
GRC Engineer
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of the compliance program from start to finish, ensuring it is audit-ready throughout the year.
• Manage the relationship with auditors.
• Prepare the organization for upcoming customer-requested certifications and frameworks.
• Keep the risk register updated, advance risk treatments, and maintain an accurate risk overview.
• Develop and uphold policies, standards, and procedures as the company grows.
• Oversee and implement business continuity, disaster recovery, and incident response plans and playbooks.
• Manage commitments for customer notifications and ensure that stakeholders are aware of their responsibilities.
• Handle customer security questionnaires and oversee third-party risk management reviews from start to finish.
• Enhance the answer library to facilitate accurate, consistent, and prompt responses.
• Evaluate vendors, maintain Data Processing Agreements (DPAs) and the subprocessor list, scale third-party risk management, and address customer data requests.
• Map controls across industry frameworks to maximize the reuse of evidence.
• Automate the gathering of evidence through APIs and scripts.
• Collaborate closely with the head of security, engineers, and customers.
• Drive the advancement of AegisAI's security program for its AI-attack defense business.
• A minimum of 4 years of experience in Governance, Risk, and Compliance (GRC), security compliance, or auditing within a SaaS company.
• Must have successfully managed a SOC 2 Type II process from beginning to end at least once.
• Proficient in responding to enterprise security questionnaires.
• Strong written communication skills sufficient to resolve security review discussions.
• Technical proficiency to interpret architecture diagrams and assess the practical implementation of controls.
• Experience in scripting with Python or a similar language.
• Comfortable working with APIs.
• Familiarity with major privacy regulations and their implications for data processors.
• Highly organized, self-motivated, and honest about areas of limited knowledge.
• Experience with ISO 27001 implementation or certification is a plus.
• Preferred experience with compliance automation platforms, particularly custom tests and APIs.
• Exposure to AI governance, including ISO 42001 or NIST AI RMF, is considered a bonus.
• Experience in building or testing Business Continuity/Disaster Recovery (BC/DR) for production SaaS environments is advantageous.
• A privacy certification such as CIPP is preferred.
• Prior experience working with a security vendor is a plus.
• A flat, flexible, and fast-paced culture.
• Defined Key Performance Indicators (KPIs) for success with the autonomy to determine how to meet them.
We Insure
ExactCare
ApartmentIQ
The Center for Aquaculture Technologies (CAT)
Get handpicked remote jobs straight to your inbox weekly.