GRC Engineer

Posted 12 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take charge of the compliance program from start to finish, ensuring it is audit-ready throughout the year.

• Manage the relationship with auditors.

• Prepare the organization for upcoming customer-requested certifications and frameworks.

• Keep the risk register updated, advance risk treatments, and maintain an accurate risk overview.

• Develop and uphold policies, standards, and procedures as the company grows.

• Oversee and implement business continuity, disaster recovery, and incident response plans and playbooks.

• Manage commitments for customer notifications and ensure that stakeholders are aware of their responsibilities.

• Handle customer security questionnaires and oversee third-party risk management reviews from start to finish.

• Enhance the answer library to facilitate accurate, consistent, and prompt responses.

• Evaluate vendors, maintain Data Processing Agreements (DPAs) and the subprocessor list, scale third-party risk management, and address customer data requests.

• Map controls across industry frameworks to maximize the reuse of evidence.

• Automate the gathering of evidence through APIs and scripts.

• Collaborate closely with the head of security, engineers, and customers.

• Drive the advancement of AegisAI's security program for its AI-attack defense business.


⛳️ Requirements

• A minimum of 4 years of experience in Governance, Risk, and Compliance (GRC), security compliance, or auditing within a SaaS company.

• Must have successfully managed a SOC 2 Type II process from beginning to end at least once.

• Proficient in responding to enterprise security questionnaires.

• Strong written communication skills sufficient to resolve security review discussions.

• Technical proficiency to interpret architecture diagrams and assess the practical implementation of controls.

• Experience in scripting with Python or a similar language.

• Comfortable working with APIs.

• Familiarity with major privacy regulations and their implications for data processors.

• Highly organized, self-motivated, and honest about areas of limited knowledge.

• Experience with ISO 27001 implementation or certification is a plus.

• Preferred experience with compliance automation platforms, particularly custom tests and APIs.

• Exposure to AI governance, including ISO 42001 or NIST AI RMF, is considered a bonus.

• Experience in building or testing Business Continuity/Disaster Recovery (BC/DR) for production SaaS environments is advantageous.

• A privacy certification such as CIPP is preferred.

• Prior experience working with a security vendor is a plus.


🏝️ Benefits

• A flat, flexible, and fast-paced culture.

• Defined Key Performance Indicators (KPIs) for success with the autonomy to determine how to meet them.

People also viewed

We Insure9 hours ago

Director, Insurance Licensing & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
ExactCare10 hours ago

Compliance Licensing Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job
ApartmentIQ11 hours ago

Multifamily Fee Compliance Expert

US flagUnited States OnlyFull-timeCompliance
ApplyView job
The Center for Aquaculture Technologies (CAT)11 hours ago

VP, Regulatory & Public Affairs

US flagUnited States OnlyFull-timeCompliance$210k – $230k/year
ApplyView job
Lead12 hours ago

Deposits Compliance Analyst

US flagCalifornia, +2 more statesFull-timeCompliance$69.2k – $120.8k/year
ApplyView job
NVIDIA12 hours ago

Governance, Risk, and Compliance Engineer

US flagWashington OnlyFull-timeCompliance$168k – $270.3k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers