GRC Principal - Data Privacy and Security
JobgetherRemotely
data governancegrcpci dssiso 27001gdprccpasoc 2dsar
Job Description
📋 Description
- Lead the end-to-end annual SOC 1 and SOC 2 Type II audit lifecycle, including control readiness
- Own and continuously evolve the Information Security Management System (ISMS), policies, and
- Develop and mature vendor and third-party risk management programs, including frameworks
- Lead customer assurance activities, including enterprise security reviews, customer and prospect
- Scale security and privacy documentation, processes, and mechanisms to support enterprise growth
- Build and evolve data governance practices across the complete data lifecycle, including
🎯 Requirements
- 10+ years of experience across GRC, information security, privacy, and compliance, with a proven
- Deep hands-on expertise with security frameworks and standards such as SOC 2, ISO 27001, and PCI
- Strong privacy compliance experience covering GDPR, CCPA, DSAR operations, data mapping, data
- Demonstrated ownership of SOC audit lifecycles, enterprise risk management, and third-party/vendor
- Proven ability to leverage AI to automate GRC workloads, improve operational efficiency, and
- Working knowledge of AI/ML governance and emerging regulatory requirements, with the ability to
🎁 Benefits
- Remote flexibility: Work from anywhere in Canada or the United States.
- Unlimited paid time off.
- Health and dental benefits.
- Up to CA$2,025 toward home IT setup.
- Up to 2% matching RRSP / 401(k) contributions.
- Learning and development opportunities.
Back to all jobs