Principal GRC Business Engineer
Core
Architect, execute, and mature global Governance, Risk, and Compliance (GRC) programs by bridging technical security engineering, enterprise risk management, and business operations.
Role type
Principal GRC Business Engineer (Strategy & Engineering)
Builds
Global governance frameworks, scalable risk assessment methodologies, automated GRC platforms, and executive-level risk reporting.
Domain
Cybersecurity, Enterprise Risk Management, Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
GRC program architecture, enterprise risk engineering, policy drafting and maintenance, regulatory framework translation, quantitative and qualitative risk assessment, GRC platform configuration, multi-cloud architecture, policy-as-code, automated evidence collection, process automation
Preferred skills
AI governance framework development (NIST AI RMF, ISO 42001), CCSP or CIPP certification
Technologies
ISO 27001/2, NIST SP 800-53, NIST CSF, SOC 2 Type II, PCI-DSS, GDPR, AWS, Azure, GCP
Responsibilities
Design and scale global GRC vision to align with enterprise goals; Partner with senior leaders to align risk tolerance with business objectives; Lead drafting and review of security policies and standards; Translate regulatory frameworks into actionable requirements; Architect risk assessment methodologies for cloud and hybrid environments; Lead end-to-end technical security risk evaluations; Design executive-level risk reporting; Implement and optimize GRC platforms and risk management tools; Design policy-as-code test plans for automated control testing; Redesign manual processes into scalable automated workflows
Seniority
Principal, hands-on IC with strategic leadership
