Description
The Senior / Principal GRC Analyst will architect, implement, and scale enterprise governance, risk, and compliance programs across highly regulated technology environments. The role owns ISO/IEC 27001, ISO/IEC 42001, GDPR, CCPA/CPRA, and CMMC/NIST 800‑171 programs; translates security architectures into compliant policies and evidence; leads risk assessments and audits; advises security, engineering, legal, and executive stakeholders; and mentors junior GRC professionals. It requires 7–12+ years of GRC, security, privacy, or risk management experience, strong technical and regulatory expertise, and the ability to work independently at a senior or principal individual contributor level.
