
GRC Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in California, +3 more states.
• Develop and oversee the process for managing customer security questionnaires, assessments, and due diligence requests.
• Participate in calls with customers and prospects to articulate the company's security posture, controls, architecture, and risk management practices.
• Create and sustain reusable trust materials, including standard responses, evidence packages, security documentation, and content for the trust center.
• Oversee compliance programs and audits, such as SOC 2 and ISO 27001, from preparation through evidence collection, testing, remediation, and continuous monitoring.
• Automate processes for evidence collection, control monitoring, questionnaire responses, and repetitive GRC workflows.
• Maintain policies, risk registers, control mappings, vendor reviews, and remediation plans.
• Collaborate with Product, Engineering, IT, Legal, Sales, and Customer Success teams on security and compliance requirements.
• Convert regulatory, contractual, and customer requirements into actionable product and operational controls.
• Engage in product design and roadmap discussions, identifying control requirements and proposing secure, scalable, and user-friendly solutions.
• Monitor evolving customer expectations and compliance requirements, assisting in prioritizing enhancements to the security program.
• Establish metrics that demonstrate the effectiveness, efficiency, and business impact of the GRC and customer trust program.
• Proven experience in GRC, security assurance, customer trust, compliance, security engineering, or a related area.
• Practical experience in completing customer security questionnaires and facilitating customer security assessments.
• Excellent written and verbal communication skills, with the ability to clearly convey technical and compliance concepts to both technical and non-technical audiences.
• Experience in managing or contributing to SOC 2, ISO 27001, NIST CSF, NIST 800-53, or other similar frameworks.
• Familiarity with SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk management.
• Capability to critically assess evidence rather than merely viewing compliance as a checklist.
• Strong project management abilities and comfort in coordinating efforts across various teams.
• Interest in leveraging APIs, scripts, integrations, AI, or GRC platforms to minimize manual workloads.
• A genuine curiosity about product design and integrating controls into systems from the outset.
• Sound judgment in balancing security, customer commitments, usability, and business needs.
• Experience in startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or other technology companies focused on security (optional).
• Knowledge of GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP (optional).
• Familiarity with GRC automation, trust center, or questionnaire management platforms (optional).
• Ability to interpret technical architecture diagrams, audit logs, configurations, and code to verify control design and evidence (optional).
• Experience in designing product-level controls (optional).
• Relevant certifications like CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor; while certifications are beneficial, they are not mandatory.
• An inclusive workplace dedicated to welcoming, respecting, and empowering every team member.
• An equal opportunity employer.
• A work environment that is free from discrimination and harassment.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.