GRC Principal – Data Privacy and Security

Posted Sep 1

This is a fully remote position, open to applicants in United States, +1 more country.

📋 Description

• Act as the subject matter expert and technical authority for Wrapbook's governance, risk, and compliance (GRC) programs related to privacy and security.

• Oversee the complete lifecycle of the annual SOC 1 and SOC 2 audits, which includes control monitoring, audit coordination, evidence gathering, reporting, and ongoing control enhancement.

• Take ownership of and improve the Information Security Management System (ISMS) policy suite and control framework for SOC 1, SOC 2 Type II, and potential ISO compliance opportunities.

• Advance the vendor risk management program, focusing on frameworks, prioritization, stakeholder engagement, and performance measurement.

• Lead Customer Assurance initiatives for enterprise security evaluations and cyber insurance self-assessments.

• Expand security and privacy documentation as well as mechanisms.

• Develop and enhance the Data Governance program concerning data collection, storage, access, retention, and deletion.

• Provide recommendations and make decisions regarding evolving data governance challenges.

• Develop and enhance privacy compliance measures for GDPR and CCPA, which includes handling Data Subject Access Requests (DSARs), data mapping, retention policies, data governance, and classification.

• Collaborate with the Legal team on Data Processing Agreements (DPAs), subprocessor obligations, and integrating privacy-by-design principles in products.

• Influence the enterprise AI data governance framework throughout the AI/ML lifecycle for both internally developed and externally sourced AI solutions.

• Monitor developments in regulations and frameworks such as NIST AI RMF, ISO 42001, and the EU AI Act.

• Convert technical and regulatory risks into practical business terms for executive understanding.

• Act as a trusted advisor on governance and compliance related to Security and Privacy.

• Mentor cross-functional partners and team members while establishing the organizational standard for the discipline.


⛳️ Requirements

• Over 10 years of experience in governance, risk, and compliance (GRC), information security, and privacy compliance.

• Proven history of building, scaling, and managing highly rigorous programs, preferably within a fintech, startup, or payments organization.

• Exemplary integrity and discretion; adept at handling sensitive data and making difficult risk trade-offs with ethical soundness and confidentiality.

• Strong project management capabilities, including the ability to establish, track, measure, and convey cross-functional program progress, prioritization decisions/trade-offs, risks, and impact.

• Demonstrated experience in utilizing AI to automate GRC workloads and significantly enhance GRC programs to achieve measurable outcomes.

• Extensive hands-on expertise in SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, DSAR operations, and data governance compliance.

• Proficient understanding of AI/ML governance and the current regulatory environment.

• Proven track record in managing SOC audit lifecycles and enterprise risk as well as third-party risk programs.

• Exceptional ability to influence cross-functional teams without direct authority.

• Relevant certifications are a plus: CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP.


🏝️ Benefits

• Unlimited Paid Time Off.

• Flexibility to work from anywhere in Canada and the USA.

• Comprehensive Health and Dental benefits.

• Up to $1,500 USD / $2,025 CAD towards home IT setup.

• Up to 2% matching RRSP / 401K contributions.

• Opportunities for Learning and Development.

• Up to $50 USD / $67.50 CAD for Internet/Cell phone service.

People also viewed

Pair Team1 day ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$170k – $190k/year
ApplyView job
Veta Virtual1 day ago

CISO/VP, Data Security

EuropeFull-timeCybersecurity / Security Engineer$90k – $100k/year
ApplyView job
Chinook Systems Inc.1 day ago

Cybersecurity Operational Technology (OT) Specialist

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer$115k – $135k/year
ApplyView job
Rithum1 day ago

Staff Information Security Engineer – AI First

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$170k – $220k/year
ApplyView job
Palo Alto Networks1 day ago

Manager, Domain Consulting – AI Security

US flagConnecticut, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
NBCUniversal1 day ago

Staff Cyber Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security Engineer$125k – $155k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers