Job SummaryThe Principal DT Gov Risk & Compliance collaborates with Digital Technology, Cybersecurity, and business stakeholders to establish, implement, and mature enterprise cybersecurity governance capabilities. Lead the development of governance frameworks, policies, standards, decision-making processes, and performance metrics that align cybersecurity strategy with business objectives. Coordinate governance forums, executive reporting, and policy lifecycle management while ensuring regulatory, risk, and compliance requirements are appropriately integrated into governance activities. Support the continuous improvement of security governance programs through measurement, transparency, and stakeholder engagement.
Essential Functions- Lead the cybersecurity policy governance program, including policy lifecycle management, approvals, exceptions, periodic reviews, and stakeholder accountability.
- Establish and maintain cybersecurity governance forums, committees, and working groups to support executive decision-making and accountability.
- Develop and present cybersecurity governance metrics, dashboards, and key performance indicators to senior leadership and executive stakeholders.
- Drive alignment between cybersecurity strategy, business objectives, regulatory requirements, and technology initiatives.
- Define governance processes for risk acceptance, policy exceptions, standards management, and security oversight activities.
- Partner with business units, BISOs, enterprise architecture, legal, privacy, and compliance teams to ensure effective governance integration across the enterprise.
- Audit remediation/tracking
- Maintain governance documentation including charters, operating models, decision rights, accountability matrices, and governance procedures.
- Promote cybersecurity awareness, governance education, and stakeholder engagement initiatives across the organization.
- Support maturity assessments and continuous improvement initiatives for cybersecurity governance capabilities utilizing industry frameworks such as NIST CSF, COBIT, and CIS.
- Develop and support new policies, standards, guidelines, and procedures to ensure compliance with NIST, PCI-DSS, GDPR/CCPA, and other regulations.
- Collaborate with GRC leadership to develop and review audit responses for external audits and ensure compliance with laws and regulations.
- Develop and manage GRC Administrative, Physical, and Technical Controls Catalog, including system security plans and cybersecurity language in contracts and agreements.
- Work with internal and external audit firms, regulatory agencies, and the Infrastructure systems team to provide documentation and develop ITGC process standards.
- Identify major risk factors impacting Amtrak's objectives, generate communication and educational plans, and mitigate obstacles to change.
Minimum Qualifications- Bachelor's Degree or equivalent combination of education, training and/or relevant experience. Plus 7 years of relevant work experience
Preferred Qualifications- Bachelor's Degree or equivalent combination of education, training and/or relevant experience. Plus 9 years of relevant work experience
Knowledge, Skills, and Abilities- Experience developing and operating enterprise cybersecurity governance programs.
- Experience facilitating governance councils, steering committees, and executive-level working groups.
- Ability to develop executive-facing reporting, KPIs, KRIs, scorecards, and governance dashboards.
- Knowledge of cybersecurity operating models, organizational governance structures, and decision-rights frameworks.
- Experience managing policy exception processes and governance workflows.
- Ability to influence senior leaders and business stakeholders without direct authority.
- Experience aligning cybersecurity strategy and initiatives with business priorities and enterprise objectives.
- Strong understanding of accountability frameworks, RACI models, and governance best practices.
- Experience in GRC/IRM space with leading, developing and maintaining cybersecurity and ITGC policies and associated controls management
- Understanding of the ServiceNow platform ecosystem
- Familiarity with the risk-based frameworks' associated analysis and data analytics
- Familiarity with industry frameworks (e.g., NIST, CIS, COBIT, etc.), best practices and methodologies
- Strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated
- Solid understanding of data handling best-practices, information management, and governance
- Strong writing and oral skills with ability to effectively communicate technical issues to diverse audiences
- Excellent attention to detail
The salary/hourly range is $113,200.00 - $146,664.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee's assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee's base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.
Health and WellbeingFinancial and RetirementWork and Family Life SupportHealth, Dental, and Vision Insurance401K with Employer MatchGenerous Paid Time Off Wellness ProgramsRailroad Retirement BenefitsPaid Caregiving Days and Backup CareHealth Savings AccountPublic Service Student Loan ForgivenessFertility and Family Building BenefitsNo-cost Personal Health AdvocateStudent Loan AssistanceAdoption and Surrogacy AssistanceMedical Plan Opt-out CreditTuition and Education ReimbursementPaid Family Leave Life InsuranceRail Pass Privileges Short- and Long-term Disability InsuranceEmployee Assistance Program No-cost Financial Advisor SessionsCommuter and Flexible Spending Accounts
Learn more about our benefits offerings here.
Requisition ID:167003
Work Arrangement:02-Remote Optional Click here for more information about work arrangements at Amtrak.
Relocation Offered:No
Travel Requirements:Up to 25%