Principal Security GRC Analyst
jobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security GRC Analyst based in the United States.
This is a senior individual contributor role responsible for strengthening and scaling a complex security governance, risk, and compliance program within a cloud-based technology environment.
You’ll take ownership of compliance initiatives from control design and implementation through evidence collection, audit preparation, and auditor engagement.
The role spans multiple frameworks, including FedRAMP Moderate, DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX, and related security requirements.
You’ll collaborate closely with security, IT, engineering, product, platform, and other teams to translate regulatory expectations into practical controls.
The position offers significant autonomy and the opportunity to lead long-term, cross-functional compliance programs while improving automation and operational maturity.
You’ll also interact with auditors, government stakeholders, customers, and internal leadership on high-impact security and compliance matters.
This is an ideal opportunity for an experienced GRC professional who enjoys solving complex problems, building scalable processes, and enabling innovation without compromising security or privacy.
Accountabilities:
- Drive the continued maturity of a comprehensive security governance, risk, and compliance program across multiple regulatory and security frameworks.
- Own complex compliance initiatives end-to-end, from requirements analysis and control design through implementation, evidence collection, audit readiness, and external assessment.
- Manage large, multi-month or multi-year compliance projects, ensuring milestones, dependencies, stakeholders, and deliverables remain on track.
- Work directly with auditors, government officials, and other external stakeholders across frameworks including NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related standards.
- Partner with security, IT, engineering, product, platform, and other teams to gather audit evidence and validate control effectiveness.
- Translate compliance and regulatory requirements into practical, implementable controls that balance security, privacy, compliance, and business innovation.
- Identify opportunities to harmonize controls and evidence across multiple frameworks, reducing duplication and improving the efficiency of the overall compliance program.
- Leverage AI and automation to improve compliance operations, including processes for policy management, evidence collection, knowledge dissemination, and control monitoring.
- Develop, maintain, and improve security, compliance, and privacy policies, procedures, plans, and supporting documentation.
- Represent the compliance function in customer-facing discussions, security questionnaires, due diligence processes, and other external assessments.
- Identify emerging compliance requirements and help determine how new frameworks or regulatory changes should be incorporated into existing governance processes.
- Collaborate with leadership to resolve complex compliance challenges and continuously improve the organization’s security and risk posture.
- Remain adaptable as the scope of the role evolves, taking on broader security, privacy, risk, or compliance responsibilities as organizational needs develop.
Requirements:
- 8+ years of experience working with multiple security, risk, and compliance frameworks, including both small and large-scale audits and complex implementation programs.
- Deep expertise in at least one major security or compliance framework, such as SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series standards.
- Demonstrated ability to lead compliance initiatives through changing requirements, complex implementations, and evolving technology environments.
- Practical experience with audit preparation, control implementation, evidence management, assessment activities, and auditor or regulator engagement.
- Exposure to additional frameworks and regulations such as GDPR, ITAR, EAR, NISPOM, CMMC , or similar requirements is highly valued.
- Strong understanding of security governance, risk management, control frameworks, compliance operations, and security/privacy principles.
- Excellent project management and organizational skills, with the ability to independently manage initiatives spanning multiple months, quarters, or years.
- Strong communication and stakeholder-management skills, with the ability to work effectively with technical teams, executives, auditors, government stakeholders, and customers.
- Ability to translate complex regulatory and compliance requirements into clear, actionable guidance for engineering and business teams.
- Strong analytical and problem-solving capabilities, with exceptional attention to detail and the ability to identify practical solutions to novel compliance challenges.
- Self-directed and comfortable operating with a high degree of autonomy in a fast-moving technology environment.
- Curiosity and willingness to use AI and automation to improve traditional compliance processes and enable scalable governance.
- Relevant certifications such as CISM, GSLC, Security+ CE, CISSP , or comparable credentials are advantageous.
- U.S. citizenship is required due to the nature of the work.
- Successful completion of a comprehensive background check is required as part of employment.
Benefits:
- Opportunity to work on complex, high-impact security and compliance challenges within a cloud-based technology environment.
- High-autonomy role with significant ownership over strategic, multi-framework compliance initiatives.
- Exposure to major frameworks and regulatory environments including FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, and NIST.
- Collaboration with security, engineering, product, platform, IT, audit, government, and customer stakeholders.
- Opportunity to apply AI and automation to modernize security governance and compliance operations.
- Supportive, collaborative, and mission-driven team environment.
- Opportunities to expand responsibilities across security, privacy, risk, and compliance as the organization evolves.
- Equal opportunity workplace committed to considering qualified candidates regardless of race, sex, disability, religion or belief, sexual orientation, or age.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$150k - $200k
...DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX AL2, and Facility Clearance License (FCL) requirements. As a Principal Security GRC Analyst, you will serve as a senior individual contributor driving control implementation, audit readiness, and cross-framework...PrincipalFull timeImmediate start$209.25k - $271.71k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of...SuggestedFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$117.2k - $176.7k
...place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships....SuggestedFull timeWork at office$112.2k - $168.2k
...is impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Sr. Principal Industrial Security Analyst 4/Lead CPSO to support multiple program(s) as it relates to all applicable classified federal, contractual, customer...PrincipalFull timeWork experience placementRelocationShift work$114k - $139k
Reno, NV / Remote - USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations...SuggestedFull timeTemporary workWork experience placementRemote work$75.8k - $113.8k
...Internship Program Description: As one of the largest global security companies in the world, Northrop Grumman is proud to help... ...Aeronautics Systems sector is seeking an Industrial Security Analyst or Principal Industrial Security Analyst to join our team of qualified, diverse...PrincipalFull timeWork experience placementInternshipRelocation packageShift work$81.4k - $122k
...impossible. Our employees are not only part of history, they're making history.Northrop Grumman Defense Systems is seeking a Principal Security Analyst. This position will be located in Roy, UT and will support the Sentinel (GBSD) Ground Base Strategic Deterrent program....PrincipalFull timeFor subcontractorWork at officeRelocation packageMonday to ThursdayShift work$86.8k - $165.2k
...Position Role Type:Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements:Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security...PrincipalTemporary workWork experience placementFor subcontractorWork at officeRemote workFlexible hours$94.1k - $164.8k
...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk management policies, procedures and limits. Essential Functions...Hourly payFull timeTemporary workWork experience placementWork at office$113.01k - $208.54k
Duties: Provide thought leadership to the organization in information security frameworks, business continuity management, reporting and metrics, security risk management, firewall protection, information security training, intrusion prevention, data loss prevention, anti...PrincipalMinimum wageShift work- ...A leading energy company is seeking an SAP Security support professional to manage security applications across multiple SAP environments. You will ensure compliance with security guidelines, advocate for standard solutions, and maintain user security management. Ideal...Flexible hours
- ...Mid-Senior Level GRC Security AnalystWe need a mid-senior level Governance, Risk and Compliance (GRC) Security Analyst for a 6+ month contract for a public sector client in Long Beach, CA.The GRC Security Analyst will plan and implement policies, procedures, standards,...Contract workWork experience placementRemote work
- ...SAP GRC Analyst / SAP Security AnalystLocation: Monday - Friday - Onsite in Richardson, TX Position OverviewWe are seeking an experienced SAP GRC Analyst to serve as the critical link between IT and business stakeholders, ensuring a secure, compliant, and scalable SAP...Monday to Friday
- Expedia Group in Seattle is seeking a Principal Security Operations Analyst to lead complex security analyses, detect and respond to sophisticated threats, and drive measurable risk reduction across our global environments. You will design and optimize incident response...Principal
- ...office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC (Governance Risk & Compliance)-Senior Security Analyst will be responsible for safeguarding Kura’s IT (Information Technology) infrastructure by monitoring...Work at office
- ...Job Description Job Description Principal Security Analyst (L3) Full-time, onsite preferred but remote candidates accepted. Principal Security Analyst (L3) are expected to handle customer-facing investigations, mentoring, and training of fellow analysts, and to...PrincipalFull timeRemote work
- ...RSA Archer Administration/Configuration), Preferred 10+ Years (Enterprise/Government GRC Environments) Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the...
$96.2k - $144.2k
...impossible. Our employees are not only part of history, they're making history. Northrop Grumman is seeking an FSO/Sr. Principal Industrial Security Analyst 4 to join our excellent, diverse team of security professionals. This is an on-site position located in Oklahoma...PrincipalFull timeContract workWork experience placementLocal areaRelocationShift work- Expedia Group is seeking a Principal Analyst in Security Operations to lead advanced security analyses and orchestration across its global environments, including threat detection and incident response. You will design scalable dashboards, runbooks, and workflows, enabling...Principal
- Blue Yonder is seeking a Staff Security Analyst II, GRC to oversee IT and security control assessments, align with ISO 27001/ SOC 1/2, and support audits across product and internal processes. The role partners with cross-functional teams to ensure controls are implemented...Remote job
- Blue Yonder, a global leader in AI-driven digital supply chain solutions, is seeking a Staff Security Analyst II, GRC. This role ensures product and internal processes are governed by IT and security controls aligned to regulatory and industry standards. You will partner...Remote job
- Momentum is seeking a Security GRC & Risk Analyst to own governance, risk, and compliance across our portfolio. You will drive SOC 2 Type II and NIST CSF programs, maintain policy libraries, and manage vendor risk, audits, and client questionnaires. The role collaborates...Full timeWork at office
- Lucid Software is seeking a Security Analyst to protect corporate assets, web apps, and staff. You will manage day-to-day GRC operations, vendor risk assessments, and support audits (SOC 2, ISO 27001) while fostering a security-aware culture across the organization. Join...Work at officeRemote work
$96.3k - $145.2k
...and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Experience The Security GRC Analyst role is part of our Security and Compliance team, sitting at the intersection of internal operations and external audit relationships...Work at office$89.6k - $194k
SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Position Description CGI is seeking a Senior SAP GRC and Application Security Analyst to join an SAP S/4HANA Greenfield implementation project for a large government contract. As a senior-...Contract workWork at officeLocal area2 days per week$108.8k - $147.2k
...delivering a business-driven Enterprise Network to support BICES Global Enterprise Mission Support Services increasing performance, security, scalability, and stability while reducing costs and complexity resulting in increased supportability. Responsibilities :...PrincipalFull timeTemporary workWork at officeImmediate startRemote workWorldwideFlexible hours- Aqua seeks a GRC Security Analyst II to ensure the security and integrity of information systems. Responsibilities include risk assessments, developing remediation plans, and ensuring compliance with best practices. The ideal candidate will have a Bachelor’s degree in...
- Discord is seeking a Security Compliance professional to drive the customer questionnaire program end-to-end, building a reusable answer... ...workflows, triaging issues and escalating as needed. You will analyze GRC posture, align standards to policies, and automate evidence...
- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC...
- Discord is seeking a Security Analyst to lead and scale its Security GRC program. You will own the day-to-day workflows—from questionnaires to risk tracking—partnering with Security, Engineering, IT, and Legal to make compliance friction-free. The role emphasizes automation...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Security GRC Analyst. Be the first to apply!
- rate analyst United States
- work from home security analyst United States
- entry level information security analyst United States
- national security analyst United States
- physical security analyst United States
- application security analyst United States
- information security analyst United States
- entry level security analyst United States
- security analyst United States
- security operations analyst United States


