Senior / Principal GRC Analyst
Core
Architecting and scaling enterprise governance, risk, and compliance programs for highly regulated, technology-driven environments, serving security leadership, engineering, legal, and executive stakeholders.
Role type
Senior/Principal GRC Analyst (Individual Contributor)
Builds
Enterprise GRC architecture and compliance outcomes aligned with ISO, NIST, privacy, and regulatory requirements.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC) in Defense/Government, Semiconductor, and SaaS sectors.
Deliverable
Production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO/IEC 27001 implementation, ISO/IEC 42001 (AI governance), GDPR/CCPA/CPRA program ownership, CMMC/NIST SP 800-171 compliance, risk-based architecture design, technical control validation, cloud security mapping, data protection engineering, incident response planning, AI risk assessment.
Preferred skills
CMMC L1-L3 technical control interpretation, AI governance frameworks, semiconductor supply chain security, SaaS security questionnaires, AI-enabled compliance tooling.
Technologies
ISO/IEC 27001, ISO/IEC 42001, GDPR, CCPA/CPRA, CMMC, NIST SP 800-171, AWS, Azure, GCP, Microsoft Purview, Defender, Entra ID.
Responsibilities
Define and maintain risk-based GRC architecture; lead end-to-end implementations of ISO 27001, ISO 42001, GDPR, CCPA, and CMMC; translate security architectures into compliant policies and evidence; lead enterprise, third-party, cloud, and AI-specific risk assessments; serve as primary interface for auditors and regulators; drive efficiency using GRC platforms and AI tooling; mentor junior GRC professionals.
Seniority
Senior/Principal, hands-on IC with strategy & mentorship