Principal Governance, Risk and Compliance (GRC) Architect
Design security controls for AWS infrastructure
Implement and maintain security certifications like SOC 2, TISAX, ITAR, and FedRAMP. Ensure compliance with international standards while supporting a fast-paced software company. The role involves designing and implementing controls, managing technical infrastructure, and leading global expansion.
Why This Role?
Directly impact the company's security posture and work with demanding organizations
Key Responsibilities
- Maintain continuous observation for SOC 2 Type II compliance
- Develop technical infrastructure strategy for ITAR and FedRAMP
- Implement controls for change management and access reviews
- Lead global expansion for TISAX, ITAR, and FedRAMP implementation
- Act as internal authority on privacy and data mapping
Requirements
- Technical AWS depth, including GovCloud and IAM architecture
- Expert-level knowledge of at least two standards: TISAX, ITAR, or FedRAMP
- Experience with network security, encryption, and compliance
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
Keywords
View Original Description from Arbeitnow
Original description from Arbeitnow
The Role: The Bridge Between Rigor and Velocity We are looking for a Principal GRC Architect who can solve a unique challenge: How do we maintain "gold-standard" security certifications without killing our "ship-fast" culture? We are already under continuous observation for SOC 2 Type II and are GDPR compliant . We are now ready to evolve toward the most rigorous standards in the industry: TISAX, ITAR, and FedRAMP . This is a hands-on, individual contributor role. You will be the architect of the system and the person turning the gears, designing the roadmap and then personally implementing the controls. Your mission is to reconcile the rigidity of international standards with the agility of a fast-paced software company. You aren't here to create bureaucracy; you’re here to engineer compliance directly into our AWS infrastructure . Core Responsibilities Maintain Continuous Observation: Uphold our SOC 2 Type II standard using automated monitoring to ensure compliance is a constant state, not an annual event. Technical Infrastructure Strategy: Directly satisfy the high-bar technical requirements of ITAR and FedRAMP . This includes managing the transition to/oversight of AWS GovCloud , defining network security boundaries, and ensuring encryption and IAM standards meet federal requirements. Bridge the "Speed vs. Standard" Gap: Act as a technical enabler for the Engineering team, designing and implementing controls (e.g., change management, access reviews) that satisfy auditors but don’t bottleneck our Engineering or DevOps teams. Lead Global Expansion: Architect and execute the technical and procedural implementation of TISAX, ITAR, and FedRAMP . GDPR Stewardship: Act as the internal authority on privacy, ensuring our data mapping and PIAs remain current without adding unnecessary friction. Customer Trust & Sales Support: Join calls with customer Infosec counterparts and handle technical vendor questionnaires to prove our security posture can be trusted by the world’s most demanding organizations. Individual Contributor Ownership: Act as a "department of one". You will write the policies, perform the risk assessments, and manage the audits yourself. What You Bring Technical AWS Depth: You understand how to configure AWS beyond simple evidence collection. You are familiar with GovCloud, VPC isolation, network security, and IAM architecture. Standard Mastery: Expert-level knowledge in at least two of: TISAX, ITAR, or FedRAMP. You have previously led a company through these audits or were responsible for maintaining their compliance. Privacy & AI Knowledge: A deep, working knowledge of GDPR and an active interest in the evolving landscape of AI regulation. The "Translator" Skillset: You can translate rigid regulatory requirements into actionable technical tasks that make sense to a developer. Independence: You are energized by "getting your hands dirty" and owning the full lifecycle of a program without a team to delegate to. Communication: Exceptional English skills; able to negotiate effectively with both internal engineers and external auditors. What you can expect from us A direct seat at the table: full ownership of the compliance and GRC roadmap. Your work directly enables our largest enterprise and government deals: measurable, visible business impact. Enjoy flexible hours and the freedom to work remotely from anywhere in the world. Access comprehensive health coverage, retirement plans, paid time off, and wellness support. Stay active with subsidized gym memberships, sports meetups, and wellness programs. Grow as a professional with online/offline learning, language courses, and tech talks. Connect at team events, join support groups, and contribute to our ESG and DE&I initiatives. Participate in fun team challenges and competitions for added excitement and team spirit. Multicultural team (35+ nationalities), flexible work, relocation and visa support where applicable. Diversity, Equity and Inclusion at SimScale At SimScale
Salary Context
Similar Engineering roles on LokerDollar pay around $215k/yr (range $19.575k–2745.996k/yr, n=426 active listings).
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Frequently asked questions
- Is Principal Governance, Risk and Compliance (GRC) Architect at SimScale GmbH a remote job?
- Yes. Principal Governance, Risk and Compliance (GRC) Architect at SimScale GmbH is a fully remote role open to candidates worldwide.
- What type of employment is Principal Governance, Risk and Compliance (GRC) Architect at SimScale GmbH?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at SimScale GmbH.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- AI Job Trends in June 2026Analysis of seven latest AI jobs on Loker Dollar: OpenAI, Mistral AI, Spotify, and others with competition and application strategies.
- Top Remote USD Jobs: July 2026 Global EditionDiscover the latest USD-paying remote jobs for engineers, designers, and operators worldwide in July 2026. Salary insights and application tips included!
- 10 Remote Jobs Nobody Wants (Yet!)Are there remote openings with few applicants? We'll show you 10 high-demand, low-supply positions – and why your skills might be a perfect fit.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume