
Senior GRC Engineer – Special Programs
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Take ownership of primary account relationship management for intricate, long-term client accounts.
• Foster proactive communication, provide milestone updates, and build executive trust.
• Facilitate client kickoff meetings and milestone review meetings for both yourself and your team.
• Assist clients through audits, risk assessments, evidence gathering, and milestone evaluations.
• Address high-stakes client escalations with professionalism and support long-term client retention.
• Offer daily operational leadership, constructive feedback, and mentorship to junior analyst teams.
• Analyze, interpret, and implement technical security controls that are in line with SOC 2, ISO 27001, HIPAA, and NIST CSF.
• Design, launch, and maintain enterprise cybersecurity policies, procedures, and documentation.
• Enhance internal playbooks, standard operating procedures, and delivery frameworks.
• Manage active client accounts within the first 15 days.
• Provide specialized compliance services for organizations across various industries.
• Minimum of 3 years of experience leading small analyst teams.
• Over 3 years of direct cybersecurity compliance experience with practical execution across SOC 2, ISO 27001, or NIST CSF frameworks.
• Proven experience managing high-complexity accounts, facilitating challenging conversations, and acting as the primary representative in technical engagements.
• Demonstrated ability to oversee multiple complex compliance projects concurrently.
• Proficient in creating, implementing, and enforcing corporate security policies.
• Outstanding written and verbal communication skills in English.
• Familiarity with SOC 2, ISO 27001, or NIST CSF frameworks.
• Experience with Big 4 or top-tier consulting firms is advantageous.
• Exposure to HIPAA, PCI DSS, or related regulatory compliance frameworks is beneficial.
• Practical proficiency with Vanta, Drata, or similar automated GRC platforms is advantageous.
• Recognized certifications such as CISA, CISSP, ISO 27001 Lead Implementer, or Security+ are a plus.
• Experience leading external audits, third-party risk assessments, and auditor evaluations is beneficial.
• Reliable, high-speed internet connection and a professional home office setup.
• Availability to work from 8:00 AM to 5:00 PM U.S. Eastern Time.
• Willingness and capability to travel locally for occasional onsite meetings, team gatherings, or business functions.
• Required to participate in live video interviews with the camera on and confirm identity during the recruitment and onboarding process.
• Employment is contingent upon identity verification and background checks, where permissible by law.
• Must have authorization to work in the U.S. without visa sponsorship, now or in the future.
• Opportunities for career development through mentorship and training.
• Reimbursement for approved training and certification courses relevant to the current position.
• Competitive base salary.
• Regular performance reviews tied to merit-based evaluations.
• Bonus opportunities available.
• Significant potential for career advancement.
• Remote-first flexibility to work from any location while collaborating with a global team.
CrossCountry Mortgage, LLC
Mashreq
Revvity
Stefanini Brasil
Get handpicked remote jobs straight to your inbox weekly.