
GRC Automation Engineer
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in United States.
• Develop automations aimed at minimizing manual tasks related to information security and compliance, which includes collecting evidence, validating controls, preparing for audits, tracking POA&M, continuous monitoring, reporting, and managing tasks.
• Create automations for third-party security assessments within procurement and recurring reviews, specifically for third parties impacting FedRAMP, CJIS, HIPAA, PCI, and IP.
• Leverage AI-driven tools, AI agents, low-code/no-code platforms, scripts, APIs, and integrations to enhance compliance workflows.
• Design, test, and refine workflows and prompts that utilize AI assistance.
• Assess new AI technologies for their applicability in governance, risk, and compliance scenarios.
• Review AI-enabled automations for security, privacy, regulatory compliance, auditability, and alignment with AI governance.
• Utilize AI-assisted analysis to uncover trends, risks, control deficiencies, and opportunities for remediation.
• Collaborate with Security, Engineering, Product, IT, Legal, and business teams to document requirements and convert manual processes into automated workflows.
• Facilitate automation efforts across FedRAMP, CJIS, ISO 27001, ISO 42001, SOC 2, PCI, HIPAA, FISMA, and CyberEssentials.
• Assist in the transition from FedRAMP rev5 legacy reporting and auditing standards to Consolidated New Rules and 20.x.
• Revamp vulnerability management, inventory management, FedRAMP reporting, POA&M reporting, and deviation management processes.
• Analyze team workflows to pinpoint and implement automation opportunities.
• Create dashboards, metrics, and consistent reporting for compliance status, control health, audit readiness, risks, gaps, and progress in remediation.
• Cultivate expertise as a trusted GRC builder by acquiring knowledge of compliance frameworks, cloud environments, secure engineering practices, and automation patterns.
• Safeguard the confidentiality, integrity, and availability of Granicus information assets.
• Ensure the privacy of employee and customer data while completing the necessary privacy training.
• 3–6 years of relevant experience in various development positions.
• BA/BS in Engineering or a related discipline.
• Practical experience in evaluating and implementing AI tools, agents, or automation technologies to address business or operational challenges.
• A strong desire for continuous learning about emerging AI capabilities and their practical applications in security and compliance.
• Proven experience in identifying automation possibilities and constructing solutions.
• Excellent communication skills with team members and customers.
• Flexibility to thrive in a fast-paced, dynamic environment.
• Capacity to meet deadlines without sacrificing accuracy.
• Ability to maintain the confidentiality, integrity, and availability of Granicus information assets.
• Commitment to ensuring employee and customer data privacy along with completing required privacy training.
• Flexible Time Off.
• Company-Wide Wellbeing Days.
• Work From Home Reimbursement.
• Multiple Health Plan Options, including a 100% employer-paid plan.
• Employer HSA Contributions.
• Fitness Reimbursement Program.
• On-Demand Mental Health Support, including Headspace and other wellness tools.
• Paid Parental Leave for birthing and non-birthing parents.
• Traditional & Roth 401(k) with a generous company match.
• 100% employer-paid Life & AD&D Insurance.
• Access to Online Learning Platforms.
• Competitive Salary & Bonuses.
Upgrade, Inc.
S4 Capital Group
NBCUniversal
NBCUniversal
Get handpicked remote jobs straight to your inbox weekly.