← All roles
Director

Principal of Cybersecurity and AI GRC

Panda Restaurant Group · Retail · 10,000+ employees

Rosemead, CA · Hybrid · full_time

Listed by the employer as “Principal, Cybersecurity & AI GRC”. Title normalized for comparability.

CLI Career Level

VP-equivalent

Moderate confidence

Opportunity Score

67/100

Solid

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Aug 17, 2026 · Last verified 3 hours ago · Sourced from LinkedIn — Principal / GRC leadership (US)

CLI Take

Broader than the title suggests

This role reads VP-equivalent despite being advertised as “Principal, Cybersecurity & AI GRC” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries SOC 2 accountability. The reporting line sits below the executive team — the role reports to Head of Cybersecurity and Risk. Team size is not disclosed and remains the main open question before pursuing it.

Why this role scores the way it does

67/100 — solid opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Head of Cybersecurity and Risk. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

VP-equivalent — The employer lists this as “Principal, Cybersecurity & AI GRC”. CLI reads it as VP-equivalent because the role shows enterprise-wide remit, 10,000+ employee organization.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • The role carries more scope than the employer's title suggests.
  • Employer profile: 10,000+ employee organization, privately held, not applicable, revenue 1b 10b.
  • Signals worth probing: Obtaining a valid Food Handler's Card within 30 days of employment is a requirement of this position. (Unusual requirement for a cybersecurity leadership role).

What to probe before applying

  • The reporting line sits below the executive team — the role reports to Head of Cybersecurity and Risk.

Scoring components · Solid

Compensation versus comparable roles55 · weight 15%

The employer discloses a base range, but there is no comparable set to benchmark it against yet.

Reporting level0 · weight 12%

The reporting line sits below the executive team — the role reports to Head of Cybersecurity and Risk.

Functional and geographic scope57 · weight 12%

Scope language covers enterprise-wide remit.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposureNot disclosed · excluded from the score

Executive and board exposure: not disclosed.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory100 · weight 10%

Employer profile: 10,000+ employee organization, privately held, not applicable, revenue 1b 10b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals75 · weight 5%

Signals worth probing: Obtaining a valid Food Handler's Card within 30 days of employment is a requirement of this position. (Unusual requirement for a cybersecurity leadership role).

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

$157,000 – $220,000 base salary, disclosed by employer

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

The Principal, Cybersecurity & AI GRC is a strategic advisor tasked with defining and sustaining enterprise-wide frameworks for AI risk, privacy, and regulatory compliance. The leader will establish long-term direction, decision models, and guardrails to enable AI innovation while ensuring alignment with the brand's values and regulatory obligations.

Reporting to the Head of Cybersecurity and Risk, this is an enterprise-wide enablement and oversight role. The remit covers AI risk, privacy, and technology GRC across the global restaurant concept.

Scope

  • Reports to Head of Cybersecurity and Risk

Domains and regulation

  • GRC
  • Privacy
  • Third-Party Risk
  • Compliance
  • Identity
  • SOC 2

Requirements

Must have

  • Minimum seven years of experience in GRC, privacy, security, enterprise risk, or technology enablement with increasing management responsibility.
  • Experience leading AI governance program design and implementation.
  • Experience with AI frameworks: NIST AI RMF, EU AI Act, and ISO 42001.
  • Demonstrated expertise implementing cybersecurity frameworks: NIST CSF, NIST 800-53, ISO 27001, and CIS.
  • Experience performing enterprise/security risk assessments and TPRM programs.
  • Bachelor’s degree in Computer Science, Business, or an IT-related discipline.

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Signals worth probing

Not stated in the posting: Specific team size or headcount not mentioned; Public company experience requirement not specified (company is described as family-owned); Clearance requirements not mentioned.

About Panda Restaurant Group

Panda Restaurant Group is the parent company of Panda Express, Panda Inn, and Hibachi-San. It is a family-owned global foodservice retailer operating over 2,300 locations and employing more than 40,000 people. For a security leader, the environment involves protecting high-volume retail point-of-sale systems, supply chain logistics, and extensive employee and customer data.

Industry
Retail
Headcount
10,000+ employees
Headquarters
Rosemead, California
Founded
1973
Ownership
Privately held
Funding
Not applicable
Revenue
$1B – $10B

Full company profile for Panda Restaurant Group →

View original job description
Summary Of Job DescriptionThe Principal, Cybersecurity & AI GRC is a strategic advisor responsible for defining and sustaining enterprise-wide frameworks across AI risk, privacy, regulatory compliance, and technology and cyber risk. Reporting to the Head of Cybersecurity and Risk, this role establishes long-term direction, decision models, and guardrails that enable AI and data-driven innovation to align with Panda’s values, regulatory obligations, and business objectives. The role is a principal-level enablement, oversight, and influence role that ensures teams can make informed, consistent decisions while protecting guests, associates, and the brand. Principle responsibilities include enterprise AI enablement strategy and operating model, Integrated GRC and privacy enablement, clear decision ownership, escalation, risk tolerance frameworks, and safe, compliant, and scalable AI adoption.Job ResponsibilitiesDefines and evolves enterprise digital trust and AI enablement strategy, frameworks, and operating model and advises senior leadership on AI risk, privacy posture, and tradeoffs using business-relevant language.Establishes policies and standards for responsible AI, privacy, data usage, transparency, and human oversight. Integrates AI risk, privacy, and compliance into enterprise GRC and risk management processes.Defines risk classification, approval workflows, and lifecycle governance for AI and digital capabilities.Establish clear decision ownership, escalation models, and risk tolerance frameworks across the enterpriseLeads enablement for high-risk, high-impact AI, data, and digital initiatives. Enables Product, Engineering, Analytics, and Business teams with clear, practical, and actionable guidance.Defines and manages risk acceptance, exception handling, and escalation processes for AI and technology risk.Partners with Legal and Privacy to operationalize regulatory requirements impacting AI, data, and automation.Influences platform, vendor, and tooling strategy related to AI capabilities and embedded AI features.Represents digital trust, AI, and privacy enablement in enterprise architecture, risk, and investment forums.How We Reward YouHybrid Work schedule 401K with company matchYearly bonus opportunity*Full medical, dental, and vision insurance *On-site fitness center, biometric screen, and flu shot clinicDiscounts at Panda restaurants, theme parks, and gym membershipsPaid time off starting at 15 days with 7 federal holidays*Continuous education assistance and scholarships*Income protection including Disability, Life and AD&D insurance*Bereavement leave*Benefits available for eligible permanent full time associatesYour Background & ExperienceBachelor’s degree in Computer Science, Business, or an IT-related disciplineMinimum seven years of experience in GRC, privacy, security, enterprise risk, or technology enablement with increasing management responsibility; experience performing or leading: enterprise/security risk assessments, control design/testing, policy and standards development, TPRM programs, compliance/regulatory readiness programs, AI governance program design and implementation as well as experience in AI governance and compliance frameworks (NIST AI RMF, EU AI Act, ISO 42001), including AI risk classification, algorithmic impact assessments, responsible AI principles, and practical application within enterprise or client-facing advisory engagementsDemonstrated expertise implementing and operationalizing cybersecurity frameworks and control programs: NIST CSF / NIST 800-53, ISO 27001/27002, CIS, NIST AI RMF, ISO 42001Successful completion of initial and periodically required trainings.Obtaining a valid Food Handler's Card within 30 days of employment is a requirement of this position. Pay Range: M3H: $157,000 - $220,000 / Annual Within the range, individual pay is determined using various factors, including work location and experience.Panda Strong Since 1983Founded in Glendale, California, we are now the largest family-owned American Chinese Restaurant concept in America. With close to 2,800 locations globally, we continue our mission of delivering exceptional Asian dining experiences by building an organization where people are inspired to better their lives. Whether it’s impacting our team or the communities we work in, we’re proud to be an organization that embraces family values.You’re Wanted HerePanda Restaurant Group, Inc. is an Equal Opportunity Employer and is committed to providing equal opportunity, and does not discriminate on the basis of any characteristic protected by law, including but not limited to sex/gender (including pregnancy, childbirth, lactation and related conditions), gender expression, race, color, religion, national origin, sexual orientation, gender identity, disability, age, ancestry, medical condition, genetic information, marital status, and veteran status. Additionally, Panda Restaurant Group, Inc. complies with all federal, state, and local laws regarding requests for workplace accommodation. The Americans with Disabilities Act (ADA) prohibits discrimination against qualified individuals on the basis of disability. Applicants are entitled to reasonable accommodations, absent undue hardship, to effectively participate in the application and hiring process, for example, sign language interpreters. If you believe you require an accommodation for the application or interview process or for the position for which you are applying, please reach out to TASupport@PandaRG.com.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.