GoDaddy
Technology
PrincipalSecurityEngineer-InfoSecGRC
Neural analysis suggests this role is
optimal for Senior candidates.
“Principal Security Engineer - InfoSec GRC at GoDaddy. Skills: Security governance, Risk management, Audit programs, Compliance frameworks. Support GRC compliance specialists. Build unified security controls framework”
Industry & Context.
Not eligible for Alaska, Not eligible for Mississippi, Not eligible for North Dakota, Not eligible for Virgin Islands, Not considering California, Not considering Seattle, Not considering NYC
What They're Looking For.
Must Have
10+ years information security experience, 6+ years managing security programs, Experience building unified security controls frameworks, Experience managing audits using PCI DSS, Experience managing audits using SOC 2, Experience managing audits using ISO 27001, Experience managing audits using NIST CSF, Experience managing audits using NIST SP 800-53, Experience assessing cloud environments, Experience applying threat modeling, Experience applying architecture reviews, Experience applying access management, Experience applying encryption, Experience presenting audit results to executives, Experience automating compliance systems, Experience scripting compliance systems, Experience designing automated compliance systems
Nice to Have
CISSP certification, CISA certification, CISM certification, CRISC certification, PCI QSA certification, ISO Lead Assessor certification, Experience with Big Four audit firms, Experience with ServiceNow, Experience with Jira
What You'll Do.
Support GRC compliance specialists
Build unified security controls framework
Manage unified security controls framework
Perform gap assessments
Identify control gaps
Evaluate compensating controls
Support internal audits
Support external audits
Present security risks
Present remediation priorities
Drive risk-based processes
Manage exception workflows
Manage risk acceptance workflows
Manage governance initiatives
How You'll Work.
Team & Collaboration
Partner with engineering teams; Partner with security teams; Work with product teams; Work with legal teams
Communication Scope
Executive presentations
Full Job Description
Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join our team The Governance, Risk, and Compliance team helps GoDaddy identify, assess, and address security risk across the business. We lead regulatory and compliance audits, manage risk acceptances and exception workflows, support third-party risk activities, and define security standards and policies that guide teams across the company. This role is a strong fit for someone who wants to build a durable audit and controls program from the ground up, influence security strategy, and work directly with senior leaders on risk-based decision-making. The ideal candidate will gain the opportunity to shape a long-term security governance initiative, partner broadly across engineering and security teams, and drive meaningful improvements in how GoDaddy manages risk and audit readiness. What you'll get to do... Support a team of GRC compliance specialists in helping to build and manage a unified security controls framework that supports regulatory and industry compliance requirements Perform targeted gap assessments across business units to support new regulatory frameworks Partner with engineering, product, legal, and other security teams to identify control gaps, evaluate compensating controls, and reduce risk Support internal and external audits across frameworks such as PCI DSS, SOC 2, ISO 27001, and other applicable regulations Develop reporting and present security ri
Applying for this Principal Security Engineer - InfoSec GRC role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
ANONYMOUS · UNFILTERED
What do employees actually say about GoDaddy?
Real rants from real employees. Read before you apply.