Principal Security GRC Analyst

Jobgether

United States

On-site

USD 150,000 - 210,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

High autonomy
Multi-framework exposure
Cloud environment experience

Job summary

Jobgether is seeking a Principal Security GRC Analyst in the United States to lead governance, risk, and compliance across FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001 and related standards in a cloud environment.

You will own complex compliance initiatives end-to-end, partner with security, IT, engineering, and product teams, and engage auditors and government stakeholders to drive practical, scalable controls with automation.

Qualifications

  • 8+ years across multiple security, risk and compliance programs and audits.
  • Lead compliance initiatives through evolving requirements and complex implementations.
  • Audits, evidence management, and regulator engagement experience.
  • Exposure to GDPR, ITAR, EAR, NISPOM, CMMC is highly valued.
  • US citizenship and ability to pass a background check.

Responsibilities

  • Drive maturity of a multi-framework GRC program across frameworks like FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001.
  • Own end-to-end compliance initiatives from requirements to evidence and audit readiness.
  • Collaborate with security, IT, product, engineering, and leadership to implement controls.
  • Engage auditors and government stakeholders and translate requirements into practical controls.
  • Leverage AI/automation to improve compliance operations and governance.

Skills

Governance
Risk management
Compliance frameworks
Audits
Stakeholder management
Automation/AI in compliance

Education

CISM
GSLC
Security+ CE
CISSP

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security GRC Analyst based in the United States.

This is a senior individual contributor role responsible for strengthening and scaling a complex security governance, risk, and compliance program within a cloud-based technology environment.
You'll take ownership of compliance initiatives from control design and implementation through evidence collection, audit preparation, and auditor engagement.
The role spans multiple frameworks, including FedRAMP Moderate, DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX, and related security requirements.
You'll collaborate closely with security, IT, engineering, product, platform, and other teams to translate regulatory expectations into practical controls.
The position offers significant autonomy and the opportunity to lead long-term, cross-functional compliance programs while improving automation and operational maturity.
You'll also interact with auditors, government stakeholders, customers, and internal leadership on high-impact security and compliance matters.
This is an ideal opportunity for an experienced GRC professional who enjoys solving complex problems, building scalable processes, and enabling innovation without compromising security or privacy.

Accountabilities:

  • Drive the continued maturity of a comprehensive security governance, risk, and compliance program across multiple regulatory and security frameworks.
  • Own complex compliance initiatives end-to-end, from requirements analysis and control design through implementation, evidence collection, audit readiness, and external assessment.
  • Manage large, multi-month or multi-year compliance projects, ensuring milestones, dependencies, stakeholders, and deliverables remain on track.
  • Work directly with auditors, government officials, and other external stakeholders across frameworks including NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related standards.
  • Partner with security, IT, engineering, product, platform, and other teams to gather audit evidence and validate control effectiveness.
  • Translate compliance and regulatory requirements into practical, implementable controls that balance security, privacy, compliance, and business innovation.
  • Identify opportunities to harmonize controls and evidence across multiple frameworks, reducing duplication and improving the efficiency of the overall compliance program.
  • Leverage AI and automation to improve compliance operations, including processes for policy management, evidence collection, knowledge dissemination, and control monitoring.
  • Develop, maintain, and improve security, compliance, and privacy policies, procedures, plans, and supporting documentation.
  • Represent the compliance function in customer-facing discussions, security questionnaires, due diligence processes, and other external assessments.
  • Identify emerging compliance requirements and help determine how new frameworks or regulatory changes should be incorporated into existing governance processes.
  • Collaborate with leadership to resolve complex compliance challenges and continuously improve the organization’s security and risk posture.
  • Remain adaptable as the scope of the role evolves, taking on broader security, privacy, risk, or compliance responsibilities as organizational needs develop.
Requirements:
  • 8+ years of experience working with multiple security, risk, and compliance frameworks, including both small and large-scale audits and complex implementation programs.
  • Deep expertise in at least one major security or compliance framework, such as SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series standards.
  • Demonstrated ability to lead compliance initiatives through changing requirements, complex implementations, and evolving technology environments.
  • Practical experience with audit preparation, control implementation, evidence management, assessment activities, and auditor or regulator engagement.
  • Exposure to additional frameworks and regulations such as GDPR, ITAR, EAR, NISPOM, CMMC, or similar requirements is highly valued.
  • Strong understanding of security governance, risk management, control frameworks, compliance operations, and security/privacy principles.
  • Excellent project management and organizational skills, with the ability to independently manage initiatives spanning multiple months, quarters, or years.
  • Strong communication and stakeholder-management skills, with the ability to work effectively with technical teams, executives, auditors, government stakeholders, and customers.
  • Ability to translate complex regulatory and compliance requirements into clear, actionable guidance for engineering and business teams.
  • Strong analytical and problem-solving capabilities, with exceptional attention to detail and the ability to identify practical solutions to novel compliance challenges.
  • Self-directed and comfortable operating with a high degree of autonomy in a fast-moving technology environment.
  • Curiosity and willingness to use AI and automation to improve traditional compliance processes and enable scalable governance.
  • Relevant certifications such as CISM, GSLC, Security+ CE, CISSP, or comparable credentials are advantageous.
  • U.S. citizenship is required due to the nature of the work.
  • Successful completion of a comprehensive background check is required as part of employment.
Benefits:
  • Opportunity to work on complex, high-impact security and compliance challenges within a cloud-based technology environment.
  • High-autonomy role with significant ownership over strategic, multi-framework compliance initiatives.
  • Exposure to major frameworks and regulatory environments including FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, and NIST.
  • Collaboration with security, engineering, product, platform, IT, audit, government, and customer stakeholders.
  • Opportunity to apply AI and automation to modernize security governance and compliance operations.
  • Supportive, collaborative, and mission-driven team environment.
  • Opportunities to expand responsibilities across security, privacy, risk, and compliance as the organization evolves.
  • Equal opportunity workplace committed to considering qualified candidates regardless of race, sex, disability, religion or belief, sexual orientation, or age.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Governance, Risk, & Compliance Analyst
Senior Governance, Risk, & Compliance Analyst

Jobgether • United States

On-site
USD 58,000 - 222,000
Medical, dental, vision insurance
Flexible work environment
Paid time off
+1
Lead Security Compliance Advisor (GRC)
Lead Security Compliance Advisor (GRC)

Frey Consulting Group • Columbus (OH)

Remote
USD 100,000 - 150,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Director, GRC & Privacy Security
Director, GRC & Privacy Security

Jobtailor • New York (NY)

On-site
USD 130,000 - 160,000
Competitive salary & equity
Unlimited PTO
Full Health, Vision, & Dental coverage
+2
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Principal Security GRC Analyst
Principal Security GRC Analyst

Rescale • United States

Remote
USD 150,000 - 230,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus