
Senior GRC Engineer
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in Massachusetts.
• Oversee audit preparedness and evidence management for SOC 2, ISO 27001, ISO 27701, and privacy frameworks with a focus on automation.
• Design and implement automated workflows that evolve point-in-time audits into continuous compliance monitoring across cloud and SaaS platforms.
• Handle customer assurance inquiries, security questionnaires, and due diligence processes to uphold customer confidence and enhance business operations.
• Collaborate with Engineering, Security, Legal, Privacy, and Product teams to embed compliance controls within software development and operational workflows.
• Keep security policies, controls, and compliance documentation up to date to meet changing regulatory standards.
• Proven experience in GRC, cybersecurity, or IT audit in SaaS or cloud settings, ideally within AWS.
• Practical experience in facilitating multi-framework audits like SOC 2 or ISO 27001, as well as managing customer security due diligence processes.
• Ability to interpret regulatory standards and convert compliance controls into practical engineering and operational workflows.
• Solid understanding of cloud security principles, automation technologies, and workflow tools utilized to enhance compliance operations.
• Relevant professional certifications such as Security+, CISA, CRISC, or ISO 27001 Internal Auditor are advantageous.
• Flock Stock Options
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.