Principal Governance, Risk and Compliance (GRC) Architect
Core
Architect and implement rigorous security standards (TISAX, ITAR, FedRAMP) within AWS infrastructure to enable enterprise and government deals without bottlenecking engineering velocity.
Role type
Principal GRC Architect (hands-on IC)
Builds
AWS GovCloud infrastructure, automated compliance monitoring, and technical controls for federal/international standards
Domain
Cybersecurity, Cloud Infrastructure (AWS), Government/Defense Compliance
Deliverable
production ML models | product features | infrastructure
Required skills
AWS GovCloud architecture, VPC isolation, IAM design, network security boundaries, TISAX/ITAR/FedRAMP audit leadership, GDPR data mapping, risk assessment, policy writing
Preferred skills
AI regulation knowledge, technical translation of regulatory requirements, stakeholder negotiation with Infosec counterparts
Technologies
AWS, GovCloud, VPC, IAM, automated monitoring tools
Responsibilities
Maintain SOC 2 Type II continuous observation, define network security boundaries for ITAR/FedRAMP, design controls that satisfy auditors without bottlenecks, execute TISAX/ITAR/FedRAMP implementation, steward GDPR data mapping, join customer Infosec calls, perform risk assessments and manage audits
Seniority
Principal, hands-on IC