Remote job
GRC Engineer
Job details
About this role
Role overview A distributed developer-infrastructure company is hiring a senior Governance, Risk, and Compliance (GRC) engineer to own and automate its security assurance program. The role sits on a small security team and centers on turning manual audit work into continuous, code-driven controls. Success means customer security reviews become routine rather than fire drills.
Responsibilities - Drive SOC 2 Type II and HIPAA programs end to end, including scope, control design, evidence collection, auditor walkthroughs, and remediation tracking - Scope and lead the next major framework adoption (likely ISO 27001) based on what prospective and current customers request - Build and maintain integrations that pull data from cloud providers, SaaS tools, and internal systems into the GRC platform - Convert controls into continuous checks using policy-as-code, configuration drift detection, and automated failure-to-resolution pipelines - Operate the vendor security review program, from initial intake through periodic re-review - Own the security questionnaire and trust-center content workflow - Maintain the risk register and run risk assessments that produce documented decisions - Embed compliance requirements into the software development lifecycle and change management so they are enforced by tooling
Requirements - At least 5 years in security, with hands-on experience building automation for a GRC or compliance program - Technical ownership of at least one SOC 2 Type II or ISO 27001 audit, with perspective on what to do differently next time - Strong programming skills and practical use of large language models to accelerate work without reducing quality - API-level fluency with a GRC platform, not just dashboard administration - Deep knowledge of cloud IAM and configuration on at least one major provider, preferably GCP - Ability to judge what evidence satisfies an auditor and defend automated tests during review - Comfort operating with minimal process as one of a few security engineers, able to scope, prioritize, and ship independently - Clear written communication for policies, control narratives, and customer-facing questionnaire responses
Nice to have - Prior experience at a fully remote company - Production experience shipping LLM or agentic workflows applied to compliance work - Background at a developer-tools company
Benefits and work setup - Competitive compensation with equity participation through a stock option plan - Comprehensive health insurance coverage - Home office gear stipend to set up a productive workspace - Unlimited paid time off, with a recommended baseline of 25 days per year plus country-specific public holidays - Globally distributed team with an explicit commitment to diversity and inclusion