Remote job
GRC Engineer
Job details
About this role
Role overview Run and scale a security-compliance program at a fast-moving AI security vendor that sells to enterprise security teams. The work treats compliance like infrastructure: controls mapped once across frameworks, evidence pulled automatically through APIs, and audits that fall out of daily operations. The role partners with engineering, security leadership, and customers who scrutinize the program as closely as any other vendor's.
Responsibilities - Own SOC 2 Type II end to end, keeping the program audit-ready year-round and managing the auditor relationship. - Maintain the risk register, drive treatments forward, and keep an accurate view of company-wide risk. - Keep policies, standards, and procedures current, aligned with operations, and clear for outside readers. - Maintain and exercise business-continuity, disaster-recovery, and incident-response plans, including customer notification commitments. - Own customer security questionnaires and third-party risk reviews, growing the answer library and keeping turnaround fast. - Run vendor and subprocessor risk: review critical vendors, keep DPAs current, and handle customer data requests. - Map controls across multiple frameworks so a single piece of evidence serves many audits. - Expand evidence automation by pulling proof from systems via APIs and scripts.
Requirements - 4+ years in GRC, security compliance, or audit at a SaaS company, with at least one full SOC 2 Type II cycle owned end to end. - Track record of answering enterprise security questionnaires with clear, thread-closing responses. - Technical depth to read architecture diagrams, challenge engineers, and distinguish real controls from paper ones. - Comfort scripting in Python or similar and working with APIs; commitment to not collecting the same evidence twice. - Working knowledge of major privacy regimes as they apply to a data processor. - Organized, self-directed, and candid about open gaps.
Nice to have - ISO 27001 implementation or certification experience. - Compliance automation platform experience, especially custom API-driven tests. - AI governance exposure such as ISO 42001, NIST AI RMF, or building an AI policy from scratch. - BC/DR build or test experience for a production SaaS. - Privacy certifications like CIPP. - Prior work at a security vendor.