Remotery

Senior Security Assurance Engineer

Posted 18 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Design, develop, and manage automated security control monitoring systems.

• Produce production-ready code with version control, peer reviews, and CI/CD processes.

• Transition manual, periodic control testing into continuous control monitoring.

• Engineer self-service technical evidence collection within AWS environments.

• Remove reliance on screenshot-based and ticket-driven evidence collection methods.

• Revamp GRC processes utilizing LLMs and agentic workflows with human oversight and safeguards.

• Maintain a standardized control library aligned with ISO 27001, SOC 2, PCI DSS, SOX, GDPR, and NIST frameworks.

• Develop automated workflows for control-failure detection, enrichment, ticketing, routing, SLA tracking, remediation verification, closure, exceptions, and risk acceptance.

• Collaborate with Platform Engineering, DevOps, and IT to establish preventive guardrails and secure-by-default infrastructure.

• Create dashboards to monitor control health, including automation coverage, evidence freshness, failure rates, remediation times, and audit preparedness.

• Lead both internal and external audits utilizing automated evidence collection.

• Conduct intricate control tests and assessments of third-party and operational security risks.

• Formulate risk treatment strategies and confirm remediation through automated re-testing.

• Review and provide guidance to fellow GRC Engineers regarding automation, queries, and test logic.

• Manage GRC technology, integrations, API-based data flows, and user training.

• Enhance security governance, training, and awareness initiatives.

• Keep GRC documentation, playbooks, runbooks, dashboards, and controlled security documents up to date.

• Achieve quarterly individual Key Results that align with team OKRs.


⛳️ Requirements

• Over 5 years of experience on a GRC or similar team.

• At least 2 years of practical experience in building and maintaining automation systems.

• Proficiency in a minimum of one scripting or programming language, with a preference for Python.

• Experience working with Git, code reviews, and CI/CD methodologies.

• Hands-on experience with AWS services including Config, Security Hub, CloudTrail, IAM, Organizations and SCPs, Lambda, EventBridge, S3/Athena, and CloudWatch.

• Ability to retrieve, normalize, and reconcile data across different systems using APIs and SQL.

• Real-world experience implementing LLMs or AI agents in workflows, including prompt and workflow design, output assessment, human review, and guardrails.

• Familiarity with security tools and cloud environments, including GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, and AWS.

• Knowledge of industry frameworks, regulations, and standards such as ISO 27001, SOC 2, GDPR, PCI, SOX, and NIST.

• Capability to determine adequate audit evidence and justify automated control testing and system-generated evidence to auditors.

• Excellent verbal, written, and presentation skills.

• Preferred: experience with Terraform, CloudFormation, OPA/Rego, AWS Config custom rules, cfn-guard, and large-scale continuous control monitoring; API-based GRC integrations; internal self-service tooling; experience with Big 4 or similar firms.

• Preferred: Bachelor's degree in a relevant field.

• Highly desirable: certifications such as CISSP, CISM, GIAC, AWS Certified Security – Specialty, CCSK, or CCSP.


🏝️ Benefits

• Comprehensive health insurance coverage.

• Life insurance benefits.

• Disability insurance options.

• 401K employer matching program.

• Paid holidays.

• Self-care days.

• Paid time off (PTO).

• Bonus opportunities or commission plans.

• Stock options available.

• Equipment and support for remote work and team collaboration.

• Access to the LinkedIn Learning platform.

• Opportunities for learning and development initiatives.

• Quarterly wellness education sessions.

• Wellness days provided.

• Events hosted by Employee Resource Groups (ERGs).

• Paid parental leave.

People also viewed

FRSecure15 hours ago

Information Security Assessor

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$85k – $95k/year
ApplyView job
Synack, Inc.16 hours ago

Manager, Information Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$150k – $180k/year
ApplyView job
Coinbase16 hours ago

Product Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$154k/year
ApplyView job
GoodLeap18 hours ago

Senior Security Engineer, Product Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$146k – $185k/year
ApplyView job
Vultr18 hours ago

Physical Security System Designer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$90k – $10k/year
ApplyView job
Vultr18 hours ago

Physical Security Evaluator

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$80k – $100k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers