GRC Principal - Data Privacy and Security in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Principal - Data Privacy and Security based in United States.
This is a senior individual-contributor role responsible for shaping and advancing enterprise security, privacy, and governance programs.
You will provide strategic direction while remaining deeply involved in the execution, measurement, and continuous improvement of GRC initiatives.
The role spans security compliance, privacy governance, third-party risk, customer assurance, and emerging AI governance.
You will help evolve audit readiness from a periodic exercise into a durable, evidence-driven operating discipline.
Working across Legal, Security, Business, and executive stakeholders, you will translate complex regulatory and technical risks into actionable business decisions.
The environment is highly autonomous and fast-paced, requiring strong judgment, systems thinking, and a focus on measurable outcomes.
This opportunity is particularly suited to a GRC leader who can combine deep technical expertise with strategic influence and responsible adoption of AI.
- Lead the end-to-end annual SOC 1 and SOC 2 Type II audit lifecycle, including control readiness, evidence collection, auditor coordination, reporting, and remediation.
- Own and continuously evolve the Information Security Management System (ISMS), policies, and control framework, with consideration for additional standards such as ISO compliance.
- Develop and mature vendor and third-party risk management programs, including frameworks, prioritization, stakeholder engagement, and performance measurement.
- Lead customer assurance activities, including enterprise security reviews, customer and prospect questionnaires, and cyber-insurance assessments.
- Scale security and privacy documentation, processes, and mechanisms to support enterprise growth and customer trust.
- Build and evolve data governance practices across the complete data lifecycle, including collection, storage, access, retention, classification, and deletion.
- Own the privacy compliance program across GDPR and CCPA, including data mapping, DSAR operations, retention practices, and privacy governance.
- Partner with Legal on Data Processing Agreements (DPAs), subprocessor obligations, and privacy-by-design practices within products and services.
- Establish and advance enterprise AI data governance policies, standards, and controls across the AI/ML lifecycle for internally developed and third-party AI solutions.
- Monitor emerging regulatory and industry frameworks, including NIST AI RMF, ISO 42001, and the EU AI Act, and translate developments into practical organizational requirements.
- Serve as a trusted subject-matter authority for security, privacy, risk, governance, and compliance matters across the organization.
- Translate technical, regulatory, and operational risks into clear business implications and recommendations for executives and senior stakeholders.
- Manage cross-functional GRC initiatives, establishing priorities, tracking progress, measuring outcomes, communicating risks, and escalating decisions when necessary.
- Mentor cross-functional partners and team members while establishing high standards for governance and compliance practices.
- Identify opportunities to use AI to automate GRC activities, improve efficiency, and increase the measurable impact of governance programs.
- 10+ years of experience across GRC, information security, privacy, and compliance, with a proven history of building, scaling, and operating rigorous programs; fintech, payments, SaaS, or startup experience is highly desirable.
- Deep hands-on expertise with security frameworks and standards such as SOC 2, ISO 27001, and PCI DSS.
- Strong privacy compliance experience covering GDPR, CCPA, DSAR operations, data mapping, data governance, and privacy controls.
- Demonstrated ownership of SOC audit lifecycles, enterprise risk management, and third-party/vendor risk programs.
- Proven ability to leverage AI to automate GRC workloads, improve operational efficiency, and deliver measurable outcomes.
- Working knowledge of AI/ML governance and emerging regulatory requirements, with the ability to establish practical policies and controls in evolving areas.
- Exceptional project and program management skills, including prioritization, measurement, risk management, stakeholder communication, and executive reporting.
- Excellent judgment, integrity, discretion, and confidentiality when handling sensitive information and making complex risk trade-offs.
- Strong cross-functional influence and communication skills, with the ability to work effectively with executives, technical teams, auditors, legal stakeholders, and enterprise customers without direct authority.
- Strong strategic thinking and systems-thinking capabilities, with a focus on outcomes, risk appetite, business priorities, and long-term program maturity.
- Relevant professional certifications are an advantage, including CISSP, CISA, CISM, CRISC, CIPP, CIPM, CIPT, and/or AIGP.
- Comfortable working autonomously in a high-ambiguity, rapidly evolving environment.
- Remote flexibility: Work from anywhere in Canada or the United States.
- Unlimited paid time off.
- Health and dental benefits.
- Up to CA$2,025 toward home IT setup.
- Up to 2% matching RRSP / 401(k) contributions.
- Learning and development opportunities.
- Up to CA$67.50 toward internet or cell phone service.
- Opportunity to work on high-impact security, privacy, compliance, and AI governance initiatives.
- High-autonomy environment with significant influence over long-term GRC strategy and program maturity.
- Collaborative culture focused on creativity, continuous improvement, and meaningful business impact.
- Commitment to an inclusive, respectful, and discrimination-free workplace.