← Back to results

GRC Principal - Data Privacy and Security

Lead Wrapbook's privacy and security GRC programs as a Principal GRC Manager in a fully remote role.

Location
Remote - US & Canada
Compensation
Not disclosed
Level
principal
Type
full time · Remote

Posted by employer 1 week ago

First seen on Joblaze 1 week ago

Last verified on the company career page 1 day ago

Apply at Wrapbook → Save job Scanned from wrapbook.com

AI in the day-to-day

You have a proven track record of building AI-first solutions for traditional GRC problems; you leverage AI to amplify your output.

Requirements

Experience
10+ years

Not disclosed in this posting: compensation, visa sponsorship.

Benefits

401k Match Education Budget Unlimited PTO Remote Work Health Insurance

Joblaze summary

The GRC Principal for Data Privacy and Security at Wrapbook is responsible for leading the company's governance, risk, and compliance initiatives, particularly focusing on data security and privacy frameworks. This role requires extensive experience in building and managing GRC programs, especially within fintech or SaaS environments, and a strong understanding of regulatory requirements like GDPR and SOC audits. Ideal candidates will have a proven track record of leveraging AI to enhance compliance processes and will thrive in a high-autonomy setting that demands strategic thinking and cross-functional collaboration.

Joblaze insights

Quick facts

Is the GRC Principal - Data Privacy and Security role remote?
Yes — Wrapbook lists this as a fully remote position.
How much experience is required?
At least 10 years of relevant experience for this GRC Principal - Data Privacy and Security role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, CCPA, Data Privacy, Data Security, GDPR, GRC.
What seniority level is this role?
Wrapbook targets principal-level candidates for this position.
Is this full-time or contract?
Full-time for this GRC Principal - Data Privacy and Security role at Wrapbook.

From the original posting

About Us:

Wrapbook is the AI platform for production finance. We’re building a system of action that puts finance teams in control of their whole production, from payroll, to spend, to accounting.

Built for feature films, TV, and commercials, Wrapbook is trusted by teams at Netflix, Paramount, Anonymous Content, and more. With backing from Andreessen Horowitz, Bessemer Venture Partners, and Jeffrey Katzenberg's WndrCo, our team of 350+ is using AI to transform how finance teams work and empower them to do more with less.

The Opportunity – GRC Principal - Data Privacy and Security (Remote - USA / CANADA):

We're hiring a Principal GRC Manager (Individual Contributor) to serve as a subject matter expert and technical authority leading Wrapbook's privacy and security GRC programs. This is a high-ambiguity, high-autonomy role for someone who has built and matured GRC programs at a fintech or SaaS company from the ground up. This person will not just maintain grc activities, but bring a strong point of view to set the multi-year direction for how Wrapbook manages GRC investment on the security and privacy front as our AI capabilities expand. This person is both excited to drive the strategic direction and own the ground-level execution across their areas, leveraging AI to amplify their output. You understand the difference between checking boxes and high judgment decisions, you focus on outcomes over activity. You cleanly separate the must-dos and the nice-to-haves informed by a business’ risk appetite, industry context, and overall company objectives.

You have a proven track record of building AI-first solutions for traditional GRC problems; you have the expertise and experience to validate AI outputs. You thrive on systems-thinking and delivering measurable results with rigor; you’ll own the project management, frameworks, measurement, outward and upward reporting, influence executives and leaders. You’ll evolve a program that passes SOC 1 and SOC 2 Type II audits, moving it from "successful audits" to durable, continuously audit-ready operational maturity. You are a bridge-builder, you know how to develop, grow, and leverage strong relationships and trust with cross-functional stakeholders and leadership.

What You'll Do:

Data Security GRC

  • Lead the annual SOC 1 and 2 audit lifecycle end-to-end: control monitoring/readiness, work with our SOC auditors and internal business teams to complete the audit project and reporting supporting evidence collection and clarification process, drive control-owner accountability and lead program development to embed continuous, evidence-driven controls.

  • Own and evolve Wrapbook's ISMS policy suite and control framework (SOC 1, SOC 2 Type II; explore additional ISO compliance opportunities) in collaboration with our Business, Legal, and Security teams.

  • Mature our approach to vendor risk management, developing and evolving the program, frameworks, prioritization, stakeholder management, and measurement.

  • Lead Customer Assurance efforts for enterprise security reviews (e.g., enterprise customer and prospect review requirements, cyber-insurance self-assessments) and scale Wrapbook's security and privacy documentation and mechanisms.

Data Privacy GRC

  • Collaborate with Legal and Security teams to build and evolve Wrapbook’s Data Governance program across the data lifecycle (data collection, storage, access, retention, deletion).

  • Beyond project management you will make recommendations and own decisions on how to best solve Wrapbook’s dynamic and growing data governance challenges.

  • Build and evolve the privacy compliance program across GDPR and CCPA — DSAR operations, data mapping, retention, and the data governance and classification program.

  • Partner with Legal on DPAs, subprocessor obligations, and privacy-by-design in product.

  • Help shape Wrapbook's enterprise AI data governance framework in collaboration with our Security and Legal leadership/org— policies, standards, and controls across the AI/ML lifecycle for both internally built and procured AI.

  • Track the evolving regulatory and framework landscape (e.g., NIST AI RMF, ISO 42001, EU AI Act) and translate it into Wrapbook’s needs.

Cross-functional leadership

  • Executive fluency and credibility. Translates technical and regulatory risk into business terms leadership can act on, and holds their own in front of executives, auditors, and enterprise customers. Trusted to represent Wrapbook's risk posture externally.

  • Serve as the subject-matter authority and trusted advisor on Security and Privacy governance and compliance topics.

  • Mentor cross-functional partners and team members and set the standard for the discipline across the org.

What We're Looking For:

  • 10+ years in GRC, information security and privacy compliance with a track record of building, scaling, and operating highly rigorous programs — ideally at a fintech, start-up, or payments organization.

  • You have the highest integrity and discretion. ****Customer trust is paramount at Wrapbook and this role will interact with highly sensitive data, owning difficult risk trade-offs with sound ethics and confidentiality.

  • Project management is second nature, you effectively establish, track, measure and communicate/report out on cross-functional program progress, prioritization decisions/trade-offs, risks, and impact.

  • Proven experience leveraging AI to automate GRC workload and force-multiply GRC programs to measurable outcomes.

  • Deep, hands-on expertise across security (SOC 2 / ISO 27001 / PCI DSS), privacy (GDPR / CCPA, DSAR operations, data governance) compliance.

  • Working fluency in AI/ML governance and the current regulatory landscape. You are comfortable with setting policy where standards are still forming.

  • Demonstrated ownership of SOC audit lifecycles and enterprise risk and third-party risk programs.

  • Exceptional cross-functional influence — able to move executives and technical teams without direct authority.

  • Relevant certifications a plus: CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP.


Why Join Us

At Wrapbook, creativity meets technology — and not just in the product.

In addition to a competitive salary and all the benefits you can expect from a fast-growing technology company, you’ll get access to a team of creative problem solvers and the chance to see your contributions make large impacts. Benefits include:

  • Unlimited Paid Time Off

  • Work from anywhere in Canada and USA

  • Health and Dental benefits

  • Up to $1,500 USD/ $2,025 CAD towards IT set up for your home

  • Up to 2% matching RRSP / 401K

  • Learning and Development opportunities

  • Up to $50 USD/ $67.50 CAD towards Internet/Cell phone service

Our Pledge to Fostering an Inclusive and Safe Workplace:

Wrapbook pledges to be a harassment- and discrimination-free space for everyone, regardless of age, disability, ethnicity, gender identity or expression, nationality, neurotype, personal appearance, political affiliation, professional background, race, religion, or sexual identity or orientation.

Apply Now

Have we got your attention? Submit your application today and a member of our Talent team will be in touch with you shortly!

#LI-Remote

Similar positions

Wrapbook
Senior Software Engineer II, Business Systems
Wrapbook · Remote - US & Canada
Wrapbook
Manager, Engineering - Frontend
Wrapbook · Remote - US & Canada
Wrapbook
Director, Product Operations
Wrapbook · Remote - US & Canada