
GRC Principal – Data Privacy and Security
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States, +1 more country.
• Act as the subject matter expert and technical authority for Wrapbook's governance, risk, and compliance (GRC) programs related to privacy and security.
• Oversee the complete lifecycle of the annual SOC 1 and SOC 2 audits, which includes control monitoring, audit coordination, evidence gathering, reporting, and ongoing control enhancement.
• Take ownership of and improve the Information Security Management System (ISMS) policy suite and control framework for SOC 1, SOC 2 Type II, and potential ISO compliance opportunities.
• Advance the vendor risk management program, focusing on frameworks, prioritization, stakeholder engagement, and performance measurement.
• Lead Customer Assurance initiatives for enterprise security evaluations and cyber insurance self-assessments.
• Expand security and privacy documentation as well as mechanisms.
• Develop and enhance the Data Governance program concerning data collection, storage, access, retention, and deletion.
• Provide recommendations and make decisions regarding evolving data governance challenges.
• Develop and enhance privacy compliance measures for GDPR and CCPA, which includes handling Data Subject Access Requests (DSARs), data mapping, retention policies, data governance, and classification.
• Collaborate with the Legal team on Data Processing Agreements (DPAs), subprocessor obligations, and integrating privacy-by-design principles in products.
• Influence the enterprise AI data governance framework throughout the AI/ML lifecycle for both internally developed and externally sourced AI solutions.
• Monitor developments in regulations and frameworks such as NIST AI RMF, ISO 42001, and the EU AI Act.
• Convert technical and regulatory risks into practical business terms for executive understanding.
• Act as a trusted advisor on governance and compliance related to Security and Privacy.
• Mentor cross-functional partners and team members while establishing the organizational standard for the discipline.
• Over 10 years of experience in governance, risk, and compliance (GRC), information security, and privacy compliance.
• Proven history of building, scaling, and managing highly rigorous programs, preferably within a fintech, startup, or payments organization.
• Exemplary integrity and discretion; adept at handling sensitive data and making difficult risk trade-offs with ethical soundness and confidentiality.
• Strong project management capabilities, including the ability to establish, track, measure, and convey cross-functional program progress, prioritization decisions/trade-offs, risks, and impact.
• Demonstrated experience in utilizing AI to automate GRC workloads and significantly enhance GRC programs to achieve measurable outcomes.
• Extensive hands-on expertise in SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, DSAR operations, and data governance compliance.
• Proficient understanding of AI/ML governance and the current regulatory environment.
• Proven track record in managing SOC audit lifecycles and enterprise risk as well as third-party risk programs.
• Exceptional ability to influence cross-functional teams without direct authority.
• Relevant certifications are a plus: CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP.
• Unlimited Paid Time Off.
• Flexibility to work from anywhere in Canada and the USA.
• Comprehensive Health and Dental benefits.
• Up to $1,500 USD / $2,025 CAD towards home IT setup.
• Up to 2% matching RRSP / 401K contributions.
• Opportunities for Learning and Development.
• Up to $50 USD / $67.50 CAD for Internet/Cell phone service.
Pair Team
Veta Virtual
Chinook Systems Inc.
Rithum
Get handpicked remote jobs straight to your inbox weekly.