> Markdown version of [/jobs/ext/622424-principal-security-engineer-grc](https://www.wearedevelopers.com/jobs/ext/622424-principal-security-engineer-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - GRC - **Company:** GoDaddy - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $140,000.0 - $273,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cyber Security, Identity and Access Management, Information Technology Audit, Cloud Platform System, Godaddy, Information Technology - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=db029338c1637f6d ## About the Role Do you have experience in Risk management compliance audits?, * 10+ years of professional experience in information security, information technology, information technology audit, or related fields * 6+ years of professional experience managing information security programs, audits, or formal assessment activities * Experience building unified security controls frameworks across multiple compliance and regulatory standards * Experience managing or performing audits using frameworks such asPCI DSS, NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, and SOC 2 * Experience assessing cloud environments such as AWS and applying core security engineering concepts such as threat modeling, architecture reviews, access management, and encryption * Experience presenting audit results, risk posture, and remediation priorities to executivestakeholders You might also have... * Certifications like PCI ISA, CISA, CRISC, ISO Lead Assessor, CISSP, etc. * Experience working at a Big 4 Audit firm(s) We encourage you to apply even if your experience or skillset doesn't align perfectly with every requirement. We value a wide range of backgrounds and transferable skills, and we are excited to support learning and growth. ## Description This is a remote position, so you'll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join our team The Governance, Risk, and Compliance team helps GoDaddy identify, assess, and address security risk across the business. We lead regulatory and compliance audits, manage risk acceptances and exception workflows, support third-party risk activities, and define security standards and policies that guide teams across the company. This role is a strong fit for someone who wants to build a durable audit and controls program from the ground up, influence security strategy, and work directly with senior leaders on risk-based decision-making. The ideal candidate will gain the opportunity to shape a long-term security governance initiative, partner broadly across engineering and security teams, and drive meaningful improvements in how GoDaddy manages risk and audit readiness. What you'll get to do... * Build and manage a unified security controls framework that supports regulatory and industry compliance requirements * Perform targeted gap assessments across business units, withan initial focus on hosting environments and audit readiness * Partner with engineering, product, legal, and other security teams toidentify control gaps, evaluate compensating controls, and reduce risk * Support internal and external audits across frameworks such asPCI DSS, SOC 2, ISO 27001, and other applicable regulations * Develop reporting and present security risks, audit status, and remediation priorities to senior leadership, including the Chief Information Security Officer * Drive scalable risk-based processes for exception management, risk acceptanceworkflows, and broader governance initiatives ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Reliable scalability: How Amazon.com scales on AWS](https://www.wearedevelopers.com/videos/983-reliable-scalability-how-amazon-com-scales-on-aws) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)