Principal, Cybersecurity & AI GRC

Panda Restaurant Group

Rosemead (CA)

Hybrid

USD 157,000 - 220,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid schedule
401K match
Yearly bonus
Medical, dental, and vision insurance
On-site fitness center and health tech

Job summary

Panda Restaurant Group is seeking a Principal, Cybersecurity & AI GRC to shape enterprise AI risk, privacy, and compliance strategy. You will define frameworks, advise leadership, and enable teams with practical guidance for compliant AI adoption.

Reporting to the Head of Cybersecurity and Risk, you will partner with Legal, Privacy, and engineering leads to align AI initiatives with Panda’s values and regulatory obligations. This is a senior advisory role with impact across the organization.

Qualifications

  • Bachelor’s degree in Computer Science, Business, or an IT-related discipline.
  • Minimum seven years of experience in GRC, privacy, security, enterprise risk, or technology enablement with increasing management responsibility.
  • Experience leading enterprise risk assessments, control design/testing, policy/standards development, AI governance program design.
  • AI governance frameworks such as NIST AI RMF, EU AI Act, ISO 42001.

Responsibilities

  • Defines and evolves enterprise AI enablement strategy, frameworks, and operating model; advises on AI risk and privacy posture.
  • Establishes policies and standards for responsible AI, privacy, data usage, transparency, and human oversight.
  • Integrates AI risk, privacy, and compliance into enterprise GRC and risk management processes.
  • Defines risk classification, approval workflows, and lifecycle governance for AI and digital capabilities.
  • Establish clear decision ownership, escalation models, and risk tolerance frameworks across the enterprise.
  • Leads enablement for high-risk AI, data, and digital initiatives with practical guidance.
  • Defines risk acceptance, exception handling, and escalation processes for AI and technology risk.
  • Partners with Legal and Privacy to operationalize regulatory requirements impacting AI and data.

Skills

GRC experience
AI governance
Risk assessments
Policy & standards

Education

Bachelor’s degree in CS/Business/IT

Job description

Summary Of Job Description

The Principal, Cybersecurity & AI GRC is a strategic advisor responsible for defining and sustaining enterprise-wide frameworks across AI risk, privacy, regulatory compliance, and technology and cyber risk. Reporting to the Head of Cybersecurity and Risk, this role establishes long-term direction, decision models, and guardrails that enable AI and data-driven innovation to align with Panda’s values, regulatory obligations, and business objectives. The role is a principal-level enablement, oversight, and influence role that ensures teams can make informed, consistent decisions while protecting guests, associates, and the brand. Principal responsibilities include enterprise AI enablement strategy and operating model, integrated GRC and privacy enablement, clear decision ownership, escalation, risk tolerance frameworks, and safe, compliant, and scalable AI adoption.

Job Responsibilities
  • Defines and evolves enterprise digital trust and AI enablement strategy, frameworks, and operating model and advises senior leadership on AI risk, privacy posture, and tradeoffs using business-relevant language.
  • Establishes policies and standards for responsible AI, privacy, data usage, transparency, and human oversight.
  • Integrates AI risk, privacy, and compliance into enterprise GRC and risk management processes.
  • Defines risk classification, approval workflows, and lifecycle governance for AI and digital capabilities.
  • Establish clear decision ownership, escalation models, and risk tolerance frameworks across the enterprise.
  • Leads enablement for high-risk, high-impact AI, data, and digital initiatives. Enables Product, Engineering, Analytics, and Business teams with clear, practical, and actionable guidance.
  • Defines and manages risk acceptance, exception handling, and escalation processes for AI and technology risk.
  • Partners with Legal and Privacy to operationalize regulatory requirements impacting AI, data, and automation.
  • Influences platform, vendor, and tooling strategy related to AI capabilities and embedded AI features.
  • Represents digital trust, AI, and privacy enablement in enterprise architecture, risk, and investment forums.
Benefits
  • Hybrid Work schedule
  • 401K with company match
  • Yearly bonus opportunity*
  • Full medical, dental, and vision insurance *
  • On-site fitness center, biometric screen, and flu shot clinic
  • Discounts at Panda restaurants, theme parks, and gym memberships
  • Paid time off starting at 15 days with 7 federal holidays*
  • Continuous education assistance and scholarships*
  • Income protection including Disability, Life and AD&D insurance*
  • Bereavement leave*
  • Benefits available for eligible permanent full time associates
Your Background & Experience
  • Bachelor’s degree in Computer Science, Business, or an IT-related discipline.
  • Minimum seven years of experience in GRC, privacy, security, enterprise risk, or technology enablement with increasing management responsibility; experience performing or leading enterprise or security risk assessments, control design/testing, policy and standards development, TPRM programs, compliance/regulatory readiness programs, AI governance program design and implementation, and AI governance and compliance frameworks (NIST AI RMF, EU AI Act, ISO 42001), including AI risk classification, algorithmic impact assessments, responsible AI principles, and practical application within enterprise or client-facing advisory engagements.
  • Demonstrated expertise implementing and operationalizing cybersecurity frameworks and control programs: NIST CSF / NIST 800-53, ISO 27001/27002, CIS, NIST AI RMF, ISO 42001.
  • Successful completion of initial and periodically required trainings.
  • Obtaining a valid Food Handler’s Card within 30 days of employment is a requirement of this position.

Pay Range: M3H: $157,000 - $220,000 / Annual

Pay is determined within the range using factors such as work location and experience.

Panda Restaurant Group, Inc. is an Equal Opportunity Employer and is committed to providing equal opportunity, and does not discriminate on the basis of any characteristic protected by law, including but not limited to sex/gender (including pregnancy, childbirth, lactation and related conditions), gender expression, race, color, religion, national origin, sexual orientation, gender identity, disability, age, ancestry, medical condition, genetic information, marital status, and veteran status. Additionally, Panda Restaurant Group, Inc. complies with all federal, state, and local laws regarding requests for workplace accommodation. The Americans with Disabilities Act (ADA) prohibits discrimination against qualified individuals on the basis of disability. Applicants are entitled to reasonable accommodations, absent undue hardship, to effectively participate in the application and hiring process, for example, sign language interpreters. If you believe you require an accommodation for the application or interview process or for the position for which you are applying, please reach out to TASupport@PandaRG.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Risk Governance and PMO
Senior Manager, Risk Governance and PMO

Panda Restaurant Group • Rosemead (CA)

Hybrid
USD 127,000 - 178,000
Hybrid schedule
401K match
Yearly bonus
+8
Senior Manager, Guest Care (Community Management)
Senior Manager, Guest Care (Community Management)

Panda Restaurant Group • Rosemead (CA)

Hybrid
USD 127,000 - 178,000
Hybrid work schedule
401K with company match
Yearly bonus opportunity
+4
Senior Cloud Solutions Architect
Senior Cloud Solutions Architect

Panda Restaurant Group Inc • Rosemead (CA)

Hybrid
USD 124,000 - 176,000
Hybrid Work schedule
401K with company match
Yearly bonus opportunity
+4
Senior Facilities Analyst
Senior Facilities Analyst

Panda Restaurant Group • Rosemead (CA)

Hybrid
USD 90,000 - 127,000
Hybrid work schedule
401K with company match
Yearly bonus
+2
Senior Manager, Risk Governance and PMO
Senior Manager, Risk Governance and PMO

Panda Restaurant Group Inc • Rosemead (CA)

Hybrid
USD 127,000 - 178,000
Hybrid Work schedule
Yearly bonus opportunity
Full medical, dental, and vision
+2
Senior Manager, Program Management Office (International & Licensing)
Senior Manager, Program Management Office (International & Licensing)

Panda Restaurant Group • Rosemead (CA)

Hybrid
USD 127,000 - 178,000
Hybrid Work Schedule
401K with company match
Yearly bonus opportunity
+3
Human Resources Associate Manager (Support Center)
Human Resources Associate Manager (Support Center)

Panda Restaurant Group Inc • Rosemead (CA)

Hybrid
USD 90,000 - 127,000
Hybrid Work schedule
401K with company match
Yearly bonus
+7
Senior Technical Support Trainer
Senior Technical Support Trainer

Panda Restaurant Group Inc • Rosemead (CA)

Hybrid
USD 90,000 - 127,000
Hybrid Work schedule
401K with company match
Yearly bonus
+7
Workday Talent Program Manager
Workday Talent Program Manager

Panda Restaurant Group • Rosemead (CA)

Hybrid
USD 113,000 - 158,000
Hybrid Work schedule
401K with company match
Yearly bonus opportunity
+2
Senior Facilities Analyst
Senior Facilities Analyst

Panda Restaurant Group Inc • Rosemead (CA)

Hybrid
USD 90,000 - 127,000
Hybrid Work schedule
401K with company match
Yearly bonus opportunity
+7