← All rolesHead
Principal GRC Manager
Wrapbook · Software · 201-500 employees
United States · Remote · full_time
Listed by the employer as “GRC Principal - Data Privacy and Security”. Title normalized for comparability.
CLI Career Level
Senior Manager-equivalent
Low confidence
Opportunity Score
62/100
Solid
Moderate confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 2, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — Principal / GRC leadership (US)
CLI Take
Broader than the title suggests
This role reads Senior Manager-equivalent despite being advertised as “GRC Principal - Data Privacy and Security” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries SOC 2 and PCI DSS accountability. The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected. The reporting line and team size are not disclosed and remain the main open questions before pursuing it.
Why this role scores the way it does
62/100 — solid opportunity quality. CLI reads this as a Senior Manager-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected. 5 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
Senior Manager-equivalent — The employer lists this as “GRC Principal - Data Privacy and Security”. CLI reads it as Senior Manager-equivalent because the role shows 201-500 employee organization.
Low confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Signals worth probing: This is a high-ambiguity, high-autonomy role... this person is both excited to drive the strategic direction and own the ground-level execution across their areas..
What to probe before applying
- The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected.
Scoring components · Solid
Compensation versus comparable roles55 · weight 15%
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
Reporting levelNot disclosed · excluded from the score
Reporting line: not disclosed.
Functional and geographic scopeNot disclosed · excluded from the score
Scope: no enterprise, global or multi-unit remit is described.
Quality of the mandate100 · weight 12%
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposureNot disclosed · excluded from the score
Executive and board exposure: not disclosed.
Role authority versus title25 · weight 10%
The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected.
Company scale and trajectory58 · weight 10%
Employer profile: 201-500 employee organization, vc backed ownership, series b, revenue 50m 250m.
Team ownershipNot disclosed · excluded from the score
Team size: not disclosed.
Budget ownershipNot disclosed · excluded from the score
Budget ownership: not disclosed.
Risk signals75 · weight 5%
Signals worth probing: This is a high-ambiguity, high-autonomy role... this person is both excited to drive the strategic direction and own the ground-level execution across their areas..
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$143,000 – $232,000 base salary, disclosed by employer
Sample size not yet sufficient for a market comparison
See the full benchmark bands by level and region
The mandate
Serve as the technical authority to build, scale, and lead Wrapbook's security and privacy GRC programs from the ground up. The leader will own the strategic multi-year direction for risk investment, particularly concerning AI data governance, while executing hands-on SOC audit cycles, vendor risk management, and global privacy compliance.
Individual contributor role functioning as a subject matter expert and technical authority for GRC across the US and Canada. Remit covers Data Security GRC (SOC audits, ISMS), Data Privacy GRC (GDPR/CCPA), and AI Governance.
Domains and regulation
- GRC
- Privacy
- Third-Party Risk
- Compliance
- Enterprise Security
- SOC 2
- PCI DSS
- CCPA
- SOC 2
Requirements
Must have
- 10+ years in GRC, information security, and privacy compliance.
- Deep, hands-on expertise across security (SOC 2, ISO 27001, PCI DSS) and privacy (GDPR, CCPA, DSAR) compliance.
- Proven experience leveraging AI to automate GRC workload and force-multiply GRC programs.
- Demonstrated ownership of SOC audit lifecycles and enterprise/third-party risk programs.
Preferred / bonus
- Proven track record of building, scaling, and operating rigorous programs, ideally at a fintech or startup.
- Preferred: Relevant certifications such as CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Building and maturing GRC programs from the ground up in a high-ambiguity environment.
- Translating evolving AI regulatory landscapes (NIST AI RMF, EU AI Act) into internal governance frameworks.
- Moving from successful one-time audits to a state of durable, continuous audit-ready operational maturity.
- Scaling data governance and privacy operations (GDPR/CCPA/DSAR) as AI capabilities expand.
Signals worth probing
- This is a high-ambiguity, high-autonomy role... this person is both excited to drive the strategic direction and own the ground-level execution across their areas.
Not stated in the posting: Specific reporting line (e.g., to CISO, General Counsel, or CTO) not explicitly named.; Size of the immediate GRC team not specified..
About Wrapbook
Wrapbook provides a cloud-based payroll, insurance, and compliance platform specifically designed for the entertainment industry. The platform automates production onboarding and payment processing for film, television, and commercial production companies. The organization manages sensitive financial and personal identifiable information for a large workforce of project-based contractors.
- Industry
- Software
- Headcount
- 201-500 employees
- Headquarters
- New York, NY
- Founded
- 2018
- Ownership
- Venture backed
- Funding
- Series B · $130M raised
- Revenue
- $50M – $250M
- Investors
- Andreessen Horowitz (a16z), Tiger Global Management, Avenir Growth Capital, Equal Ventures, Uncork Capital
Full company profile for Wrapbook →
View original job description
About UsWrapbook is the AI platform for production finance. We’re building a system of action that puts finance teams in control of their whole production, from payroll, to spend, to accounting.Built for feature films, TV, and commercials, Wrapbook is trusted by teams at Netflix, Paramount, Anonymous Content, and more. With backing from Andreessen Horowitz, Bessemer Venture Partners, and Jeffrey Katzenberg's WndrCo, our team of 350+ is using AI to transform how finance teams work and empower them to do more with less.The Opportunity – GRC Principal - Data Privacy and Security (Remote - USA / CANADA):We're hiring a Principal GRC Manager (Individual Contributor) to serve as a subject matter expert and technical authority leading Wrapbook's privacy and security GRC programs. This is a high-ambiguity, high-autonomy role for someone who has built and matured GRC programs at a fintech or SaaS company from the ground up. This person will not just maintain grc activities, but bring a strong point of view to set the multi-year direction for how Wrapbook manages GRC investment on the security and privacy front as our AI capabilities expand. This person is both excited to drive the strategic direction and own the ground-level execution across their areas, leveraging AI to amplify their output. You understand the difference between checking boxes and high judgment decisions, you focus on outcomes over activity. You cleanly separate the must-dos and the nice-to-haves informed by a business’ risk appetite, industry context, and overall company objectives.You have a proven track record of building AI-first solutions for traditional GRC problems; you have the expertise and experience to validate AI outputs. You thrive on systems-thinking and delivering measurable results with rigor; you’ll own the project management, frameworks, measurement, outward and upward reporting, influence executives and leaders. You’ll evolve a program that passes SOC 1 and SOC 2 Type II audits, moving it from "successful audits" to durable, continuously audit-ready operational maturity. You are a bridge-builder, you know how to develop, grow, and leverage strong relationships and trust with cross-functional stakeholders and leadership.What You'll DoData Security GRCLead the annual SOC 1 and 2 audit lifecycle end-to-end: control monitoring/readiness, work with our SOC auditors and internal business teams to complete the audit project and reporting supporting evidence collection and clarification process, drive control-owner accountability and lead program development to embed continuous, evidence-driven controls.Own and evolve Wrapbook's ISMS policy suite and control framework (SOC 1, SOC 2 Type II; explore additional ISO compliance opportunities) in collaboration with our Business, Legal, and Security teams.Mature our approach to vendor risk management, developing and evolving the program, frameworks, prioritization, stakeholder management, and measurement.Lead Customer Assurance efforts for enterprise security reviews (e.g., enterprise customer and prospect review requirements, cyber-insurance self-assessments) and scale Wrapbook's security and privacy documentation and mechanisms.Data Privacy GRCCollaborate with Legal and Security teams to build and evolve Wrapbook’s Data Governance program across the data lifecycle (data collection, storage, access, retention, deletion).Beyond project management you will make recommendations and own decisions on how to best solve Wrapbook’s dynamic and growing data governance challenges.Build and evolve the privacy compliance program across GDPR and CCPA — DSAR operations, data mapping, retention, and the data governance and classification program.Partner with Legal on DPAs, subprocessor obligations, and privacy-by-design in product.Help shape Wrapbook's enterprise AI data governance framework in collaboration with our Security and Legal leadership/org— policies, standards, and controls across the AI/ML lifecycle for both internally built and procured AI.Track the evolving regulatory and framework landscape (e.g., NIST AI RMF, ISO 42001, EU AI Act) and translate it into Wrapbook’s needs.Cross-functional leadershipExecutive fluency and credibility. Translates technical and regulatory risk into business terms leadership can act on, and holds their own in front of executives, auditors, and enterprise customers. Trusted to represent Wrapbook's risk posture externally.Serve as the subject-matter authority and trusted advisor on Security and Privacy governance and compliance topics.Mentor cross-functional partners and team members and set the standard for the discipline across the org.What We're Looking For10+ years in GRC, information security and privacy compliance with a track record of building, scaling, and operating highly rigorous programs — ideally at a fintech, start-up, or payments organization.You have the highest integrity and discretion. ****Customer trust is paramount at Wrapbook and this role will interact with highly sensitive data, owning difficult risk trade-offs with sound ethics and confidentiality.Project management is second nature, you effectively establish, track, measure and communicate/report out on cross-functional program progress, prioritization decisions/trade-offs, risks, and impact.Proven experience leveraging AI to automate GRC workload and force-multiply GRC programs to measurable outcomes.Deep, hands-on expertise across security (SOC 2 / ISO 27001 / PCI DSS), privacy (GDPR / CCPA, DSAR operations, data governance) compliance.Working fluency in AI/ML governance and the current regulatory landscape. You are comfortable with setting policy where standards are still forming.Demonstrated ownership of SOC audit lifecycles and enterprise risk and third-party risk programs.Exceptional cross-functional influence — able to move executives and technical teams without direct authority.Relevant certifications a plus: CISSP, CISA, CISM, CRISC, CIPP/CIPM/CIPT, and/or AIGP.Why Join UsAt Wrapbook, creativity meets technology — and not just in the product.BenefitsIn addition to a competitive salary and all the benefits you can expect from a fast-growing technology company, you’ll get access to a team of creative problem solvers and the chance to see your contributions make large impacts. Benefits include:Unlimited Paid Time OffWork from anywhere in Canada and USAHealth and Dental benefitsUp to $1,500 USD/ $2,025 CAD towards IT set up for your homeUp to 2% matching RRSP / 401KLearning and Development opportunitiesUp to $50 USD/ $67.50 CAD towards Internet/Cell phone serviceOur Pledge To Fostering An Inclusive And Safe WorkplaceWrapbook pledges to be a harassment- and discrimination-free space for everyone, regardless of age, disability, ethnicity, gender identity or expression, nationality, neurotype, personal appearance, political affiliation, professional background, race, religion, or sexual identity or orientation.Apply NowHave we got your attention? Submit your application today and a member of our Talent team will be in touch with you shortly!Compensation Range: $143K - $232K
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.