Commercial GRC Engineer - Senior Security Engineer
New
J
JobgetherSecurity compliance
Based in United StatesFull-TimeSenior
SalaryU.S. base salary range of $175,000 - $227,500 USD. Market-competitive incentive opportunity in addition to base compensation. Monthly stipend to support work and productivity.
Apply NowOpens the employer's application page
Job Details
- Experience
- 4+ years of experience in GRC engineering, security engineering, compliance automation, IT audit support, or a related field
- Required Skills
- PythonJavascript
Requirements
- Have 4+ years of experience in GRC engineering, security engineering, compliance automation, IT audit support, or a related field.
- Have hands-on ownership of at least one complete certification cycle, such as SOC 2 or ISO 27001.
- Have practical experience with GRC or compliance automation platforms such as Vanta, Drata, Secureframe, or comparable internal solutions.
- Be able to configure integrations and build evidence pipelines.
- Understand cloud security fundamentals, including AWS, GCP, or Azure IAM, logging, and encryption, and how they relate to compliance controls.
- Have working knowledge of SOC 2 and ISO 27001, and ideally ISO 27017/27701 and HIPAA requirements.
- Be able to map controls across frameworks and reduce duplicated evidence work.
- Be comfortable using Python, JavaScript, or similar technologies for integrations, API-based evidence collection, or GRC tooling extensions.
- Clearly document controls, gaps, and remediation plans for auditors and engineering teams.
- Be able to trace control failures or audit findings to root causes and drive durable remediation across teams.
Responsibilities
- Design automated evidence collection and continuous control monitoring across cloud, identity, endpoint, and SaaS systems.
- Express controls, tests, and cross-framework mappings as version-controlled code.
- Translate compliance requirements into technical control logic, workflows, and integrations with engineering, IT, and security teams.
- Contribute to architecture and design reviews, define control requirements as acceptance criteria, and help teams build compliant-by-default infrastructure.
- Build engineer-facing compliance experiences, including self-service control status, guardrails, and feedback through tools such as CI/CD, Jira, and Slack.
- Evaluate control effectiveness against relevant risk and propose alternatives when framework requirements do not fit the threat model or workload architecture.
- Coordinate audit evidence requests, maintain evidence libraries, respond to auditor follow-ups, and track remediation through closure.
- Build dashboards and reporting for control health, evidence freshness, and audit readiness.
- Diagnose recurring control failures and stale evidence, then improve underlying processes, tooling, or ownership models.
View Full Description & ApplyYou'll be redirected to the employer's site