Jobs and Careers
GO

Principal Security Engineer - GRC

GoDaddy
United States, United StatesRemotefull_timeVerifiedPosted 27 Feb 2025

About the role

Location Details: 

At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.

This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings.  

This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands.

GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC.

Join our team...

Do you want to be an Information Security Leader at GoDaddy? We help solve large-scale and cross-company issues while ensuring that partnership with the development and operational communities remain front of mind. GoDaddy is looking for a Principal Risk Engineer with security risk management experience, technical depth, strong leadership abilities, and experience building and performing information security audits and gap assessments. You must be comfortable communicating with internal teams and external auditors, designing and leading security campaigns, and prioritizing the resolution of audit findings while applying a risk-based approach. As a team, we will help identify any gaps in security control implementation, design solutions to manage security risks at scale, and provide the information needed to make risk-based decisions and planning 

 

What you'll get to do...

  • Build and manage a Security Controls framework that encompasses the regulatory and industry compliance frameworks we comply with. 
  • Perform targeted gap assessments to identify any deviations from the control framework. 
  • Propose and manage enterprise-wide security campaigns for managing deviations to reduce risk. 
  • Partner with other InfoSec teams and Engineering teams to define and prioritize security initiatives and investments using a risk-based approach. 
  • Align risk management initiatives with applicable compliance regulations. 

Your experience should include...

  • 10+ years of experience in Information Security or related fields such as Information Technology, IT Audit, etc. 
  • 6+ years of progressive experience managing programs related to information security and information security audits. 
  • Experience building unified security controls frameworks. 
  • Experience managing audits utilizing compliance frameworks such as PCI DSS, NIST  CSF, NIST 800-53, ISO, SOC-2 etc. 
  • Executive reporting on the status of security programs and campaigns. 
  • Experience in Security Engineering concepts such as Threat modeling, architecture reviews, etc. 
  • Experience with auditing cloud infrastructure such as AWS.  

You might also have...

  • Bachelor’s degree in computer science or related field.
  • Certifications such as PCI ISA, CISA, CRISC, ISO Lead Assessor, CISSP, etc.
  • Experience working at a Big 4 Audit firm(s)

 

We've got your back...  We offer a range of total rewards that may include paid time off, retirement savings (e.g., 401k, pension schemes), bonus/incentive eligibility, equity grants, participation in our employee stock purchase plan, competitive health benefits, and other family-friendly benefits including parental leave. GoDaddy’s benefits vary based on individual role and location and can be reviewed in more detail during the interview process.

We also embrace our diverse culture and offer a range of Employee Resource Groups (Culture). Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way. 

About us...  G

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GoDaddy

View company profile →