Logo for SimScale

Principal Governance, Risk and Compliance (GRC) Architect

Role overview

Qualifications

  • Deep technical AWS experience beyond evidence collection, including GovCloud, VPC isolation, network security, and IAM architecture
  • Expert-level knowledge in at least two of TISAX, ITAR, or FedRAMP with prior audit leadership or ongoing compliance maintenance
  • GDPR privacy knowledge with active interest in evolving AI regulation
  • Strong ability to translate regulatory requirements into actionable technical tasks; independent, hands-on contributor

Responsibilities

  • Maintain continuous SOC 2 Type II compliance through automated monitoring to keep compliance a constant state
  • Direct technical infrastructure strategy to meet ITAR and FedRAMP requirements, including managing AWS GovCloud, network security boundaries, encryption, and IAM standards
  • Bridge the speed vs. standard gap by designing and implementing controls that satisfy auditors without bottlenecking engineering or DevOps teams
  • Lead global expansion by architecting and executing TISAX, ITAR, and FedRAMP implementations

About the company

SimScale logo

SimScale

Computer Software / SaaS

SimScale enables engineering teams to access accurate and fast simulation, on their terms, without compromise. We make engineering simulation technically and economically accessible from everywhere, at any time, and at any scale, in the cloud. We deliver instant access to fluid, thermal, structural, and electromagnetic simulation to hundreds of thousands of users worldwide. With SimScale, high-fidelity multiphysics simulation has moved from a complex and cost-prohibitive desktop application to an inclusive, agile, cloud-native engineering simulation platform. SimScale is a SaaS company that follows a subscription-based pricing model, visit http://simscale.com for more information.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The Role: The Bridge Between Rigor and Velocity

We are looking for a Principal GRC Architect who can solve a unique challenge: How do we maintain "gold-standard" security certifications without killing our "ship-fast" culture?

We are already under continuous observation for SOC 2 Type II and are GDPR compliant. We are now ready to evolve toward the most rigorous standards in the industry: TISAX, ITAR, and FedRAMP. This is a hands-on, individual contributor role. You will be the architect of the system and the person turning the gears, designing the roadmap and then personally implementing the controls.

Your mission is to reconcile the rigidity of international standards with the agility of a fast-paced software company. You aren't here to create bureaucracy; you’re here to engineer compliance directly into our AWS infrastructure.

Core Responsibilities

  • Maintain Continuous Observation: Uphold our SOC 2 Type II standard using automated monitoring to ensure compliance is a constant state, not an annual event.
  • Technical Infrastructure Strategy: Directly satisfy the high-bar technical requirements of ITAR and FedRAMP. This includes managing the transition to/oversight of AWS GovCloud, defining network security boundaries, and ensuring encryption and IAM standards meet federal requirements.
  • Bridge the "Speed vs. Standard" Gap: Act as a technical enabler for the Engineering team, designing and implementing controls (e.g., change management, access reviews) that satisfy auditors but don’t bottleneck our Engineering or DevOps teams.
  • Lead Global Expansion: Architect and execute the technical and procedural implementation of TISAX, ITAR, and FedRAMP.
  • GDPR Stewardship: Act as the internal authority on privacy, ensuring our data mapping and PIAs remain current without adding unnecessary friction.
  • Customer Trust & Sales Support: Join calls with customer Infosec counterparts and handle technical vendor questionnaires to prove our security posture can be trusted by the world’s most demanding organizations.
  • Individual Contributor Ownership: Act as a "department of one". You will write the policies, perform the risk assessments, and manage the audits yourself.

What You Bring

  • Technical AWS Depth: You understand how to configure AWS beyond simple evidence collection. You are familiar with GovCloud, VPC isolation, network security, and IAM architecture.
  • Standard Mastery: Expert-level knowledge in at least two of: TISAX, ITAR, or FedRAMP. You have previously led a company through these audits or were responsible for maintaining their compliance.
  • Privacy & AI Knowledge: A deep, working knowledge of GDPR and an active interest in the evolving landscape of AI regulation.
  • The "Translator" Skillset: You can translate rigid regulatory requirements into actionable technical tasks that make sense to a developer.
  • Independence: You are energized by "getting your hands dirty" and owning the full lifecycle of a program without a team to delegate to.
  • Communication: Exceptional English skills; able to negotiate effectively with both internal engineers and external auditors.

What you can expect from us

  • A direct seat at the table: full ownership of the compliance and GRC roadmap.
  • Your work directly enables our largest enterprise and government deals: measurable, visible business impact.
  • Enjoy flexible hours and the freedom to work remotely from anywhere in the world.
  • Access comprehensive health coverage, retirement plans, paid time off, and wellness support.
  • Stay active with subsidized gym memberships, sports meetups, and wellness programs.
  • Grow as a professional with online/offline learning, language courses, and tech talks.
  • Connect at team events, join support groups, and contribute to our ESG and DE&I initiatives.
  • Participate in fun team challenges and competitions for added excitement and team spirit.
  • Multicultural team (35+ nationalities), flexible work, relocation and visa support where applicable.

Diversity, Equity and Inclusion at SimScale

At SimScale, we look beyond borders and hire great talent from all parts of the world. With our team consisting of people from various backgrounds, we truly embrace diversity and encourage everyone to be themselves. We are unified by curiosity, dedication and our team spirit! As an equal opportunity employer, we acknowledge that our employees have different aspirations and career goals, and therefore are committed to create a diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. A copy of SimScale's full recruiting guideline can be made available on request. Kindly let us know how you would like to be addressed and whether you have specific requirements for the interview. 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
Β·

Risk and Compliance Analyst Related jobs

Other jobs at SimScale

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.