remote
Principal Security Engineer - GRC - GoDaddy
Security Engineer
Lead enterprise security governance, risk, and compliance initiatives, designing frameworks, conducting audits, and driving cloud security strategies for a global organization.
About the role
Key Responsibilities
- Develop and maintain comprehensive GRC frameworks aligned with industry standards (ISO 27001, NIST, SOC 2).
- Lead risk assessments, vulnerability management, and security audit programs across cloud and on‑prem environments.
- Collaborate with cross‑functional teams to design secure architecture, enforce controls, and remediate findings.
- Drive incident response planning, tabletop exercises, and post‑incident analysis to strengthen defenses.
- Provide executive reporting on risk posture, compliance status, and improvement roadmaps.
Requirements
- 10+ years of security experience with a focus on GRC, risk, and compliance.
- Deep knowledge of cloud security (AWS, Azure, GCP) and security tooling (SIEM, SOAR, vulnerability scanners).
- Strong analytical, communication, and stakeholder management skills.
- Relevant certifications (CISSP, CISM, CRISC, or equivalent) preferred.