
GRC Engineer
Posted Jul 3

Posted Jul 3
This is a fully remote position, open to applicants in United States.
• Design, develop, and manage automated controls that align with HIPAA, SOC 2, NIST, ISO 27001, and other relevant frameworks.
• Convert compliance requirements into technical control logic, workflows, integrations, dashboards, and evidence pipelines.
• Create scalable systems that minimize manual compliance efforts and enhance confidence in control effectiveness.
• Collaborate with Security, IT, Compliance, and Engineering teams to integrate control requirements into systems and operational processes.
• Establish and maintain continuous control monitoring capabilities across identity, endpoints, cloud, SaaS platforms, security tools, and business systems.
• Define metrics for control health, including thresholds, alerts, and reporting mechanisms.
• Identify control gaps, exceptions, and deviations, and work with control owners to facilitate remediation.
• Enhance visibility into the design, operation, and effectiveness of critical controls.
• Automate the collection of audit evidence across systems such as Okta, Google Workspace, Jamf, Intune, SentinelOne, Wiz, AWS, Jira, Confluence, Slack, and GRC platforms.
• Develop repeatable evidence workflows that support HIPAA, SOC 2, customer due diligence, vendor assessments, and internal risk reviews.
• Improve the quality, consistency, and traceability of audit evidence.
• Collaborate with Compliance, Legal, and external auditors to lessen audit burdens and enhance readiness.
• Configure and optimize GRC platforms, compliance tools, ticketing systems, documentation repositories, and reporting workflows.
• Create integrations between GRC systems and source systems of record utilizing APIs, webhooks, scripts, and workflow automation tools.
• Develop dashboards and reports that illustrate control health, remediation status, audit readiness, and risk trends.
• Maintain documentation for control logic, data sources, automations, and operational procedures.
• Assist in risk and control assessments by providing technical analysis, control evidence, and tracking remediation efforts.
• Construct workflows for risk acceptance, exception management, corrective action plans, and control remediation.
• Collaborate with control owners to ensure that findings are tracked, prioritized, and resolved.
• Help define metrics that evaluate risk reduction, compliance maturity, and control reliability.
• Assist in assessing how AI tools, LLM platforms, and AI-enabled workflows influence compliance, privacy, and security requirements.
• Support governance controls for enterprise AI adoption, encompassing access, logging, data protection, review workflows, and evidence collection.
• Identify opportunities to responsibly leverage automation and AI to enhance GRC operations.
• Stay informed about emerging strategies for compliance automation, continuous assurance, and AI-enabled GRC.
• 5+ years of experience in GRC engineering, security engineering, compliance automation, IT risk, security operations, cloud security, infrastructure engineering, or a related technical field.
• Practical experience in translating compliance, risk, or security requirements into technical controls, workflows, or automations.
• Familiarity with frameworks such as HIPAA, SOC 2, NIST, ISO 27001, HITRUST, PCI, or FedRAMP.
• Experience with enterprise systems such as Okta, Google Workspace, AWS, Jamf, Intune, SentinelOne, Wiz, Jira, Confluence, Slack, or equivalent platforms.
• Proficiency in using APIs, scripting, or workflow automation tools such as Python, Bash, PowerShell, Workato, Terraform, REST APIs, webhooks, or JSON.
• Experience in audit evidence collection, control testing, remediation tracking, or compliance reporting.
• Familiarity with GRC platforms, compliance automation tools, ticketing systems, or control monitoring systems.
• Strong understanding of access control, endpoint security, cloud security, logging, vulnerability management, and data protection concepts.
• Ability to work across functions with Security, IT Engineering, Compliance, Legal, and business stakeholders.
• Excellent analytical skills, ownership, and the ability to work independently in ambiguous environments.
• Charlie Health offers a comprehensive benefits package to all full-time employees. Learn more about our benefits here.
ZoomInfo
Lifelancer
unybrands
Get handpicked remote jobs straight to your inbox weekly.