
GRC Engineer
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Take ownership of the company risk register and enhance AI-driven risk management workflows.
• Oversee SOC 2 Type II external audit management and streamline evidence collection using Vanta.
• Initiate the planning for an ISO 42001 readiness pathway.
• Develop scalable intake processes for Trust and Assurance, including triage, AI-assisted questionnaire responses, and self-service trust portal functionalities.
• Create automated systems for vendor and supply chain risk intake, tiered scoring, and continuous monitoring.
• Revamp and uphold security and privacy policies utilizing AI-assisted drafting, versioning, approval, and attestation workflows.
• Manage common controls monitoring in Vanta to ensure a consistent compliance posture.
• Update and enhance security awareness and training initiatives.
• Design and maintain an integrated compliance calendar featuring automated reminders and status tracking.
• Assist in operational privacy practices, which encompass cookie consent management, data subject requests, privacy notices, and data mapping inventory.
• Keep track of regulatory and compliance updates, including the EU AI Act, NIST AI RMF, and ISO 42001.
• Exhibit measurable improvements in efficiency through the use of AI tools, automation, and workflow engineering.
• Report directly to the CISO as an individual contributor.
• A minimum of 3 years of experience in Governance, Risk Management, and Compliance (GRC), information security compliance, or risk management.
• Proficient understanding of SOC 2 Trust Services Criteria.
• Hands-on experience in supporting or leading audit processes.
• Familiarity with various frameworks, including CIS Controls v8, NIST CSF, NIST AI RMF, NIST Privacy Framework, NIST SP 1800 series, NIST 800-53 r5, ISO 42001, ISO 27701, ISO 27001, OWASP Top 10 for Agentic Applications, MITRE D3FEND, MITRE SoT, and MITRE ATLAS.
• Experience in conducting quick third-party/vendor risk assessments.
• Proven track record in managing a supply chain risk program.
• Strong organizational abilities to handle multiple workstreams and meet deadlines.
• Exceptional written communication skills with the capability to draft clear, audience-appropriate policies and executive risk summaries.
• Familiarity with Vanta or a comparable platform.
• Demonstrated experience in utilizing AI tools in both professional and personal contexts.
• Relevant certifications such as CISA, CRISC, CISSP, or CIPP are advantageous.
• Authorization to work in the United States without any current or future visa sponsorship.
• Comprehensive Medical, Dental, and Vision plans (ButterflyMX covers 80% of the cost) starting from day 1.
• A 401(k) plan with matching contributions.
• 10 paid holidays, 20 vacation days, 5 sick days, and 3 floating holidays.
• Basic Life and Accidental Death and Dismemberment Insurance (ButterflyMX covers 100% of the cost).
• Short and Long Term Disability Insurance (ButterflyMX covers 100% of the cost).
• Paid Family Leave.
• Employee Assistance Program.
• Quarterly self-care stipends.
• Optional pre-tax flexible healthcare spending accounts (FSA and HSA).
• Dependent Care FSA.
• Commuter Benefits.
• Optional Supplemental Life, AD&D, Hospital Indemnity, Legal, Accident, Critical Illness, Pet, and Personal Liability Insurance.
• Potential eligibility for bonuses, equity, or other forms of compensation.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.