# GRC Principal - Data Privacy and Security

**Company:** [Wrapbook](https://hotfix.jobs/companies/wrapbook)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $143k – $232k/yr
**Experience:** 10+ years
**Skills:** SOC 2, Soc 1, ISO 27001, Pci Dss, GDPR, CCPA, Dsar Operations, Data Governance, Vendor Risk Management, Ai/Ml Governance, Nist Ai Rmf, Iso 42001, Eu Ai Act, Project Management
**Posted:** 2026-09-01

> Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.

## Job Description

## Responsibilities

### Data Security GRC
- Lead the annual SOC 1 and SOC 2 Type II audit lifecycle, including control monitoring, readiness, auditor coordination, evidence collection, and reporting.
- Drive control-owner accountability and develop continuous, evidence-driven controls.
- Own and evolve the ISMS policy suite and control framework across SOC 1, SOC 2 Type II, and potential ISO compliance programs.
- Mature the vendor and third-party risk management program, including frameworks, prioritization, stakeholder management, and measurement.
- Lead customer assurance efforts for enterprise security reviews and cyber-insurance self-assessments.
- Scale security and privacy documentation and assurance mechanisms.

### Data Privacy GRC
- Build and evolve data governance across collection, storage, access, retention, and deletion.
- Own recommendations and decisions for dynamic data governance challenges.
- Develop the privacy compliance program across GDPR and CCPA, including DSAR operations, data mapping, retention, governance, and classification.
- Partner with Legal on DPAs, subprocessor obligations, and privacy-by-design in products.
- Help shape enterprise AI data governance policies, standards, and controls across internally built and procured AI/ML systems.
- Track regulatory and framework developments, including NIST AI RMF, ISO 42001, and the EU AI Act, and translate them into organizational requirements.

### Cross-Functional Leadership
- Translate technical and regulatory risk into actionable business terms for executives and leaders.
- Represent the organization’s risk posture to executives, auditors, enterprise customers, and other external stakeholders.
- Serve as a subject-matter authority and trusted advisor on security and privacy governance and compliance.
- Mentor cross-functional partners and team members and establish organizational standards for the discipline.
- Own project management, frameworks, measurement, prioritization, reporting, and risk-impact communication.

## Requirements
- 10+ years of experience in GRC, information security, and privacy compliance.
- Track record of building, scaling, and operating rigorous programs, ideally in fintech, startups, payments, or SaaS.
- Proven experience using AI to automate GRC work and improve measurable program outcomes.
- Deep hands-on expertise in SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, DSAR operations, and data governance.
- Working fluency in AI/ML governance and emerging regulatory requirements.
- Experience owning SOC audit lifecycles and enterprise, vendor, and third-party risk programs.
- Exceptional cross-functional influence with executives and technical teams without direct authority.
- High integrity, discretion, ethics, and confidentiality when handling sensitive data and risk decisions.
- Strong project management, prioritization, measurement, and executive reporting skills.

## Nice-to-Haves
- CISSP, CISA, CISM, CRISC, CIPP, CIPM, CIPT, and/or AIGP certification.

## Compensation and Benefits
- Salary: $143,000–$232,000 USD annually.
- Unlimited paid time off.
- Work from anywhere in Canada and the United States.
- Health and dental benefits.
- Up to $1,500 USD / $2,025 CAD toward home IT setup.
- Up to 2% matching RRSP / 401(k).
- Learning and development opportunities.
- Up to $50 USD / $67.50 CAD toward internet or cell phone service.

## Similar jobs

- [Principal Security Researcher](https://hotfix.jobs/jobs/1ceb0cbb-1f4e-4652-8d72-4e04a6b901ef) - GitLab - Remote - $203k – $275k/yr
- [Principal Security Awareness & Human Risk Engineer](https://hotfix.jobs/jobs/78ef4cbc-f12c-4557-b84e-ae3ad525db78) - GitLab - Remote - $203k – $275k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/29576103-a601-455c-a963-ce04128098e5) - Twilio - Remote - $156k – $194k/yr
- [Staff Enterprise Security Engineer, AI Security](https://hotfix.jobs/jobs/f0299624-eaec-4b80-89d9-94fde4d866e9) - Twilio - Remote - $156k – $194k/yr
- [Staff Identity Governance and Access Engineer](https://hotfix.jobs/jobs/8fe7fe60-ff7a-48f4-a805-f3f100e1814f) - Okta - Bellevue, WA - $161k – $221k/yr

**Apply:** https://hotfix.jobs/jobs/38077c67-8197-4a7b-8873-908a51fba716
**Canonical:** https://hotfix.jobs/jobs/38077c67-8197-4a7b-8873-908a51fba716