Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal, GRC Automation and Cyber Risk

F5 Networks Inc

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.The Principal, GRC Automation & Cyber Risk Quantification is a senior engineering and strategic leadership role responsible for designing, implementing, and scaling automated, data-driven cyber risk and GRC capabilities across the enterprise. This role blends deep cyber risk management expertise with hands-on software engineering, GRC platform architecture, workflow automation, API development and systems integration, and emerging AI-enabled and Agentic capabilities to modernize how the organization manages risk, compliance, and governance at scale.Reporting to the VP, Cyber Governance, Risk & Compliance, this role serves as a force multiplier for the GRC organization, translating complex regulatory and risk frameworks into automated controls, continuous monitoring workflows, decision-ready dashboards, and audit-ready evidence. The principal is expected to write, review, and own production-quality code and partner closely with ERM, Engineering, IT, Legal, Privacy, Internal Audit, and Digital teams to embed risk intelligence directly into business and technology processes.Key ObjectivesShift GRC from manual, point-in-time assessments to continuous, automated, and risk-informed execution by leveraging purpose-built engineering solutions, Python-based tooling, and Agentic workflows.Enable executive and board-ready cyber risk insights grounded in quantitative and business-relevant data, supported by automated data pipelines and integrations.Standardize and automate control mapping, testing, evidence collection, and risk reporting across frameworks and regulators through scalable API-driven architectures.Act as the technical and architectural authority for ServiceNow IRM and adjacent GRC automation capabilities, including custom-developed integrations and Agentic automation agents.Primary Responsibilities1. GRC Automation & Platform ArchitectureDesign, build, and evolve end-to-end GRC automation across risk, compliance, policy, and issue management domains — including writing and maintaining Python-based automation scripts, services, and tools.Integrate GRC workflows with source systems (cloud platforms, vulnerability tools, IAM, SDLC, third-party systems) via RESTful APIs, webhooks, and event-driven integration patterns to reduce manual effort and improve data quality.Architect and maintain a systems integration layer connecting GRC platforms to enterprise data sources, enabling real-time risk signal ingestion and automated control validation.2. Cyber Risk Quantification & Decision EnablementPartner with Cyber Risk leadership to operationalize quantitative and scenario-based risk analysis (e.g., FAIR-aligned methods).Engineer automated pipelines for ingesting threat, vulnerability, asset, and business context data to support risk-based prioritization, leveraging Python data processing libraries (e.g., pandas, NumPy) integration APIs, and Agentic work flows.Enable financially grounded cyber risk outputs that inform:Risk acceptance and investment decisionsExecutive and board-level reportingProgram prioritization and roadmap planning3. Compliance Automation & Continuous MonitoringTranslate regulatory and framework requirements into automated, testable, and traceable controls, implementing these as code-driven workflows and API-integrated monitoring checks.Implement continuous control monitoring and evidence refresh to support ISO, SOX, SOC, and regulatory audits, using automated evidence collection scripts and scheduled integrations.Reduce audit fatigue by standardizing artifacts, workflows, and control narratives across compliance programs.Partner with Internal Audit and external auditors to improve transparency, timeliness, and defensibility of GRC outputs.4. AI-Enabled GRC & Agentic DevelopmentDesign, build, and deploy Agentic automation solutions — autonomous AI-driven agents capable of reasoning across GRC data, identifying risks, triggering workflows, and recommending actions with minimal human intervention.Identify and pilot AI-assisted capabilities to accelerate GRC outcomes, such as:Control mapping and gap analysisRisk scenario generation and prioritizationPolicy-to-control alignment and impact analysisAgentic issue triage, intelligent remediation recommendations, and autonomous evidence collectionDevelop and integrate LLM-based or agent-framework tooling (e.g., LangChain, AutoGen, or comparable frameworks) into GRC workflows.Ensure all AI-enabled and Agentic GRC use cases align with internal security, privacy, and governance standards.5. API and Systems IntegrationDesign, develop, and maintain RESTful and GraphQL APIs that expose GRC data and capabilities to downstream consumers including dashboards, reporting tools, and integrated enterprise systems.Own the end-to-end systems integration architecture connecting GRC platforms to security tools, cloud environments, HR systems, asset management, and third-party risk platforms.Establish and enforce API governance standards, including versioning, authentication, documentation (OpenAPI/Swagger), and rate management.Build and maintain integration middleware, ETL pipelines, and event-driven connectors to ensure consistent, reliable data flows across GRC systems.6. Stakeholder Partnership & InfluenceServe as a trusted advisor to security, IT, engineering, and business leaders on risk-based automation, control design, and engineering best practices for GRC tooling.Influence teams to embed GRC requirements directly into SDLC, cloud, procurement, and third-party workflows.Translate technical implementations — including architecture diagrams, API designs, and automation logic — into clear, executive-ready narratives for leadership consumption.Knowledge, Skills & AbilitiesKnowledgeDeep understanding of cyber risk management and GRC frameworks (NIST CSF, NIST 800-53/171, ISO 27001, SOC 2, SOX).Strong grasp of enterprise risk management (ERM) concepts and alignment.Working knowledge of quantitative cyber risk analysis (FAIR or similar approaches).Familiarity with audit, regulatory, and certification processes.Understanding of software engineering principles, API design patterns, and systems integration methodologies.Knowledge of Agentic AI frameworks and multi-agent system design principles.SkillsExpertise designing and automating workflows within ServiceNow IRM or comparable GRC platforms.Proficient Python developer — able to write clean, maintainable, production-ready code for automation scripts, data pipelines, API clients, and Agentic workflows.Experienced in API development and integration — designing and consuming REST APIs, managing authentication (OAuth, API keys), and building integration layers.Demonstrated systems integration experience — connecting heterogeneous enterprise systems through APIs, webhooks, message queues, or ETL frameworks.Hands-on experience with Agentic development — building autonomous AI agents using frameworks.Ability to translate abstract frameworks into practical, automated, and scalable implementations.Strong systems thinking, connecting people, process, technology, and data.Excellent written and verbal communication skills, including executive-level storytelling.AbilitiesOperate comfortably at both strategic and hands-on engineering levels.Influence without authority in a highly matrixed environment.Drive change from legacy/manual processes to modern, code-driven automated execution.Independently scope, build, and ship engineering solutions with minimal oversight.QualificationsRequiredBachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, Risk Management, or related field.10+ years of experience across cybersecurity, risk management, GRC, or security architecture roles — with at least 3–5 years in a hands-on engineering or software development capacity.Demonstrated Python programming proficiency applied to automation, data processing, tooling, or security use cases.Proven API development and integration experience, including designing, building, and consuming APIs in enterprise environments.Demonstrated systems integration experience, connecting GRC, security, cloud, or enterprise systems at scale.Demonstrated experience automating or scaling GRC, risk, or compliance programs using enterprise platforms.Strong experience partnering with cross-functional technical and business teams.PreferredMaster's degree in a related field.Experience with FAIR or quantitative risk methods.Hands-on experience with Agentic AI development — building and deploying autonomous agents for task automation, decision support, or workflow orchestration.Familiarity with LLM orchestration frameworks (LangChain, LangGraph, AutoGen, CrewAI, or similar).Experience with Python data and automation libraries (pandas, NumPy, FastAPI, Celery, Airflow, etc.).Experience with API gateway tooling, integration platforms (e.g., MuleSoft, Boomi, Workato), or message broker systems (Kafka, RabbitMQ).Hands-on experience with AI, data analytics, or workflow automation applied to GRC use cases.Professional certifications (CISSP, CISM, CRISC, Open FAIR).Why This Role MattersThis role is foundational to advancing the organization's GRC maturity by reducing friction, increasing signal, and enabling leadership to make faster, better-informed risk decisions. It is a highly visible engineering leadership position with direct impact on executive confidence, audit outcomes, and enterprise risk posture. The ideal candidate is equally comfortable writing Python code and building Agentic workflows as they are presenting risk insights to a board of directors — a rare blend of engineering depth and strategic influence that will define the next generation of GRC capability.The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.The annual base pay for this position is: $167,200.00 - $250,800.00F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: . F5 reserves the right to change or terminate any benefit plan without notice. Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com View email address on click.appcast.io).Equal Employment OpportunityIt is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting View email address on click.appcast.io: Seattle; San JoseType: Full time

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Principal, GRC Automation and Cyber Risk in San Jose, CA vacancy
  • $151k - $208k

     ...shared success where your work truly matters.Job SummaryAs a Principal Consultant for Proactive Services, you will be a key leader in...  ...domains including AI Security, Zero Trust, Cloud Security, and Cyber Risk Management. You will leverage a variety of advanced tools and... 
    Cyber
    Principal
    Risk
    Full time
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Santa Clara, CA
    4 days ago
  • $162.7k - $263.18k

     ...security services.Develop internal tools to monitor and support the cyber security products.Cross-team collaboration, discover and...  ...175.00/yrOur Commitment We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t... 
    Cyber
    Principal
    Risk
    Full time
    Work at office

    Palo Alto Networks

    Santa Clara, CA
    4 days ago
  • $240k - $379.5k

     ...workflows safely and reliably.We are seeking a Principal Engineer to help define and build core...  ...and building backend services, APIs, automation, or platform components in programming...  ...systems.Familiarity with AI-specific security risks such as prompt injection, tool misuse,... 
    Cyber
    Principal
    Risk
    Full time

    Nvidia

    Santa Clara, CA
    2 days ago
  • $188k - $304.08k

     ...matters.Job SummaryWe are seeking a Senior Principal Threat Researcher for our Unit 42 Threat...  ...and internal messaging around global cyber events.Work closely with the external engagement...  ...We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo... 
    Cyber
    Principal
    Risk
    Full time
    Remote work

    Palo Alto Networks

    Santa Clara, CA
    5 days ago
  •  ...matters.Job SummaryPrincipal ArchitectAs a Principal Architect you will serve as a trusted...  ...insights and education to clients on effective risk reduction, operational excellence, and...  ...(e.g., security technologies, cyber threat intelligence, risk and regulatory... 
    Cyber
    Principal
    Risk
    Full time
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Santa Clara, CA
    1 day ago
  • $272k - $431.25k

     ...Principal Systems Software Engineer at NVIDIA is an engineering discipline to design, build...  ...on eliminating manual work through automation, performance tuning and growing efficiency...  ...them to collaborate, think big and take risks in a blame-free environment. We promote... 
    Principal
    Risk
    Full time

    Nvidia

    Santa Clara, CA
    2 days ago
  •  ...AREBalbix is the world's leading platform for cybersecurity posture automation company. The Balbix Security Cloud uses AI and automation to reinvent how the World's leading organizations reduce their cyber risk. With Balbix, security teams can accurately inventory their... 
    Cyber
    Risk
    Full time
    Work at office
    Flexible hours

    Balbix

    San Jose, CA
    5 days ago
  • $91.1k - $187k

     ...defining coverage to address integration complexity and technical risks. Oversees test environment setup across teams, adapts...  ...infrastructure, advises on build vs. buy decisions, and develops reusable automation solutions integrated into Continuous Integration/Continuous... 
    Principal
    Risk
    Temporary work
    Local area
    Flexible hours
    Shift work

    Oracle Corporation

    Santa Clara, CA
    3 days ago
  • $162.7k - $263.18k

     ...great outcomes.Job SummaryYour CareerAs a Principal Security Researcher, you will work at...  ..., exploitability analysis, and security automation to build reliable workflows for vulnerability...  ...We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status... 
    Principal
    Risk
    Full time
    Work at office

    Palo Alto Networks

    Santa Clara, CA
    7 hours ago
  • $239k - $278.75k

     ...work truly matters. Job Summary As a Principal Architect you will serve as a trusted...  ...insights and education to clients on effective risk reduction, operational excellence, and...  ...(e.g., security technologies, cyber threat intelligence, risk and regulatory... 
    Cyber
    Principal
    Risk
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Santa Clara, CA
    2 days ago
  • $193.7k - $262k

     ...Procurement team is looking for an experienced, Principal Technical Sourcing Manager to be part of...  ...strategies to reduce cost, minimize risk, protect continuity of supply, and...  ...and technical product/program managers (Automation/Tools) who manage the broad base of networking... 
    Principal
    Risk
    Local area
    Immediate start
    Worldwide
    Flexible hours

    Amazon

    Cupertino, CA
    3 days ago
  •  ...0 Categories Enterprise Software Risk Management Security Information Technology...  ...Vulnerability Management Analytics Cyber Security Network Security Security...  ...programs application testing automation analytics intrusion detection and... 
    Cyber
    Risk

    Confidential

    San Jose, CA
    1 day ago
  • $164.22k - $225.8k

     ...reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers....  ...opportunities.Communicate customer priorities, opportunities, risks, and support requirements effectively within ADI.Contribute to... 
    Principal
    Risk
    Permanent employment
    Full time
    Work at office
    Day shift

    Analog Devices

    San Jose, CA
    4 days ago
  • $164.22k - $225.8k

     ...the world, and help drive advancements in automation and robotics, mobility, healthcare,...  ...Learn more at and on LinkedIn and X.As a Principal Account Manager focused on you will lead...  ...internal stakeholders on program status, risks, and growth strategies.Required Qualifications... 
    Principal
    Risk
    Permanent employment
    Full time
    Work at office
    Day shift

    Analog Devices

    San Jose, CA
    5 days ago
  •  ...SummaryWe are seeking a visionary Senior Principal Software Engineer / Technical Staff...  ...next-generation test infrastructure, CI/CD automation, and developer platforms. In this role,...  ...thrives on taking calculated technical risks to drive massive enterprise efficiencies... 
    Principal
    Risk
    Temporary work
    For contractors
    Work at office
    Local area
    Worldwide
    Shift work

    Celestica

    San Jose, CA
    3 days ago
  •  ...Data Scientist TENEX is an AI-native, automation-first, built-for-scale Managed Detection...  ...substantial round – joining now comes with limited risk and unlimited upside. We are expanding...  ...to tackle emerging and sophisticated cyber threats. Design and implement A/B... 
    Cyber
    Risk
    Work at office

    TenEx

    San Jose, CA
    4 days ago
  • $114.6k - $234.6k

    Oracle Cloud Infrastructure (OCI) is seeking a highly motivated Principal Data Automation Engineer to help accelerate the digital transformation of...  ...alerting mechanisms that proactively identify operational risks, exceptions, and bottlenecks.Build predictive models... 
    Principal
    Risk
    Temporary work
    Flexible hours

    Oracle Corporation

    Santa Clara, CA
    4 days ago
  •  ...security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto...  ...growth. Apply AI Native by leveraging AI-powered tools and automation to improve prospecting, account planning, customer engagement,... 
    Cyber
    Risk
    Apprenticeship
    Local area
    Remote work
    Shift work

    GrabJobs

    San Jose, CA
    2 days ago
  • $164k

     ...and operationally focused Supply Chain Planning Principal Data Analyst to lead the development, execution, and automation of complex business scenarios that support...  ...sourcing, and product roadmap scenarios. Analyze risks, opportunities, constraints, and sensitivities... 
    Principal
    Risk
    Temporary work
    Immediate start
    Remote work
    Flexible hours
    Shift work

    Western Digital

    San Jose, CA
    2 days ago
  • $117.5k - $176.3k

     ...Our differentiated battle management and cyber solutions deliver timely, mission-enabling...  ...for you to join our team as a Senior Principal Program Cost Control Analyst based out of...  ...(WBS) development, budget baseline, cost risk analysis/ assessment and visibility reports... 
    Cyber
    Principal
    Risk
    Full time
    Contract work
    Relocation package
    Shift work

    Northrop Grumman

    Sunnyvale, CA
    3 days ago
  • $117.5k - $176.3k

     ...Our differentiated battle management and cyber solutions deliver timely, mission-enabling...  ...for you to join our team as a Senior Principal Contract Administrator supporting the Marine...  ...and conditions to address provisions and risks of financial terms, acceptance criteria,... 
    Cyber
    Principal
    Risk
    Full time
    Contract work
    Relocation
    Shift work

    Northrop Grumman

    Sunnyvale, CA
    3 days ago
  • $160k - $220k

     ...an experienced and innovative Principal AI Security Engineer to join...  ...checks into CI/CD workflows to automate security testing and ensure...  ...TOP 10 and OWASP LLM Top 10 risks.Strong understanding of common...  ...degree in Computer Science, Cyber Security, other tech-related... 
    Cyber
    Principal
    Risk
    Full time
    Work experience placement
    Worldwide

    Fortinet

    Sunnyvale, CA
    5 days ago
  • $240k - $265k

     ...cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship...  ...SummaryHarness is looking for a Principal / Director of Product Management to lead...  ...organizations identify, prioritize, and remediate risks across both human-written and AI-... 
    Principal
    Risk
    Work at office
    Local area
    Immediate start
    Flexible hours
    Shift work

    Harness

    Mountain View, CA
    2 days ago
  • $165.6k - $296.4k

     ...learn faster with higher confidence. As a Principal Growth Engineer in CoreAI, you’ll drive...  ..., analysis workflows, and rollout automation that improve reliability and decision quality...  ...assignment/targeting, feature flighting, and risk controls (kill‑switches, guardrails,... 
    Principal
    Risk
    Ongoing contract
    Local area
    3 days per week

    Microsoft

    Mountain View, CA
    1 day ago
  • $117.5k - $176.3k

     ...Our differentiated battle management and cyber solutions deliver timely, mission-enabling...  ...for you to join our team as a Senior Principal Contract Administrator supporting the Marine...  ...and conditions to address provisions and risks of financial terms, acceptance criteria,... 
    Cyber
    Principal
    Risk
    Contract work
    Relocation
    Shift work

    Northrop Grumman

    Sunnyvale, CA
    5 days ago
  • $183k - $276k

     ...will work across product, partnerships, risk, legal, compliance, security, and engineering...  ...capabilities in artificial intelligence, automation, software platforms, application...  .... Fraudulent job postings may be used by cyber criminals to target your personally identifiable... 
    Cyber
    Principal
    Risk
    Full time
    Temporary work
    H1b
    Work at office
    Monday to Friday

    Fiserv

    Sunnyvale, CA
    2 days ago
  • $89.9k - $141.2k

     ...Our differentiated battle management and cyber solutions deliver timely, mission-enabling...  ...is looking for you to join our team as a Principal Contracts Administrator. The position may...  ...terms and conditions to evaluate risk, accuracy, and completeness to provide for... 
    Cyber
    Principal
    Risk
    Full time
    Contract work
    For contractors
    For subcontractor
    Work at office
    Relocation
    Shift work

    Northrop Grumman

    Sunnyvale, CA
    4 days ago
  •  ...Job Description Job Description SENIOR PRINCIPAL SOFTWARE ENGINEER    Saviynt is an identity platform built to power and protect...  ...transformation, where organizations are faced with increasing cyber risk but cannot afford defensive measures to slow down progress,... 
    Cyber
    Principal
    Risk

    Saviynt

    Milpitas, CA
    4 days ago
  • $207.4k - $259.2k

     ...our extended enterprise third-party risk posture. Archer is seeking a...  ...TPRM) Engineer to execute our vendor cyber risk function across all tiers of...  ...Experience integrating TPRM tooling with GRC platforms or building risk workflow automation (e.g., auto‑routing findings, SLA... 
    Cyber
    Risk
    Contract work
    Local area

    Archer56

    San Jose, CA
    2 days ago
  • $113.1k - $228.58k

     ...multiple organizations.Proactively identify risks, dependencies, and execution challenges...  ...LeadershipServe as the primary Tech GRC lead for internal readiness assessments,...  ...governance mechanisms.Find opportunities for automation and collaborate with GRC Engineering to improve... 
    Risk
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    San Jose, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal, GRC Automation and Cyber Risk. Be the first to apply!