Principal Cybersecurity Gov Risk & Compliance

Amtrak
$113,200 - $146,664Remote

About The Position

The Principal DT Gov Risk & Compliance serves as the subject matter expert responsible for translating cyber risk into business impact. This position evaluates the potential operational, customer, financial, and revenue impacts associated with cyber risks and provides risk-based recommendations to leadership. The role supports Cybersecurity’s mission of determining which information security risks matter most by quantifying exposure, assessing business consequences, evaluating risk treatment options, and supporting informed decision-making across technology, cybersecurity, and business stakeholders.

Requirements

  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience. Plus 7 years of relevant work experience.
  • Experience performing cyber risk assessments, business impact analysis, enterprise risk analysis, risk quantification, or related risk management activities.
  • Demonstrated ability to communicate complex technical and cybersecurity risks in business terms to non-technical stakeholders

Nice To Haves

  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience. Plus 9 years of relevant work experience.
  • Experience with cyber risk quantification methodologies such as FAIR or similar quantitative risk analysis frameworks.
  • Experience performing operational, financial, customer-impact, or business impact assessments
  • Experience supporting executive decision-making through development of risk analyses, business cases, or investment prioritization recommendations
  • Relevant certifications such as CRISC, CISM, CISSP, FAIR Analyst (FAIRA), or FAIR Practitioner (FAIRP)
  • Experience in GRC/IRM space with leading, developing and maintaining cybersecurity and ITGC policies and associated controls management
  • Understanding of the ServiceNow platform ecosystem
  • Familiarity with the risk-based frameworks’ associated analysis and data analytics
  • Familiarity with industry frameworks (e.g., NIST, CIS, COBIT, etc.), best practices and methodologies
  • Strong understanding of cybersecurity risk management principles and risk assessment methodologies.
  • Ability to evaluate and quantify operational, customer, financial, and revenue impacts associated with cyber risks.
  • Strong analytical and critical-thinking skills with the ability to assess competing priorities and risk treatment options.
  • Experience developing executive-level presentations, briefings, and decision-support materials.
  • Strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated
  • Solid understanding of data handling best-practices, information management, and governance
  • Strong writing and oral skills with ability to effectively communicate technical issues to diverse audiences
  • Excellent attention to detail
  • Ability to translate technical cybersecurity risks into business-focused recommendations and actionable insights

Responsibilities

  • Perform quantitative and qualitative cyber risk assessments to evaluate potential operational, customer, financial, and revenue impacts associated with cyber risks.
  • Develop risk quantification models, business impact analyses, and risk scenarios to support executive decision-making and risk acceptance activities.
  • Analyze the effectiveness of proposed risk treatments and cybersecurity investments by evaluating potential risk reduction and residual risk.
  • Collaborate with enterprise risk stakeholders, business stakeholders, and technology teams to translate technical risks into business consequences and recommendations.
  • Prepare and present cyber risk quantification analyses, business impact assessments, and executive decision-support materials for leadership review.
  • Develop and support new policies, standards, guidelines, and procedures to ensure compliance with NIST, PCI-DSS, GDPR/CCPA, and other regulations.
  • Collaborate with GRC leadership to develop and review audit responses for external audits and ensure compliance with laws and regulations.
  • Develop and manage GRC Administrative, Physical, and Technical Controls Catalog, including system security plans and cybersecurity language in contracts and agreements.
  • Work with internal and external audit firms, regulatory agencies, and the Infrastructure systems team to provide documentation and develop ITGC process standards.
  • Identify major risk factors impacting Amtrak's objectives, generate communication and educational plans, and mitigate obstacles to change.

Benefits

  • Health, Dental, and Vision Insurance
  • Wellness Programs
  • Health Savings Account
  • No-cost Personal Health Advocate
  • Medical Plan Opt-out Credit
  • Life Insurance
  • Short- and Long-term Disability Insurance
  • No-cost Financial Advisor Sessions
  • Commuter and Flexible Spending Accounts
  • 401K with Employer Match
  • Railroad Retirement Benefits
  • Public Service Student Loan Forgiveness
  • Student Loan Assistance
  • Tuition and Education Reimbursement
  • Rail Pass Privileges
  • Employee Assistance Program
  • Generous Paid Time Off
  • Paid Caregiving Days and Backup Care
  • Fertility and Family Building Benefits
  • Adoption and Surrogacy Assistance
  • Paid Family Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service