Godaddy
Principal Security Engineer - GRC
Company
Role
Principal Security Engineer - GRC
Location
Job type
-
Posted
2 days ago
Salary
Job description
Location Details:
At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.
This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings.
This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands.
GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC.
Join our team
Do you want to be an Information Security Leader at GoDaddy? We help solve large-scale and cross-company issues while ensuring that partnership with the development and operational communities remain front of mind.
GoDaddy is looking for a Principal Risk Engineer with security risk management experience, technical depth, strong leadership abilities, and experience building and performing information security audits and gap assessments. You must be comfortable communicating with internal teams and external auditors, designing and leading security campaigns, and prioritizing the resolution of audit findings while applying a risk-based approach. As a team, we will help identify any gaps in security control implementation, design solutions to manage security risks at scale, and provide the information needed to make risk-based decisions and planning.
What you'll get to do...
- Build and manage a Security Controls framework that encompasses the regulatory and industry compliance frameworks we follow
- Perform targeted gap assessments to identify any deviations from the control framework
- Propose and manage enterprise-wide security campaigns for managing deviations to reduce risk
- Partner with other InfoSec teams and Engineering teams to define and prioritize security initiatives and investments guided by risk assessment principles
- Align risk management initiatives with applicable compliance regulations
Your experience should include...
- 10+ years of professional experience in Information Security or related fields such as Information Technology, IT Audit, etc.
- 6+ years of dynamic experience managing programs related to information security and information security audits
- Experience building unified security controls frameworks
- Experience managing audits applying compliance frameworks such as PCI DSS, NIST CSF, NIST 800-53, ISO, SOC-2 etc.
- Executive reporting on the status of security programs and campaigns
- Experience in Security Engineering concepts such as Threat modeling and architecture reviews
- Experience with auditing cloud infrastructure such as AWS
You might also have...
- A bachelor’s degree in computer science or related field
- Certifications like PCI ISA, CISA, CRISC, ISO Lead Assessor, CISSP, etc.
- Experience working at a Big 4 Audit firm(s)
We encourage you to apply even if your experience or skillset doesn’t align perfectly with every requirement. We value a wide range of backgrounds and transferable skills, and we are excited to support learning and growth.
About us... GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. GoDaddy is the place people come to name their idea, build a professional website, attract customers, sell their products and services, and manage their work. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. To learn more about the company, visit About Us.
At GoDaddy, we know diverse teams build better products—period. Our people and culture reflect and celebrate that sense of diversity and inclusion in ideas, experiences and perspectives. But we also know that’s not enough to build true equity and belonging in our communities. That’s why we prioritize integrating diversity, equity, inclusion and belonging principles into the core of how we work every day—focusing not only on our employee experience, but also our customer experience and operations. It’s the best way to serve our mission of empowering entrepreneurs everywhere, and making opportunity more inclusive for all. To read more about these commitments, as well as our representation and pay equity data, check out our Diversity and Pay Parity annual report which can be found on our Diversity Careers page.
We also embrace our diverse culture and offer a range of Employee Resource Groups (Culture). Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way.
GoDaddy is proud to be an equal opportunity employer. GoDaddy will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. Refer to our full EEO policy.
Our recruiting team is available to assist you in completing your application. If they could be helpful, please reach out to myrecruiter@godaddy.com.
Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
GoDaddy doesn’t accept unsolicited resumes from recruiters or employment agencies.
Compensation & Benefits:
What We Offer:
Working at GoDaddy offers many benefits, including competitive pay, generous time off, parental and wellness leave, healthcare, retirement savings program, and much more. Offerings vary by location.
This role is eligible for a comprehensive benefits package, which includes medical, dental, and vision insurance, a 401(k)-retirement plan, paid sick time, paid flexible time off, paid parental leave, life insurance, short- and long-term disability, AD&D insurance, mental health or EAP programs, remote or hybrid work options, paid holidays, paid Wellness days, tuition assistance, adoption, surrogacy, and fertility benefits, dependent daycare and backup care benefits, Employee stock purchase plan, financial education and advice; and other benefits in accordance with GoDaddy’s benefit plans and applicable law.
Actual compensation and benefits eligibility will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.
Compensation:
The estimated pay ranges for this role are listed below. In addition to base pay, this role may be eligible for other forms of compensation, which may include a corporate bonus and/or equity awards, subject to the terms of applicable plans and individual eligibility.


