GRC Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in North America.

πŸ“‹ Description

β€’ Take full responsibility for SOC 2 Type II and HIPAA compliance from start to finish, encompassing scoping, control design, evidence collection, auditor walkthroughs, and remediation efforts.

β€’ Define and lead the implementation of the next compliance framework, likely ISO 27001, in accordance with customer requirements.

β€’ Develop and sustain integrations that feed the GRC platform from various cloud providers, SaaS applications, and internal systems.

β€’ Transform controls into continuous monitoring using policy-as-code, configuration drift detection, and a control-failure pipeline.

β€’ Manage the vendor security review program from intake through to periodic re-assessment.

β€’ Oversee the security questionnaire and trust center workflow.

β€’ Maintain the risk register and perform risk assessments that yield documented decisions.

β€’ Integrate compliance requirements into the SDLC and change management via tooling.

β€’ Minimize the manual effort needed to successfully navigate quarterly audits.


⛳️ Requirements

β€’ A minimum of 5 years of experience in security, with a proven track record of creating automation for a GRC or compliance program.

β€’ Technical leadership in at least one SOC 2 Type II or ISO 27001 audit.

β€’ Proficient in coding and effectively utilizing LLMs without compromising quality.

β€’ Hands-on experience with the API of a GRC platform.

β€’ Expertise in Cloud IAM and configuration for at least one provider; GCP is preferred.

β€’ Capability to identify sufficient evidence and present an automated test to an auditor convincingly.

β€’ Ability to define, prioritize, and implement tasks independently within a small security engineering team.

β€’ Strong writing skills necessary for policies, control narratives, and responses to questionnaires.

β€’ Experience in an all-remote company is a plus.

β€’ Production experience in deploying LLM or agent-based workflows for compliance tasks is advantageous.

β€’ Background in a developer-tools company is a plus.


🏝️ Benefits

β€’ Competitive salary.

β€’ Stock option plan / equity ownership.

β€’ Comprehensive health insurance.

β€’ Choice of home office equipment.

β€’ Unlimited vacation policy with a recommendation of 25 days per year.

β€’ National holidays based on the country of residence.

β€’ A diverse and inclusive team distributed globally.

People also viewed

biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job
The Standard1 day ago

Investigative Consultant – Business Ethics, Compliance

US flagOregon OnlyFull-timeCompliance$88k – $129k/year
ApplyView job
American Health Staffing Group1 day ago

Compliance Coordinator

US flagOklahoma, +1 more stateFull-timeCompliance$45k – $55k/year
ApplyView job
GE Vernova1 day ago

Packaging Engineer – Regulatory & Compliance Manager

US flagUnited States OnlyFull-timeCompliance$98.4k – $164k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers