Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Security GRC Analyst

Full-time

jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security GRC Analyst based in the United States.

This is a senior individual contributor role responsible for strengthening and scaling a complex security governance, risk, and compliance program within a cloud-based technology environment.
You’ll take ownership of compliance initiatives from control design and implementation through evidence collection, audit preparation, and auditor engagement.
The role spans multiple frameworks, including FedRAMP Moderate, DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX, and related security requirements.
You’ll collaborate closely with security, IT, engineering, product, platform, and other teams to translate regulatory expectations into practical controls.
The position offers significant autonomy and the opportunity to lead long-term, cross-functional compliance programs while improving automation and operational maturity.
You’ll also interact with auditors, government stakeholders, customers, and internal leadership on high-impact security and compliance matters.
This is an ideal opportunity for an experienced GRC professional who enjoys solving complex problems, building scalable processes, and enabling innovation without compromising security or privacy.

Accountabilities:

  • Drive the continued maturity of a comprehensive security governance, risk, and compliance program across multiple regulatory and security frameworks.
  • Own complex compliance initiatives end-to-end, from requirements analysis and control design through implementation, evidence collection, audit readiness, and external assessment.
  • Manage large, multi-month or multi-year compliance projects, ensuring milestones, dependencies, stakeholders, and deliverables remain on track.
  • Work directly with auditors, government officials, and other external stakeholders across frameworks including NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related standards.
  • Partner with security, IT, engineering, product, platform, and other teams to gather audit evidence and validate control effectiveness.
  • Translate compliance and regulatory requirements into practical, implementable controls that balance security, privacy, compliance, and business innovation.
  • Identify opportunities to harmonize controls and evidence across multiple frameworks, reducing duplication and improving the efficiency of the overall compliance program.
  • Leverage AI and automation to improve compliance operations, including processes for policy management, evidence collection, knowledge dissemination, and control monitoring.
  • Develop, maintain, and improve security, compliance, and privacy policies, procedures, plans, and supporting documentation.
  • Represent the compliance function in customer-facing discussions, security questionnaires, due diligence processes, and other external assessments.
  • Identify emerging compliance requirements and help determine how new frameworks or regulatory changes should be incorporated into existing governance processes.
  • Collaborate with leadership to resolve complex compliance challenges and continuously improve the organization’s security and risk posture.
  • Remain adaptable as the scope of the role evolves, taking on broader security, privacy, risk, or compliance responsibilities as organizational needs develop.

Requirements:

  • 8+ years of experience working with multiple security, risk, and compliance frameworks, including both small and large-scale audits and complex implementation programs.
  • Deep expertise in at least one major security or compliance framework, such as SOC 2 Type 2, ISO 27001, FedRAMP, or NIST SP 800-series standards.
  • Demonstrated ability to lead compliance initiatives through changing requirements, complex implementations, and evolving technology environments.
  • Practical experience with audit preparation, control implementation, evidence management, assessment activities, and auditor or regulator engagement.
  • Exposure to additional frameworks and regulations such as GDPR, ITAR, EAR, NISPOM, CMMC , or similar requirements is highly valued.
  • Strong understanding of security governance, risk management, control frameworks, compliance operations, and security/privacy principles.
  • Excellent project management and organizational skills, with the ability to independently manage initiatives spanning multiple months, quarters, or years.
  • Strong communication and stakeholder-management skills, with the ability to work effectively with technical teams, executives, auditors, government stakeholders, and customers.
  • Ability to translate complex regulatory and compliance requirements into clear, actionable guidance for engineering and business teams.
  • Strong analytical and problem-solving capabilities, with exceptional attention to detail and the ability to identify practical solutions to novel compliance challenges.
  • Self-directed and comfortable operating with a high degree of autonomy in a fast-moving technology environment.
  • Curiosity and willingness to use AI and automation to improve traditional compliance processes and enable scalable governance.
  • Relevant certifications such as CISM, GSLC, Security+ CE, CISSP , or comparable credentials are advantageous.
  • U.S. citizenship is required due to the nature of the work.
  • Successful completion of a comprehensive background check is required as part of employment.

Benefits:

  • Opportunity to work on complex, high-impact security and compliance challenges within a cloud-based technology environment.
  • High-autonomy role with significant ownership over strategic, multi-framework compliance initiatives.
  • Exposure to major frameworks and regulatory environments including FedRAMP, DoD IL5, CMMC, SOC 2, ISO 27001, and NIST.
  • Collaboration with security, engineering, product, platform, IT, audit, government, and customer stakeholders.
  • Opportunity to apply AI and automation to modernize security governance and compliance operations.
  • Supportive, collaborative, and mission-driven team environment.
  • Opportunities to expand responsibilities across security, privacy, risk, and compliance as the organization evolves.
  • Equal opportunity workplace committed to considering qualified candidates regardless of race, sex, disability, religion or belief, sexual orientation, or age.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Principal Security GRC Analyst in United States vacancy
  • $150k - $200k

     ...DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX AL2, and Facility Clearance License (FCL) requirements. As a Principal Security GRC Analyst, you will serve as a senior individual contributor driving control implementation, audit readiness, and cross-framework... 
    Principal
    Full time
    Immediate start

    Rescale

    Remote
    4 days ago
  • $209.25k - $271.71k

     ...challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of... 
    Suggested
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    1 day ago
  • $117.2k - $176.7k

     ...place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships.... 
    Suggested
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    3 days ago
  • $112.2k - $168.2k

     ...is impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Sr. Principal Industrial Security Analyst 4/Lead CPSO to support multiple program(s) as it relates to all applicable classified federal, contractual, customer... 
    Principal
    Full time
    Work experience placement
    Relocation
    Shift work

    Northrop Grumman

    Baltimore, MD
    3 days ago
  • $114k - $139k

    Reno, NV / Remote - USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    4 days ago
  • $75.8k - $113.8k

     ...Internship Program Description: As one of the largest global security companies in the world, Northrop Grumman is proud to help...  ...Aeronautics Systems sector is seeking an Industrial Security Analyst or Principal Industrial Security Analyst to join our team of qualified, diverse... 
    Principal
    Full time
    Work experience placement
    Internship
    Relocation package
    Shift work

    Northrop Grumman

    Redondo Beach, CA
    1 day ago
  • $81.4k - $122k

     ...impossible. Our employees are not only part of history, they're making history.Northrop Grumman Defense Systems is seeking a Principal Security Analyst. This position will be located in Roy, UT and will support the Sentinel (GBSD) Ground Base Strategic Deterrent program.... 
    Principal
    Full time
    For subcontractor
    Work at office
    Relocation package
    Monday to Thursday
    Shift work

    Northrop Grumman

    Utah
    3 days ago
  • $86.8k - $165.2k

     ...Position Role Type:Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements:Active and transferable U.S. government issued security clearance is required prior to start date.​ U.S. citizenship is required, as only U.S. citizens are eligible for a security... 
    Principal
    Temporary work
    Work experience placement
    For subcontractor
    Work at office
    Remote work
    Flexible hours

    Raytheon

    Tucson, AZ
    10 hours ago
  • $94.1k - $164.8k

     ...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk management policies, procedures and limits. Essential Functions... 
    Hourly pay
    Full time
    Temporary work
    Work experience placement
    Work at office

    CareSource

    Remote
    11 hours ago
  • $113.01k - $208.54k

    Duties: Provide thought leadership to the organization in information security frameworks, business continuity management, reporting and metrics, security risk management, firewall protection, information security training, intrusion prevention, data loss prevention, anti... 
    Principal
    Minimum wage
    Shift work

    Providence Health & Services

    Renton, WA
    3 days ago
  •  ...A leading energy company is seeking an SAP Security support professional to manage security applications across multiple SAP environments. You will ensure compliance with security guidelines, advocate for standard solutions, and maintain user security management. Ideal... 
    Flexible hours

    PSEG

    Hicksville, NY
    4 days ago
  •  ...Mid-Senior Level GRC Security AnalystWe need a mid-senior level Governance, Risk and Compliance (GRC) Security Analyst for a 6+ month contract for a public sector client in Long Beach, CA.The GRC Security Analyst will plan and implement policies, procedures, standards,... 
    Contract work
    Work experience placement
    Remote work

    ShiftCode Analytics

    Long Beach, CA
    3 days ago
  •  ...SAP GRC Analyst / SAP Security AnalystLocation: Monday - Friday - Onsite in Richardson, TX Position OverviewWe are seeking an experienced SAP GRC Analyst to serve as the critical link between IT and business stakeholders, ensuring a secure, compliant, and scalable SAP... 
    Monday to Friday

    Anveta

    Richardson, TX
    3 days ago
  • Expedia Group in Seattle is seeking a Principal Security Operations Analyst to lead complex security analyses, detect and respond to sophisticated threats, and drive measurable risk reduction across our global environments. You will design and optimize incident response... 
    Principal

    Expedia Group

    Seattle, WA
    2 days ago
  •  ...office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC (Governance Risk & Compliance)-Senior Security Analyst will be responsible for safeguarding Kura’s IT (Information Technology) infrastructure by monitoring... 
    Work at office

    Kura Sushi Corporate Support Center

    Irvine, CA
    6 days ago
  •  ...Job Description Job Description Principal Security Analyst (L3) Full-time, onsite preferred but remote candidates accepted.  Principal Security Analyst (L3) are expected to handle customer-facing investigations, mentoring, and training of fellow analysts, and to... 
    Principal
    Full time
    Remote work

    Lumifi Cyber

    Scottsdale, AZ
    24 days ago
  •  ...RSA Archer Administration/Configuration), Preferred 10+ Years (Enterprise/Government GRC Environments) Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the... 

    Siritech Solutions Corp

    Austin, TX
    more than 2 months ago
  • $96.2k - $144.2k

     ...impossible. Our employees are not only part of history, they're making history. Northrop Grumman is seeking an FSO/Sr. Principal Industrial Security Analyst 4 to join our excellent, diverse team of security professionals. This is an on-site position located in Oklahoma... 
    Principal
    Full time
    Contract work
    Work experience placement
    Local area
    Relocation
    Shift work

    Northrop Grumman

    Oklahoma City, OK
    8 days ago
  • Expedia Group is seeking a Principal Analyst in Security Operations to lead advanced security analyses and orchestration across its global environments, including threat detection and incident response. You will design scalable dashboards, runbooks, and workflows, enabling... 
    Principal

    Expedia, Inc.

    Seattle, WA
    4 days ago
  • Blue Yonder is seeking a Staff Security Analyst II, GRC to oversee IT and security control assessments, align with ISO 27001/ SOC 1/2, and support audits across product and internal processes. The role partners with cross-functional teams to ensure controls are implemented... 
    Remote job

    Blue Yonder

    Coppell, TX
    7 days ago
  • Blue Yonder, a global leader in AI-driven digital supply chain solutions, is seeking a Staff Security Analyst II, GRC. This role ensures product and internal processes are governed by IT and security controls aligned to regulatory and industry standards. You will partner... 
    Remote job

    Socket

    Dallas, TX
    5 days ago
  • Momentum is seeking a Security GRC & Risk Analyst to own governance, risk, and compliance across our portfolio. You will drive SOC 2 Type II and NIST CSF programs, maintain policy libraries, and manage vendor risk, audits, and client questionnaires. The role collaborates... 
    Full time
    Work at office

    Momentum

    Fort Worth, TX
    3 days ago
  • Lucid Software is seeking a Security Analyst to protect corporate assets, web apps, and staff. You will manage day-to-day GRC operations, vendor risk assessments, and support audits (SOC 2, ISO 27001) while fostering a security-aware culture across the organization. Join... 
    Work at office
    Remote work

    Lucid Software

    Raleigh, NC
    21 hours ago
  • $96.3k - $145.2k

     ...and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Experience The Security GRC Analyst role is part of our Security and Compliance team, sitting at the intersection of internal operations and external audit relationships... 
    Work at office

    salesforce.com, inc.

    San Francisco, CA
    5 days ago
  • $89.6k - $194k

    SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Position Description CGI is seeking a Senior SAP GRC and Application Security Analyst to join an SAP S/4HANA Greenfield implementation project for a large government contract. As a senior-... 
    Contract work
    Work at office
    Local area
    2 days per week
    Fairfax, VA
    more than 2 months ago
  • $108.8k - $147.2k

     ...delivering a business-driven Enterprise Network to support BICES Global Enterprise Mission Support Services increasing performance, security, scalability, and stability while reducing costs and complexity resulting in increased supportability. Responsibilities :... 
    Principal
    Full time
    Temporary work
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Hampton, VA
    6 days ago
  • Aqua seeks a GRC Security Analyst II to ensure the security and integrity of information systems. Responsibilities include risk assessments, developing remediation plans, and ensuring compliance with best practices. The ideal candidate will have a Bachelor’s degree in... 

    Aqua

    Bryn Mawr, PA
    2 days ago
  • Discord is seeking a Security Compliance professional to drive the customer questionnaire program end-to-end, building a reusable answer...  ...workflows, triaging issues and escalating as needed. You will analyze GRC posture, align standards to policies, and automate evidence... 

    VAMP Inc

    San Francisco, CA
    2 days ago
  • Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC... 

    Embedded Shishya

    Portland, OR
    1 day ago
  • Discord is seeking a Security Analyst to lead and scale its Security GRC program. You will own the day-to-day workflows—from questionnaires to risk tracking—partnering with Security, Engineering, IT, and Legal to make compliance friction-free. The role emphasizes automation... 

    Discord

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Security GRC Analyst. Be the first to apply!