SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal Security GRC Analyst

Rescale - Remote - Remote - posted 2026-08-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Rescale is a digital engineering platform pioneering the future of product development through intelligent automation, applied AI, and data management. The company serves aerospace, energy, life sciences, and manufacturing industries with cloud-based HPC and simulation capabilities. As Principal Security GRC Analyst, you will be a senior individual contributor driving the maturation of Rescale's multi-framework compliance program spanning FedRAMP Moderate, DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX AL2, and Facility Clearance License (FCL) requirements. This is a high-autonomy role where you own complex compliance problems end-to-end—from control design through evidence collection to auditor engagement. Key responsibilities include: - Work under the Director of Compliance to mature the comprehensive security governance, risk, and compliance program - Engage directly with auditors and government officials across NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, and CSA frameworks - Own and drive large multi-month and multi-quarter projects ensuring Rescale's compliance with chosen frameworks - Collaborate with security, IT, engineering, product, and platform teams to gather audit evidence and translate compliance requirements into practical, implementable controls - Represent the compliance program in customer-facing discussions, security questionnaires, and due diligence reviews - Draft policies and procedures that improve compliance and privacy - Create and manage automated processes for disseminating policies, procedures, and security knowledge - Leverage AI to enable products to comply with new and existing frameworks Required qualifications: - 8+ years of experience with multiple compliance frameworks and audits, managing complex implementation projects - Deep expertise in at least one security framework (SOC2 Type II, ISO 27001, FedRAMP, or NIST SP 800 series) - Exposure to additional frameworks including GDPR, ITAR, EAR, NISPOM, CMMC - US Citizenship required Preferred qualifications include certifications such as CISM, GSLC, Security+CE, or CISSP.

Similar roles