Jobs and Careers
IN

Sr Principal, Governance, Risk, and Compliance Specialist

Ingram Micro
United Statesfull_timeVerifiedPosted 15 May 2025
💰 $258,700/yr($152,200/yr$258,700/yr)

About the role

Accelerate your career. Join the organization that's driving the world's technology and shape the future. 

Ingram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to business-to-business technology experts. Our market reach, diverse solutions and services portfolio, and digital platform Ingram Micro Xvantage™ set us apart. Learn more at www.ingrammicro.com

Come join our team where you’ll make technology happen in surprising ways. Let’s shape tomorrow - it’ll be a fun journey!

Summary:

Ingram Micro is looking for a Sr Principal consultant for the Governance, Risk, and Compliance (GRC) organization. This position is responsible for creating and maintaining a cybersecurity governance framework, managing risk through an enterprise risk register, tracking remediation for identified risk, and creating and maintaining an effective third-party risk management program (planning, due diligence, contract, transition, on-going monitoring, and exit). The position will also be responsible for performing compliance reviews, developing detail audit/compliance programs, executing audit/compliance programs steps, analyzing results and communicating results to the senior management.

This position will work closely with business leaders and managers to ensure awareness and understanding of third-party risk program requirements and associated risk within their portfolios.

The ideal candidate will have a background in contract language, contract management, vendor management, vendor negotiations, risk management, and internal audit.

The role:

  • Develop, implement, and maintain cybersecurity governance frameworks, policies, and procedures.
  • Lead the enterprise risk management process, including maintaining the risk register, facilitating risk assessments, and tracking remediation efforts
  • Design and manage an effective Third-Party Risk Management (TPRM) program, including due diligence, contracting, onboarding, monitoring, and offboarding.
  • Conduct compliance and audit reviews in accordance with regulatory frameworks such as SOX, SOC 1, SOC 2, NIST CSF, PCI DSS/PIN/P2PE, ISO 27001, and SWIFT.
  • Develop audit and compliance testing procedures and communicate findings and recommendations to senior management.
  • Collaborate with legal, procurement, IT, and business leaders to ensure awareness and understanding of risk program requirements and responsibilities.
  • Complete required PCI-related training and serves as the subject matter expert (SME) for PCI DSS/PIN/P2PE, advising stakeholders on compliance strategies, risks, and security best practices.
  • Provide expert guidance on vendor contracts, contract language, and risk-related clauses to minimize exposure.
  • Monitor changes in the regulatory environment and recommend updates to compliance and risk strategies accordingly.
  • Support the execution of internal and external audits, including preparation, evidence gathering, and remediation follow-up.

What you bring to the role:

  • Possesses a highly specialized level of technical expertise or business acumen. Extensive breadth and depth of knowledge arrived through exposure to emerging technical advancements or complex business situations.
  • 4 Year College Degree in a related field (Management Information Systems, Computer Science, Business Management, Finance, Engineering, etc.) required
  • Minimum 10 years functional experience including a minimum of 7 years relevant work experience in information security, risk management, internal IT audit, technical writing, or information security governance
  • Demonstrated knowledge and experience with PCI compliance requirements and implementation. Current PCI-QSA certification preferred (will consider former QSA)
  • Experienced in applying and interpreting various IT audit and compliance frameworks, including but not limited to SOX, SOC 1, SOC 2, ISO 27001, PCI DSS, FedRAMP, and HITRUST HITRUST
  • Proven ability to develop and execute audit and compliance programs.
  • Experience with third-party risk management, contract reviews, and vendor risk assessments.
  • Technical leader with an understanding of cloud technologies, API systems, infrastructure, network, and mobile security.
  • Ability to work in complex environments effectively, independently, and collaboratively within a team environment.
  • Relevant certifications such as CISA, CFE, CISSP, CRISC, or CIA are a plus.

The ideal candidate

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Ingram Micro

View company profile →