Principal Governance, Risk and Compliance (GRC) Architect
Bangun sistem keamanan AWS yang memenuhi standar internasional
Anda akan merancang dan menerapkan kontrol keamanan di infrastruktur AWS untuk memenuhi standar TISAX, ITAR, dan FedRAMP. Anda akan memastikan kompliansi terus-menerus untuk SOC 2 Type II dan GDPR, serta menjadi penasihat keamanan untuk tim Engineering dan DevOps.
Kenapa Menarik?
Anda akan bekerja di perusahaan yang memprioritaskan kecepatan dan keamanan, dengan kesempatan untuk mempengaruhi kebijakan keamanan secara global.
Tanggung Jawab Utama
- Mempertahankan standar SOC 2 Type II dengan pemantauan otomatis
- Menyusun strategi infrastruktur teknis untuk memenuhi persyaratan ITAR dan FedRAMP
- Merancang dan menerapkan kontrol keamanan yang tidak menghambat tim Engineering dan DevOps
- Mengarahkan ekspansi global dengan implementasi TISAX, ITAR, dan FedRAMP
- Menjadi penasihat internal untuk GDPR dan memastikan pemetaan data tetap aktual
Persyaratan
- Pengalaman mendalam dalam konfigurasi AWS, termasuk GovCloud dan IAM
- Pemahaman ekspert dalam setidaknya dua standar: TISAX, ITAR, atau FedRAMP
- Kemampuan untuk merancang dan menerapkan kontrol keamanan secara mandiri
Skills Wajib
Konteks Indonesia
- Overlap Jam Kerja:
- Fleksibel — atur jam kerjamu sendiri
Keywords
Lihat Deskripsi Asli dari Arbeitnow
Deskripsi asli dari Arbeitnow
The Role: The Bridge Between Rigor and Velocity We are looking for a Principal GRC Architect who can solve a unique challenge: How do we maintain "gold-standard" security certifications without killing our "ship-fast" culture? We are already under continuous observation for SOC 2 Type II and are GDPR compliant . We are now ready to evolve toward the most rigorous standards in the industry: TISAX, ITAR, and FedRAMP . This is a hands-on, individual contributor role. You will be the architect of the system and the person turning the gears, designing the roadmap and then personally implementing the controls. Your mission is to reconcile the rigidity of international standards with the agility of a fast-paced software company. You aren't here to create bureaucracy; you’re here to engineer compliance directly into our AWS infrastructure . Core Responsibilities Maintain Continuous Observation: Uphold our SOC 2 Type II standard using automated monitoring to ensure compliance is a constant state, not an annual event. Technical Infrastructure Strategy: Directly satisfy the high-bar technical requirements of ITAR and FedRAMP . This includes managing the transition to/oversight of AWS GovCloud , defining network security boundaries, and ensuring encryption and IAM standards meet federal requirements. Bridge the "Speed vs. Standard" Gap: Act as a technical enabler for the Engineering team, designing and implementing controls (e.g., change management, access reviews) that satisfy auditors but don’t bottleneck our Engineering or DevOps teams. Lead Global Expansion: Architect and execute the technical and procedural implementation of TISAX, ITAR, and FedRAMP . GDPR Stewardship: Act as the internal authority on privacy, ensuring our data mapping and PIAs remain current without adding unnecessary friction. Customer Trust & Sales Support: Join calls with customer Infosec counterparts and handle technical vendor questionnaires to prove our security posture can be trusted by the world’s most demanding organizations. Individual Contributor Ownership: Act as a "department of one". You will write the policies, perform the risk assessments, and manage the audits yourself. What You Bring Technical AWS Depth: You understand how to configure AWS beyond simple evidence collection. You are familiar with GovCloud, VPC isolation, network security, and IAM architecture. Standard Mastery: Expert-level knowledge in at least two of: TISAX, ITAR, or FedRAMP. You have previously led a company through these audits or were responsible for maintaining their compliance. Privacy & AI Knowledge: A deep, working knowledge of GDPR and an active interest in the evolving landscape of AI regulation. The "Translator" Skillset: You can translate rigid regulatory requirements into actionable technical tasks that make sense to a developer. Independence: You are energized by "getting your hands dirty" and owning the full lifecycle of a program without a team to delegate to. Communication: Exceptional English skills; able to negotiate effectively with both internal engineers and external auditors. What you can expect from us A direct seat at the table: full ownership of the compliance and GRC roadmap. Your work directly enables our largest enterprise and government deals: measurable, visible business impact. Enjoy flexible hours and the freedom to work remotely from anywhere in the world. Access comprehensive health coverage, retirement plans, paid time off, and wellness support. Stay active with subsidized gym memberships, sports meetups, and wellness programs. Grow as a professional with online/offline learning, language courses, and tech talks. Connect at team events, join support groups, and contribute to our ESG and DE&I initiatives. Participate in fun team challenges and competitions for added excitement and team spirit. Multicultural team (35+ nationalities), flexible work, relocation and visa support where applicable. Diversity, Equity and Inclusion at SimScale At SimScale
Konteks Gaji
Posisi Engineering serupa di LokerDollar dibayar sekitar $215k/yr (kisaran $19.575k–2745.996k/yr, dari 426 listing aktif).
Akun gratis · tanpa kartu kredit · Masuk
Pro Rp39rb/bln · lamar tanpa batas + resume AI
Pertanyaan yang sering diajukan
- Apakah Principal Governance, Risk and Compliance (GRC) Architect di SimScale GmbH bisa dikerjakan remote?
- Ya. Principal Governance, Risk and Compliance (GRC) Architect di SimScale GmbH adalah posisi remote yang terbuka untuk kandidat di seluruh dunia.
- Jenis pekerjaan apa Principal Governance, Risk and Compliance (GRC) Architect di SimScale GmbH?
- Posisi ini adalah pekerjaan full time.
- Bagaimana cara melamar?
- Klik tombol "Lamar" pada halaman ini untuk menuju halaman aplikasi resmi SimScale GmbH.
Jelajahi lebih lanjut
Data & laporan pasar
Riset gaji & permintaan skill dari data lowongan kami sendiri.
- Lowongan IT Indonesia vs Remote Global (2026)Analisis data primer 2.049 lowongan: metodologi, klasifikasi, dataset bisa diunduh.
- Permintaan Skill AI: Indonesia vs Global (2026)10.000+ lowongan, classifier taxonomy-first, Wilson CI, pra-registrasi sebelum analisis.
- Laporan Hiring Indonesia: Tech vs Non-TechPermintaan lowongan per bidang dari hitungan agregat — bukan listing per-listing.
- Benchmark Gaji IndonesiaKisaran gaji agregat lintas peran, dengan metodologi dan dataset terbuka.
- Indeks Gaji & Permintaan Kerja Remote untuk IndonesiaBerapa banyak lowongan remote global yang terbuka untuk Indonesia, dan gajinya (USD) per bidang.
- Laporan Kuartalan Pasar Kerja IndonesiaPHK, pendanaan, gaji & skill per kuartal — agregat terbuka.
- Laporan Pasar Remote per PeranLaporan otomatis per kelompok peran — skill, senioritas, perusahaan, gaji.
- Benchmark Gaji Remote GlobalGaji tahunan per bidang & mata uang, plus porsi lowongan terbuka untuk seluruh dunia.
Dari blog kami
- Tren Lowongan AI Juni 2026Analisis tujuh lowongan AI terbaru di Loker Dollar: OpenAI, Mistral AI, Spotify, dan lainnya dengan persaingan dan strategi apply.
- Loker Remote Juli 2026Temukan lowongan kerja remote USD terbaru di Juli 2026 untuk developer, desainer, dan profesional lainnya. Gaji dan tips apply!
- 10 Remote Jobs Nobody Wants (Yet!)Ada lowongan remote yang sepi pelamar? Kami tunjukkan 10 posisi yang permintaannya tinggi, tapi pasokannya minim – dan kenapa skill-mu mungkin cocok.
Akun gratis · tanpa kartu kredit · Masuk
Pro Rp39rb/bln · lamar tanpa batas + resume AI