> Markdown version of [/jobs/ext/2720870-grc-principal-data-privacy-and-security](https://www.wearedevelopers.com/jobs/ext/2720870-grc-principal-data-privacy-and-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Principal - Data Privacy and Security - **Company:** TAKEONE NETWORK CORP. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $18,000.0 - $24,300.0 - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Artificial Intelligence, Data Governance, Information Security Management, PCI Data Security Standards, Machine Learning Operations - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/grc-principal-data-privacy-and-security-wrapbook-3-9845504 ## About the Role * 10+ years in GRC, information security and privacy compliance with a track record of building, scaling, and operating highly rigorous programs - ideally at a fintech, start-up, or payments organization. * You have the highest integrity and discretion. ****Customer trust is paramount at Wrapbook and this role will interact with highly sensitive data, owning difficult risk trade-offs with sound ethics and confidentiality. * Project management is second nature, you effectively establish, track, measure and communicate/report out on cross-functional program progress, prioritization decisions/trade-offs, risks, and impact. * Proven experience leveraging AI to automate GRC workload and force-multiply GRC programs to measurable outcomes. * Deep, hands-on expertise across security (SOC 2 / ISO 27001 / PCI DSS), privacy (GDPR / CCPA, DSAR operations, data governance) compliance. * Working fluency in AI/ML governance and the current regulatory landscape. You are comfortable with setting policy where standards are still forming. * Demonstrated ownership of SOC audit lifecycles and enterprise risk and third-party risk programs. * Exceptional cross-functional influence - able to move executives and technical teams without direct authority. * Relevant certifications a plus: CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP. ## Description * Lead the annual SOC 1 and 2 audit lifecycle end-to-end: control monitoring/readiness, work with our SOC auditors and internal business teams to complete the audit project and reporting supporting evidence collection and clarification process, drive control-owner accountability and lead program development to embed continuous, evidence-driven controls. * Own and evolve Wrapbook's ISMS policy suite and control framework (SOC 1, SOC 2 Type II; explore additional ISO compliance opportunities) in collaboration with our Business, Legal, and Security teams. * Mature our approach to vendor risk management, developing and evolving the program, frameworks, prioritization, stakeholder management, and measurement. * Lead Customer Assurance efforts for enterprise security reviews (e.g., enterprise customer and prospect review requirements, cyber-insurance self-assessments) and scale Wrapbook's security and privacy documentation and mechanisms. Data Privacy GRC * Collaborate with Legal and Security teams to build and evolve Wrapbook's Data Governance program across the data lifecycle (data collection, storage, access, retention, deletion). * Beyond project management you will make recommendations and own decisions on how to best solve Wrapbook's dynamic and growing data governance challenges. * Build and evolve the privacy compliance program across GDPR and CCPA - DSAR operations, data mapping, retention, and the data governance and classification program. * Partner with Legal on DPAs, subprocessor obligations, and privacy-by-design in product. * Help shape Wrapbook's enterprise AI data governance framework in collaboration with our Security and Legal leadership/org- policies, standards, and controls across the AI/ML lifecycle for both internally built and procured AI. * Track the evolving regulatory and framework landscape (e.g., NIST AI RMF, ISO 42001, EU AI Act) and translate it into Wrapbook's needs. Cross-functional leadership * Executive fluency and credibility. Translates technical and regulatory risk into business terms leadership can act on, and holds their own in front of executives, auditors, and enterprise customers. Trusted to represent Wrapbook's risk posture externally. * Serve as the subject-matter authority and trusted advisor on Security and Privacy governance and compliance topics. * Mentor cross-functional partners and team members and set the standard for the discipline across the org. ## Related Videos - [How to Stop Your Agents From Going Rogue - Arnav Gupta](https://www.wearedevelopers.com/videos/2152-how-to-stop-your-agents-from-going-rogue-arnav-gupta) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Unlocking Value from Data: The Key to Smarter Business Decisions-](https://www.wearedevelopers.com/videos/1367-unlocking-value-from-data-the-key-to-smarter-business-decisions) - [Secure and Private AI - DeepMask](https://www.wearedevelopers.com/videos/1665-secure-and-private-ai-deepmask) - [AI is dead, long live AK](https://www.wearedevelopers.com/videos/1093-ai-is-dead-long-live-ak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges](https://www.wearedevelopers.com/magazine/488-panel-discussion-responsible-ai-in-practice-real-world-examples-and-challenges) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)