GRC Principal - Data Privacy and Security

Wrapbook

Canada (KY)

On-site

USD 180,000 - 260,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Unlimited Paid Time Off
Work from anywhere in USA and Canada
Health and Dental benefits
IT set up allowance
RRSP / 401K matching
Learning and Development opportunities
Internet/Cell phone stipend

Job summary

Wrapbook, the AI platform for production finance, seeks a Principal GRC Manager (Individual Contributor) to lead privacy and security GRC programs. This role blends strategic direction with hands-on delivery, focusing on SOC, ISO, GDPR/CCPA, and data governance within an AI-driven fintech/SaaS context.

You will own audits, build scalable controls, mentor teams, and partner with Legal and Security to advance enterprise risk management while ensuring audit-ready maturity.

Qualifications

  • 10+ years in GRC and information security with a track record of building scalable programs.
  • Integrity and discretion; customer trust is paramount.
  • Strong project management, reporting, and cross-functional coordination.
  • Experience leveraging AI to automate GRC workload and drive outcomes.
  • Expertise across SOC 2, ISO 27001, PCI DSS, GDPR, and CCPA.

Responsibilities

  • Lead the SOC 1 and 2 audit lifecycle end-to-end with evidence collection and accountability.
  • Own ISMS policy suite and SOC/ISO framework development with legal and security teams.
  • Mature vendor risk management program with metrics and governance.
  • Lead enterprise security reviews and scale privacy/documentation for customers.

Skills

GRC leadership
Security governance
Privacy compliance
AI governance
Project management
Cross-functional leadership
SOC 2 / ISO 27001 / PCI DSS
GDPR / CCPA / DSAR
Audits & risk programs
Security/Privacy certifications

Job description

About Us:

Wrapbook is the AI platform for production finance. We’re building a system of action that puts finance teams in control of their whole production, from payroll, to spend, to accounting.

Built for feature films, TV, and commercials, Wrapbook is trusted by teams at Netflix, Paramount, Anonymous Content, and more. With backing from Andreessen Horowitz, Bessemer Venture Partners, and Jeffrey Katzenberg's WndrCo, our team of 350+ is using AI to transform how finance teams work and empower them to do more with less.

The Opportunity – GRC Principal - Data Privacy and Security (Remote - USA / CANADA):

We're hiring a Principal GRC Manager (Individual Contributor) to serve as a subject matter expert and technical authority leading Wrapbook's privacy and security GRC programs. This is a high-ambiguity, high-autonomy role for someone who has built and matured GRC programs at a fintech or SaaS company from the ground up. This person will not just maintain grc activities, but bring a strong point of view to set the multi-year direction for how Wrapbook manages GRC investment on the security and privacy front as our AI capabilities expand. This person is both excited to drive the strategic direction and own the ground-level execution across their areas, leveraging AI to amplify their output. You understand the difference between checking boxes and high judgment decisions, you focus on outcomes over activity. You cleanly separate the must-dos and the nice-to-haves informed by a business’ risk appetite, industry context, and overall company objectives.

You have a proven track record of building AI-first solutions for traditional GRC problems; you have the expertise and experience to validate AI outputs. You thrive on systems-thinking and delivering measurable results with rigor; you’ll own the project management, frameworks, measurement, outward and upward reporting, influence executives and leaders. You’ll evolve a program that passes SOC 1 and SOC 2 Type II audits, moving it from "successful audits" to durable, continuously audit-ready operational maturity. You are a bridge-builder, you know how to develop, grow, and leverage strong relationships and trust with cross-functional stakeholders and leadership.

What You'll Do:
Data Security GRC
  • Lead the annual SOC 1 and 2 audit lifecycle end-to-end: control monitoring/readiness, work with our SOC auditors and internal business teams to complete the audit project and reporting supporting evidence collection and clarification process, drive control-owner accountability and lead program development to embed continuous, evidence-driven controls.

  • Own and evolve Wrapbook's ISMS policy suite and control framework (SOC 1, SOC 2 Type II; explore additional ISO compliance opportunities) in collaboration with our Business, Legal, and Security teams.

  • Mature our approach to vendor risk management, developing and evolving the program, frameworks, prioritization, stakeholder management, and measurement.

  • Lead Customer Assurance efforts for enterprise security reviews (e.g., enterprise customer and prospect review requirements, cyber-insurance self-assessments) and scale Wrapbook's security and privacy documentation and mechanisms.

Data Privacy GRC
  • Collaborate with Legal and Security teams to build and evolve Wrapbook’s Data Governance program across the data lifecycle (data collection, storage, access, retention, deletion).

  • Beyond project management you will make recommendations and own decisions on how to best solve Wrapbook’s dynamic and growing data governance challenges.

  • Build and evolve the privacy compliance program across GDPR and CCPA — DSAR operations, data mapping, retention, and the data governance and classification program.

  • Partner with Legal on DPAs, subprocessor obligations, and privacy-by-design in product.

  • Help shape Wrapbook's enterprise AI data governance framework in collaboration with our Security and Legal leadership/org— policies, standards, and controls across the AI/ML lifecycle for both internally built and procured AI.

  • Track the evolving regulatory and framework landscape (e.g., NIST AI RMF, ISO 42001, EU AI Act) and translate it into Wrapbook’s needs.

Cross-functional leadership
  • Executive fluency and credibility. Translates technical and regulatory risk into business terms leadership can act on, and holds their own in front of executives, auditors, and enterprise customers. Trusted to represent Wrapbook's risk posture externally.

  • Serve as the subject-matter authority and trusted advisor on Security and Privacy governance and compliance topics.

  • Mentor cross-functional partners and team members and set the standard for the discipline across the org.

What We're Looking For:
  • 10+ years in GRC, information security and privacy compliance with a track record of building, scaling, and operating highly rigorous programs — ideally at a fintech, start-up, or payments organization.

  • You have the highest integrity and discretion. ****Customer trust is paramount at Wrapbook and this role will interact with highly sensitive data, owning difficult risk trade-offs with sound ethics and confidentiality.

  • Project management is second nature, you effectively establish, track, measure and communicate/report out on cross-functional program progress, prioritization decisions/trade-offs, risks, and impact.

  • Proven experience leveraging AI to automate GRC workload and force-multiply GRC programs to measurable outcomes.

  • Deep, hands-on expertise across security (SOC 2 / ISO 27001 / PCI DSS), privacy (GDPR / CCPA, DSAR operations, data governance) compliance.

  • Working fluency in AI/ML governance and the current regulatory landscape. You are comfortable with setting policy where standards are still forming.

  • Demonstrated ownership of SOC audit lifecycles and enterprise risk and third-party risk programs.

  • Exceptional cross-functional influence — able to move executives and technical teams without direct authority.

  • Relevant certifications a plus: CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP.

Why Join Us

At Wrapbook, creativity meets technology — and not just in the product.

In addition to a competitive salary and all the benefits you can expect from a fast-growing technology company, you’ll get access to a team of creative problem solvers and the chance to see your contributions make large impacts. Benefits include:

  • Unlimited Paid Time Off

  • Work from anywhere in Canada and USA

  • Health and Dental benefits

  • Up to $1,500 USD/ $2,025 CAD towards IT set up for your home

  • Up to 2% matching RRSP / 401K

  • Learning and Development opportunities

  • Up to $50 USD/ $67.50 CAD towards Internet/Cell phone service

Our Pledge to Fostering an Inclusive and Safe Workplace:

Wrapbook pledges to be a harassment- and discrimination-free space for everyone, regardless of age, disability, ethnicity, gender identity or expression, nationality, neurotype, personal appearance, political affiliation, professional background, race, religion, or sexual identity or orientation.

#LI-Remote

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Executive Assistant - Engineering, Product, Design, and Legal
Senior Executive Assistant - Engineering, Product, Design, and Legal

Wrapbook • United States

Remote
USD 90,000 - 150,000
Unlimited Paid Time Off
Work from anywhere in US/Canada
Health and Dental benefits
+4
Senior Product Designer II
Senior Product Designer II

Wrapbook • Canada (KY)

Hybrid
USD 120,000 - 170,000
Unlimited PTO
Remote work USA/Canada
Health & Dental benefits
+4
GRC Principal, Data Privacy & Security (Remote)
GRC Principal, Data Privacy & Security (Remote)

Wrapbook • Canada (KY)

Hybrid
USD 180,000 - 260,000
Unlimited Paid Time Off
Work from anywhere in USA and Canada
Health and Dental benefits
+4
Principal GRC Lead: Privacy, Security & AI Governance
Principal GRC Lead: Privacy, Security & AI Governance

Wrapbook • United States

On-site
USD 150,000 - 210,000
401K & RRSP
Home IT Setup
Remote work
+5
GRC Manager
GRC Manager

Valence • United States

Hybrid
USD 130,000 - 190,000
WFH stipend
Phone stipend
Workspace support
Consultant - Senior Privacy Analyst
Consultant - Senior Privacy Analyst

Talanto • Seattle (WA), Northern (KY)

Hybrid
USD 105,000 - 135,000
Medical, dental, vision
Education stipend
401(k) and life insurance
+4
GRC Engineer
GRC Engineer

Talanto • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Paid holidays
Parental leave
Senior Technical Architect (GRC)
Senior Technical Architect (GRC)

OneTrust • Madrid (IA)

Hybrid
USD 130,000 - 190,000
Healthcare coverage
Flexible PTO
Equity RSUs
+3
GRC (Governance, Risk, and Compliance) Analyst
GRC (Governance, Risk, and Compliance) Analyst

Yipitdatajobs • United States

Remote
USD 92,000 - 113,000
Flexible work hours
Flexible vacation
401K match
+4
Risk and Compliance Lead
Risk and Compliance Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10