Assistant Director, Cyber GRC
Listed on 2026-01-17
-
IT/Tech
Cybersecurity, Information Security
What You'll Do
We're looking for an experienced Assistant Director of Cyber GRC to join our Information Security and Risk GRC team. In this role, you'll lead cybersecurity regulatory compliance activities by engaging with regulators, interpreting new and emerging regulatory requirements on a global scale, translating those requirements into practical security controls, and partnering with technology, risk, and business teams to reduce the threat landscape to demonstrate sustainable compliance.
Governance & Assurance- Design global cybersecurity assurance program, including control gap assessments, testing, evidence management, and continuous monitoring
- Evaluate control effectiveness and recommend process or tooling improvements to improve efficiency and coverage
- Monitor and interpret changes in global cybersecurity laws, regulations, and standards (e.g., NIST, SOX, SOC, GDPR, HIPAA)
- Translate regulatory requirements into actionable security controls, metrics, and framework mappings
- Support control design enhancements to address regulatory expectations and emerging risks
- Support readiness for regulatory exams, audits, and third‑party assessments
- Participate in audits, coordinate responses to inquiries, and track remediation activities
- Partner with IT, Legal, Risk, Compliance, and Audit teams to align cybersecurity controls with regulatory obligations
- Provide subject‑matter guidance on GRC best practices and control design
- Provide training and awareness on regulatory compliance topics, as needed
- Develop and maintain reporting on control posture, findings, and remediation progress
- Communicate regulatory changes, risks, and control insights to leadership
Operating at the intersection of financial services and technology, Principal builds financial tools that help our customers live better lives. We take pride in being a purpose‑led firm, motivated by our mission to make financial security accessible to all. Our mission, integrity, and customer focus have made us a trusted leader for more than 140 years.
Who You Are- Bachelor’s degree in information security, cybersecurity, law, or a related field or equivalent experience
- 8+ years of experience in cybersecurity, information risk, or IT compliance
- Direct, hands‑on experience engaging with regulators (e.g., scoping exams, responding to information requests, and/or presenting to examiners)
- Proven experience with regulatory frameworks and standards such as NIST CSF and 800‑53, SOX, SOC, GDPR, and HIPAA
- Exceptional written and verbal communication skills with an ability to brief executives and regulators with clarity and confidence
- Strong stakeholder management experience with the ability to influence cross‑functional teams and drive accountability without direct authority
- Experience designing cybersecurity assurance program in a regulated industry (e.g., finance, insurance, government)
- Professional certifications such as CISA, CISM, CGRC, CRISC, or CISSP
- Familiarity with risk management methodologies and tools
- Diplomacy and professionalism in high‑stakes discussions
- Ability to consult on technical controls
Salary ranges below reflect targeted base salaries. Non‑sales positions have the opportunity to participate in a bonus program. Sales positions are eligible for sales incentives, and in some instances a bonus plan, whereby total compensation may far exceed base salary depending on individual performance. Actual compensation for all roles will be based upon geographic location, work experience, education, licensure requirements and/or skill level and will be finalized at the time of offer.
Salary Range (Non‑Exempt expressed as hourly; Exempt expressed as yearly)$141000 - $180000 / year
Time Off ProgramFlexible Time Off (FTO) is provided to salaried (exempt) employees and provides the opportunity to take time away from the office with pay for vacation, personal or short‑term illness. Employees don’t accrue a bank of time off under FTO and there is no set number of days provided.
Pension…(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).