Principal GRC Architect - InfoSec & Enterprise Risk

Palo Alto Networks

Santa Clara (CA)

On-site

USD 168,000 - 271,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Palo Alto Networks is seeking a Principal InfoSec GRC Business Engineer to architect and mature Global Governance, Risk, and Compliance programs. You will bridge security engineering, enterprise risk, and business operations by designing frameworks and scalable risk assessment methodologies.

The role partners with stakeholders to craft security policies and standards, leveraging AI, automation, and policy-as-code for automated evidence collection.

Qualifications

  • 10+ years in Information Security or IT Risk with 6+ years in GRC in global environments.
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, MIS, or equivalent practical experience.
  • Active CISSP, CRISC, CISM, or CISA certification.
  • Deep knowledge of ISO 27001/2, NIST SP 800-53, NIST CSF, SOC 2 Type II, PCI-DSS, GDPR.
  • Proven track record of risk management processes with quantification and exec-level reporting.
  • Hands-on experience developing GRC requirements and partnering with automation teams.
  • Hands-on experience configuring GRC tools for workflows and in-app automations.
  • Experience across multi-cloud (AWS, Azure, GCP) and modern enterprise architecture.
  • Excellent communication and cross-functional influence.
  • Ability to navigate ambiguity and solve complex challenges.

Responsibilities

  • Design and scale the global GRC vision to align with enterprise goals and regulatory mandates.
  • Partner with senior leaders across IS, Legal, and Product Engineering to align risk tolerance with business objectives.
  • Lead drafting, maintenance, rollout, and annual review of information security policies, standards, procedures, and guidelines.
  • Translate complex regulatory and security frameworks into clear, actionable requirements.
  • Architect quantitative and qualitative risk assessment methodologies for cloud, SaaS, and hybrid environments.
  • Lead end-to-end security risk evaluations for critical applications and infrastructure.
  • Design executive risk reporting to provide visibility into risk posture and drive reduction.
  • Lead implementation, optimization, and continuous improvement of enterprise GRC platforms and tools.
  • Design test plans and policy-as-code for automated evidence collection and real-time control testing.
  • Redesign manual risk and compliance processes into scalable automated workflows.

Skills

GRC
Risk management
Policy drafting
Executive reporting
Multi-cloud
Communication
Ambiguity handling
CISSP
CRISC
CISM
CISA

Education

Bachelor's or Master's in CS/Cybersecurity/MIS

Tools

AWS
Azure
GCP
GRC platforms

Job description

Palo Alto Networks is seeking a Principal InfoSec GRC Business Engineer to architect and mature Global Governance, Risk, and Compliance programs. You will bridge security engineering, enterprise risk, and business operations by designing frameworks and scalable risk assessment methodologies.

The role partners with stakeholders to craft security policies and standards, leveraging AI, automation, and policy-as-code for automated evidence collection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Architect & Risk Strategy Leader
GRC Architect & Risk Strategy Leader

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 168,000 - 271,000
Senior GRC Architect: Policy, Risk & Automation
Senior GRC Architect: Policy, Risk & Automation

Palo Alto Networks • California (MO)

On-site
USD 168,000 - 271,000
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks • California (MO)

On-site
USD 168,000 - 271,000
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks • Santa Clara (CA)

On-site
USD 168,000 - 271,000
Principal GRC Business Engineer
Principal GRC Business Engineer

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 168,000 - 271,000
GRC Engineer: AI-Driven Security & Compliance Architect
GRC Engineer: AI-Driven Security & Compliance Architect

Webhosting • Austin (TX)

On-site
USD 140,000 - 210,000
Equity plan
Global Network Security Architect & Automation Leader
Global Network Security Architect & Automation Leader

Socket.dev • California (MO)

On-site
USD 154,000 - 250,000
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
Senior GRC Engineer: Cloud Security & Compliance
Senior GRC Engineer: Cloud Security & Compliance

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development
Security GRC Analyst — Risk, Policy & Audit
Security GRC Analyst — Risk, Policy & Audit

Pinterest • San Francisco (CA)

On-site
USD 124,000 - 255,000