical teams, executives, auditors, government stakeholders, and customers.
      • Ability to translate complex regulatory and compliance requirements into clear, actionable guidance for engineering and business teams.
      • Strong analytical and problem-solving capabilities, with exceptional attention to detail and the ability to identify practical solutions to novel compliance challenges.
      • Self-directed and comfortable operating with a high degree of autonomy in a fast-moving technology environment.
      • Curiosity and willingness to use AI and automation to improve traditional compliance processes and enable scalable governance.
      • Relevant certifications such as CISM, GSLC, Security+ CE, CISSP, or comparable credentials are advantageous.
      • U.S. citizenship is required due to the nature of the work.
      • Successful completion of a comprehensive background check is required as part of employment.
      • Benefits:

        • Opportunity to work on complex, high-impact security and compliance challenges within a cloud-based technology environment.
        • High-autonomy role with significant ownership over strategic, multi-framework compliance initiatives.
        • Exposure to major frameworks and regulatory environments including FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, and NIST.
        • Collaboration with security, engineering, product, platform, IT, audit, government, and customer stakeholders.
        • Opportunity to apply AI and automation to modernize security governance and compliance operations.
        • Supportive, collaborative, and mission-driven team environment.
        • Opportunities to expand responsibilities across security, privacy, risk, and compliance as the organization evolves.
        • Equal opportunity workplace committed to considering qualified candidates regardless of race, sex, disability, religion or belief, sexual orientation, or age.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now
Principal Security GRC Analyst at Jobgether — Remote