About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Principal - Data Privacy and Security based in United States.
Responsibilities
- Lead the end-to-end annual SOC 1 and SOC 2 Type II audit lifecycle, including control readiness, evidence collection, auditor coordination, reporting, and remediation.
- Own and continuously evolve the Information Security Management System (ISMS), policies, and control framework, with consideration for additional standards such as ISO compliance.
- Develop and mature vendor and third-party risk management programs, including frameworks, prioritization, stakeholder engagement, and performance measurement.
- Lead customer assurance activities, including enterprise security reviews, customer and prospect questionnaires, and cyber-insurance assessments.
- Scale security and privacy documentation, processes, and mechanisms to support enterprise growth and customer trust.
- Build and evolve data governance practices across the complete data lifecycle, including collection, storage, access, retention, classification, and deletion.
- Own the privacy compliance program across GDPR and CCPA, including data mapping, DSAR operations, retention practices, and privacy governance.
- Partner with Legal on Data Processing Agreements (DPAs), subprocessor obligations, and privacy-by-design practices within products and services.
- Establish and advance enterprise AI data governance policies, standards, and controls across the AI/ML lifecycle for internally developed and third-party AI solutions.
- Monitor emerging regulatory and industry frameworks, including NIST AI RMF, ISO 42001, and the EU AI Act, and translate developments into practical organizational requirements.
- Serve as a trusted subject-matter authority for security, privacy, risk, governance, and compliance matters across the organization.
- Translate technical, regulatory, and operational risks into clear business implications and recommendations for executives and senior stakeholders.
- Manage cross-functional GRC initiatives, establishing priorities, tracking progress, measuring outcomes, communicating risks, and escalating decisions when necessary.
- Mentor cross-functional partners and team members while establishing high standards for governance and compliance practices.
- Identify opportunities to use AI to automate GRC activities, improve efficiency, and increase the measurable impact of governance programs.
Requirements
- 10+ years of experience across GRC, information security, privacy, and compliance, with a proven history of building, scaling, and operating rigorous programs; fintech, payments, SaaS, or startup experience is highly desirable.
- Deep hands-on expertise with security frameworks and standards such as SOC 2, ISO 27001, and PCI DSS.
- Strong privacy compliance experience covering GDPR, CCPA, DSAR operations, data mapping, data governance, and privacy controls.
- Demonstrated ownership of SOC audit lifecycles, enterprise risk management, and third-party/vendor risk programs.
- Proven ability to leverage AI to automate GRC workloads, improve operational efficiency, and deliver measurable outcomes.
- Working knowledge of AI/ML governance and emerging regulatory requirements, with the ability to establish practical policies and controls in evolving areas.
- Exceptional project and program management skills, including prioritization, measurement, risk management, stakeholder communication, and executive reporting.
- Excellent judgment, integrity, discretion, and confidentiality when handling sensitive information and making complex risk trade-offs.
- Strong cross-functional influence and communication skills, with the ability to work effectively with executives, technical teams, auditors, legal stakeholders, and enterprise customers without direct authority.
- Strong strategic thinking and systems-thinking capabilities, with a focus on outcomes, risk appetite, business priorities, and long-term program maturity.
- Relevant professional certifications are an advantage, including CISSP, CISA, CISM, CRISC, CIPP, CIPM, CIPT, and/or AIGP.
- Comfortable working autonomously in a high-ambiguity, rapidly evolving environment.
Conditions
- Remote flexibility: Work from anywhere in Canada or the United States.
- Unlimited paid time off.
- Health and dental benefits.
- Up to CA$2,025 toward home IT setup.
- Up to 2% matching RRSP / 401(k) contributions.
- Learning and development opportunities.
- Up to CA$67.50 toward internet or cell phone service.
- Opportunity to work on high-impact security, privacy, compliance, and AI governance initiatives.
- High-autonomy environment with significant influence over long-term GRC strategy and program maturity.
- Collaborative culture focused on creativity, continuous improvement, and meaningful business impact.
- Commitment to an inclusive, respectful, and discrimination-f