SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Rescale is a digital engineering platform pioneering the future of product development through intelligent automation, applied AI, and data management. The company serves aerospace, energy, life sciences, and manufacturing industries with cloud-based HPC and simulation capabilities.
As Principal Security GRC Analyst, you will be a senior individual contributor driving the maturation of Rescale's multi-framework compliance program spanning FedRAMP Moderate, DoD IL5, CMMC Level 2, SOC 2 Type 2, ISO 27001:2022, TISAX AL2, and Facility Clearance License (FCL) requirements. This is a high-autonomy role where you own complex compliance problems end-to-end—from control design through evidence collection to auditor engagement.
Key responsibilities include:
- Work under the Director of Compliance to mature the comprehensive security governance, risk, and compliance program
- Engage directly with auditors and government officials across NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, and CSA frameworks
- Own and drive large multi-month and multi-quarter projects ensuring Rescale's compliance with chosen frameworks
- Collaborate with security, IT, engineering, product, and platform teams to gather audit evidence and translate compliance requirements into practical, implementable controls
- Represent the compliance program in customer-facing discussions, security questionnaires, and due diligence reviews
- Draft policies and procedures that improve compliance and privacy
- Create and manage automated processes for disseminating policies, procedures, and security knowledge
- Leverage AI to enable products to comply with new and existing frameworks
Required qualifications:
- 8+ years of experience with multiple compliance frameworks and audits, managing complex implementation projects
- Deep expertise in at least one security framework (SOC2 Type II, ISO 27001, FedRAMP, or NIST SP 800 series)
- Exposure to additional frameworks including GDPR, ITAR, EAR, NISPOM, CMMC
- US Citizenship required
Preferred qualifications include certifications such as CISM, GSLC, Security+CE, or CISSP.