Principal Security GRC Analyst
JobgetherNorth AmericaFull TimeOperations
Remotely
fedrampiso 27001gdprsoc 2itarearnispom
Job Description
📋 Description
- Drive the maturity of a security GRC program across multiple frameworks.
- Own end-to-end compliance initiatives from design to audit readiness.
- Manage large, multi-month or multi-year compliance projects.
- Interact with auditors and external stakeholders across frameworks.
- Partner with security, IT, engineering, product, and teams to gather evidence.
- Translate regulatory requirements into practical, implementable controls.
🎯 Requirements
- 8+ years with multiple security, risk, and compliance frameworks.
- Deep expertise in SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series.
- Proven ability to lead compliance initiatives and audits.
- Experience with audit prep, evidence management, and regulator engagement.
- Exposure to GDPR, ITAR, EAR, NISPOM, CMMC is highly valued.
- Strong governance, risk management, and security/privacy knowledge.
🎁 Benefits
- Work on complex, high-impact security and compliance in cloud environments.
- High-autonomy role with ownership of multi-framework initiatives.
- Exposure to FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, NIST.
- Collaborate with security, engineering, product, IT, audit, government, and customers.
- Opportunities to apply AI and automation to governance operations.
- Supportive, collaborative team environment; room to grow responsibilities.