Skip to content
WrapbookWrapbook

GRC Principal - Data Privacy and Security

Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.

About the job

Responsibilities

Data Security GRC

  • Lead the annual SOC 1 and SOC 2 Type II audit lifecycle, including control monitoring, readiness, auditor coordination, evidence collection, and reporting.
  • Drive control-owner accountability and develop continuous, evidence-driven controls.
  • Own and evolve the ISMS policy suite and control framework across SOC 1, SOC 2 Type II, and potential ISO compliance programs.
  • Mature the vendor and third-party risk management program, including frameworks, prioritization, stakeholder management, and measurement.
  • Lead customer assurance efforts for enterprise security reviews and cyber-insurance self-assessments.
  • Scale security and privacy documentation and assurance mechanisms.

Data Privacy GRC

  • Build and evolve data governance across collection, storage, access, retention, and deletion.
  • Own recommendations and decisions for dynamic data governance challenges.
  • Develop the privacy compliance program across GDPR and CCPA, including DSAR operations, data mapping, retention, governance, and classification.
  • Partner with Legal on DPAs, subprocessor obligations, and privacy-by-design in products.
  • Help shape enterprise AI data governance policies, standards, and controls across internally built and procured AI/ML systems.
  • Track regulatory and framework developments, including NIST AI RMF, ISO 42001, and the EU AI Act, and translate them into organizational requirements.

Cross-Functional Leadership

  • Translate technical and regulatory risk into actionable business terms for executives and leaders.
  • Represent the organization’s risk posture to executives, auditors, enterprise customers, and other external stakeholders.
  • Serve as a subject-matter authority and trusted advisor on security and privacy governance and compliance.
  • Mentor cross-functional partners and team members and establish organizational standards for the discipline.
  • Own project management, frameworks, measurement, prioritization, reporting, and risk-impact communication.

Requirements

  • 10+ years of experience in GRC, information security, and privacy compliance.
  • Track record of building, scaling, and operating rigorous programs, ideally in fintech, startups, payments, or SaaS.
  • Proven experience using AI to automate GRC work and improve measurable program outcomes.
  • Deep hands-on expertise in SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, DSAR operations, and data governance.
  • Working fluency in AI/ML governance and emerging regulatory requirements.
  • Experience owning SOC audit lifecycles and enterprise, vendor, and third-party risk programs.
  • Exceptional cross-functional influence with executives and technical teams without direct authority.
  • High integrity, discretion, ethics, and confidentiality when handling sensitive data and risk decisions.
  • Strong project management, prioritization, measurement, and executive reporting skills.

Nice-to-Haves

  • CISSP, CISA, CISM, CRISC, CIPP, CIPM, CIPT, and/or AIGP certification.

Compensation and Benefits

  • Salary: $143,000–$232,000 USD annually.
  • Unlimited paid time off.
  • Work from anywhere in Canada and the United States.
  • Health and dental benefits.
  • Up to $1,500 USD / $2,025 CAD toward home IT setup.
  • Up to 2% matching RRSP / 401(k).
  • Learning and development opportunities.
  • Up to $50 USD / $67.50 CAD toward internet or cell phone service.

Skills

SOC 2, Soc 1, ISO 27001, Pci Dss, GDPR, CCPA, Dsar Operations, Data Governance, Vendor Risk Management, Ai/Ml Governance, Nist Ai Rmf, Iso 42001, Eu Ai Act, Project Management

GitLab

GitLab

United States
Principal Security Researcher
$203k+/yrRemote10+ YOESecurity Engineering

Leads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.

GitLab

GitLab

United States
Principal Security Awareness & Human Risk Engineer
$203k+/yrRemote10+ YOESecurity Engineering

Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Twilio

Twilio

United States

Staff Enterprise Security Engineer, AI Security
$156k+/yrRemote7+ YOESecurity Engineering

Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.