Hiring.Camp

Senior / Principal GRC Analyst

Altera

·

May 12, 2026

Location
Bengaluru, Karnataka, India
Type
Full-time
Seniority
Senior
Experience
7+ years
Education
Master
Source
Workday

Description

Job Details:

Job Description:

Role Summary

The Senior / Principal GRC Analyst is a senior individual contributor responsible for architecting, leading, and scaling enterprise governance, risk, and compliance programs across highly regulated, technology‑driven environments. This role owns implementation and continuous improvement of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), GDPR, CCPA/CPRA, and CMMC, and acts as a trusted advisor to security leadership, engineering, legal, and executive stakeholders.

This role requires strong hands‑on cybersecurity knowledge, deep regulatory expertise, and the ability to translate technical security architectures into audit‑ready, business‑aligned compliance outcomes.

Core Responsibilities (All Environments)

  • Define and maintain a risk‑based GRC architecture aligned to ISO, NIST, privacy, and regulatory requirements.
  • Lead end‑to‑end implementations of:
    • ISO/IEC 27001 (ISMS ownership, risk methodology, SoA, internal audits)
    • ISO/IEC 42001 (AI governance, AI risk and control design)
    • GDPR and CCPA/CPRA privacy programs
    • CMMC / NIST SP 800‑171
  • Translate security architectures and technical controls into compliant policies, standards, and evidence.
  • Lead enterprise, third‑party, cloud, and AI‑specific risk assessments.
  • Serve as primary interface for auditors, assessors, regulators, customers, and partners.
  • Drive efficiency using GRC platforms, security telemetry, and AI‑assisted compliance tooling.
  • Mentor junior GRC professionals and influence cross‑functional teams without direct authority.

Technical Cybersecurity Skills & Expectations

Security Architecture & Controls

  • Strong understanding of defense‑in‑depth architectures, including:
    • Network segmentation, firewalls, IDS/IPS
    • Endpoint Detection & Response (EDR/XDR)
    • Identity and Access Management (IAM), SSO, MFA, RBAC
  • Ability to assess and validate technical control effectiveness, not just paper compliance.

Cloud & SaaS Security

  • Hands‑on familiarity with cloud security models (AWS, Azure, GCP concepts):
    • Shared responsibility
    • Logging and monitoring
    • Encryption at rest and in transit
    • Secure CI/CD and infrastructure‑as‑code risks
  • Ability to map cloud security controls to ISO 27001, NIST, and CMMC requirements.

Data Protection & Privacy Engineering

  • Understanding of:
    • Data classification and labeling
    • DLP, encryption, key management
    • Data residency and cross‑border data transfer controls
  • Ability to work with engineering teams on privacy‑by‑design implementations.

Vulnerability & Risk Management

  • Familiarity with:
    • Vulnerability management lifecycle
    • Secure configuration baselines
    • Risk acceptance, compensating controls, and technical debt
  • Ability to assess real‑world risk rather than checklist compliance.

Incident Response & Monitoring

  • Knowledge of incident response processes, including:
    • Detection, containment, and post‑incident reviews
    • Regulatory and contractual notification requirements
  • Ability to validate IR plans against ISO and regulatory expectations.

AI & Emerging Technology Risk

  • Understanding of AI‑related security and governance risks:
    • Training data integrity
    • Model lifecycle and access control
    • Bias, explainability, and accountability considerations
  • Exposure to AI‑enabled security and compliance tools preferred.

Industry‑Specific Skills

Defense / Government Contractors

  • CMMC L1–L3 and NIST SP 800‑171 technical control interpretation
  • CUI protection, enclave design, boundary controls
  • Vendor and subcontractor security assurance
  • DFARS‑aligned audit and evidence readiness

Semiconductor / Hardware & Manufacturing

  • Protection of design IP, fabrication data, and production systems
  • Supplier and foundry security risk assessments
  • Alignment of cyber, physical, and operational security controls
  • Global compliance and data localization considerations

SaaS / Cloud‑Native

  • Cloud‑native ISMS design
  • Secure SDLC and CI/CD risk governance
  • Customer audits, security questionnaires, trust signals
  • AI feature governance and responsible data usage

Qualifications:

Required Qualifications

  • 7–12+ years of experience in GRC, security, privacy, or risk management.
  • Proven ownership of ISO 27001, GDPR/CCPA, and CMMC or NIST 800‑171 programs.
  • Strong technical and regulatory interpretation skills.
  • Ability to operate independently at senior or principal IC level.

Preferred Certifications & Experience

  • ISO 27001 Lead Implementer / Lead Auditor
  • CISSP, CISA, CRISC
  • CIPM, CIPP/US, CIPP/E
  • Experience with Microsoft security and compliance platforms (Purview, Defender, Entra ID) or equivalent
  • Exposure to AI governance frameworks, tools, or regulations

Role Leveling Expectations

Senior GRC Analyst

  • Leads major compliance initiatives
  • Acts as SME for key frameworks
  • Partners closely with security and engineering
  • Defines enterprise GRC strategy and architecture
  • Advises executives on material cyber and regulatory risk
  • Shapes AI governance and future compliance roadmaps
  • Mentors and raises overall GRC maturity

Job Type:

Regular

Shift:

Primary Location:

Bengaluru, Karnataka, India

Additional Locations:

Posting Statement:

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.

Skills

AWSAzureGCPCI/CDCybersecurityRisk ManagementComplianceGDPRISO 27001CISSP

Similar Jobs

30

Senior | Principal

Count & Cooper

6 months ago

Senior Principal

Scimitar Inc. · US · Remote

1+ year ago

Senior Principal Consultant

Apps Associates · United States, US

Today

Senior Mining Geotechnical Engineer/ Ingénieur géotechnique minier principal

Arcadis · Vancouver, BC,CA, CA +5

Today

Senior Mining Geotechnical Engineer/ Ingénieur géotechnique minier principal

Arcadis · Vancouver, BC, Canada · Hybrid

Today

Sr./Principal Technical Services Project Management (Level 3 or 4)

Northrop Grumman · Corinne, UT,US, US +2 · Onsite

Yesterday

Sr./Principal Technical Services Project Management (Level 3 or 4)

Northrop Grumman · UTCO11, United States of America +2 · Onsite

Yesterday

System Engineer Sr Principal

GDIT · USA MD Fort Meade - 6912 Cooper Ave (MDC119), United States of America · Remote, Hybrid, Onsite

Yesterday

Information Security Analyst Sr Principal - Cloud - Hybrid

GDIT · USA MD Fort Meade - 6912 Cooper Ave (MDC119), United States of America

Yesterday

Sr. Principal Engineer, Tech Transfer

Neurocrine · US CA San Diego, United States of America · Onsite

2 days ago

Senior Principal Strategic Planner

GDIT · USA FL MacDill AFB - 7701 Tampa Point Blvd (FLC097), United States of America

2 days ago

Cyber Systems Integration Engineer Sr Principal

GDIT · USA VA Home Office (VAHOME), United States of America · Remote

2 days ago

Senior Principal Systems Engineer – SOA CAAS Mainline Platform (Onsite)

RTX · US-IA-CEDAR RAPIDS-182 ~ 1100 Cimmie Ave Ne ~ BLDG 182, United States of America · Onsite

2 days ago

Senior Principal Strategic Planner

Gdit · USA FL MacDill AFB - 7701 Tampa Point Blvd (FLC097), United States of America

2 days ago

Cyber Systems Integration Engineer Sr Principal

Gdit · USA VA Home Office (VAHOME), United States of America · Remote

2 days ago

Senior Principal Contaminated Sites Engineer or Geoscientist

WSP · Terrace, BC, Canada

2 days ago

Senior / Principal Consultant (Transformation Advisory)

WSP · London, London, United Kingdom, GB

2 days ago

Managing Partner, Strategic Customer Team (Sr Principal)

UKG · US · Remote

2 days ago

Principal/Senior Software Engineer, Fullstack/Backend Technologies (Poland Remote)

" Turnitin, LLC" · Warsaw, Masovian Voivodeship, Poland · Remote

2 days ago

Sr/Lead/Principal Fundamentals Analyst - Midwest

EQT Corporation · Remote · Remote

2 days ago

Senior/Principal Golang Developer

Sigma Software · Warsaw, Masovian Voivodeship, Poland · Remote

3 days ago

Senior / Principal Engineer, NAND Product Engineering

Micron Technology · SG

3 days ago

Sr. Principal Reliability Engineer

Medtronic · USA-MN Mounds View South, United States of America +1 · Onsite

3 days ago

Sr Principal Engineering Program Manager

Formfactor · USA - Livermore, United States of America

3 days ago

Senior or Principal Technical Product Manager

Prescryptive · Remote - US - All, United States of America +51 · Remote

3 days ago

Sr Principal Quality Engineer

Northrop Grumman · MDLI03, United States of America

3 days ago

Sentinel - Sr Principal Mechanical Engineer (19687)

Northrop Grumman · UTRO04, United States of America · Onsite

3 days ago

Sr Principal Engineer Mission Assurance

Northrop Grumman · CASU21, United States of America · Remote, Hybrid, Onsite

3 days ago

Ingénieur principal sénior/ Senior Principal Engineer

HiNext · (HE)Office_QC, Varennes, Canada · Onsite

3 days ago

Chef de projet principal - BTM I&C / Senior Project Manager - BTM I&C

gevernova · Remote, United States of America +3 · Remote

3 days ago