REMOTEFULLTIME
Principal Security GRC Analyst
Jobgether
Remote · remote · Posted 1d ago
Your match
Sign in to see your match score, skill gaps & tailored resume.
Section · 01
About this role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security GRC Analyst based in the United States.
This is a senior individual contributor role responsible for strengthening and scaling a complex security governance, risk, and compliance program within a cloud-based technology environment. You’ll take ownership of compliance initiatives from control design and implementation through evidence collection, audit preparation, and auditor engagement. The role spans multiple frameworks, including FedRAMP Moderate, DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX, and related security requirements. You’ll collaborate closely with security, IT, engineering, product, platform, and other teams to translate regulatory expectations into practical controls. The position offers significant autonomy and the opportunity to lead long-term, cross-functional compliance programs while improving automation and operational maturity. You’ll also interact with auditors, government stakeholders, customers, and internal leadership on high-impact security and compliance matters. This is an ideal opportunity for an experienced GRC professional who enjoys solving complex problems, building scalable processes, and enabling innovation without compromising security or privacy.
Accountabilities:: Drive the continued maturity of a comprehensive security governance, risk, and compliance program across multiple regulatory and security frameworks.
Own complex compliance initiatives end-to-end, from requirements analysis and control design through implementation, evidence collection, audit readiness, and external assessment.
Manage large, multi-month or multi-year compliance projects, ensuring milestones, dependencies, stakeholders, and deliverables remain on track.
Work directly with auditors, government officials, and other external stakeholders across frameworks including NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related standards.
Partner with security, IT, engineering, product, platform, and other teams to gather audit evidence and validate control effectiveness.
Translate compliance and regulatory requirements into practical, implementable controls that balance security, privacy, compliance, and business innovation.
Identify opportunities to harmonize controls and evidence across multiple frameworks, reducing duplication and improving the efficiency of the overall compliance program.
Leverage AI and automation to improve compliance operations, including processes for policy management, evidence collection, knowledge dissemination, and control monitoring.
Develop, maintain, and improve security, compliance, and privacy policies, procedures, plans, and supporting documentation.
Represent the compliance function in customer-facing discussions, security questionnaires, due diligence processes, and other external assessments.
Identify emerging compliance requirements and help determine how new frameworks or regulatory changes should be incorporated into existing governance processes.
Collaborate with leadership to resolve complex compliance challenges and continuously improve the organization’s security and risk posture.
Remain adaptable as the scope of the role evolves, taking on broader security, privacy, risk, or compliance responsibilities as organizational needs develop.
Requirements:
8+ years of experience working with multiple security, risk, and compliance frameworks, including both small and large-scale audits and complex implementation programs.
Deep expertise in at least one major security or compliance framework, such as SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series standards.
Demonstrated ability to lead compliance initiatives through changing requirements, complex implementations, and evolving technology environments.
Practical experience with audit preparation, control implementation, evidence management, assessment activities, and auditor or regulator engagement.
Exposure to additional frameworks and regulations such as GDPR, ITAR, EAR, NISPOM, CMMC , or similar requirements is highly valued.
Strong understanding of security governance, risk management, control frameworks, compliance operations, and security/privacy principles.
Excellent project management and organizational skills, with the ability to independently manage initiatives spanning multiple months, quarters, or years.
Strong communication and stakeholder-management skills, with the ability to work effectively with technical teams, executives, auditors, government stakeholders, and customers.
Ability to translate complex regulatory and compliance requirements into clear, actionable guidance for engineering and business teams.
Strong analytical and problem-solving capabilities, with exceptional attention to detail and the ability to identify practical solutions to novel compliance challenges.
Self-directed and comfortable operating with a high degree of autonomy in a fast-moving technology environment.
Curiosity and willingness to use AI and automation to improve traditional compliance processes and enable scalable governance.
Relevant certifications such as CISM, GSLC, Security+ CE, CISSP , or comparable credentials are advantageous.
U.S. citizenship is required due to the nature of the work.
Successful completion of a comprehensive background check is required as part of employment.
Benefits:
Opportunity to work on complex, high-impact security and compliance challenges within a cloud-based technology environment.
High-autonomy role with significant ownership over strategic, multi-framework compliance initiatives.
Exposure to major frameworks and regulatory environments including FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, and NIST.
Collaboration with security, engineering, product, platform, IT, audit, government, and customer stakeholders.
Opportunity to apply AI and automation to modernize security governance and compliance operations.
Supportive, collaborative, and mission-driven team environment.
Opportunities to expand responsibilities across security, privacy, risk, and compliance as the organization evolves.
Equal opportunity workplace committed to considering qualified candidates regardless of race, sex, disability, religion or belief, sexual orientation, or age.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
Sourced from lever · view original
Let the agent run this one for you.
Tailored resume, auto-apply, and referral lookup — in under 2 minutes.
Section · 02
Skills
Section · Company
About Jobgether
Jobgether
About