Remote job
Staff GRC Engineer
Job details
About this role
Role overview
Bring an engineering mindset to governance, risk, and compliance as a Staff GRC Engineer. This senior, hands-on role is for someone who believes compliance should be automated, continuous, and backed by real evidence pulled directly from systems rather than assembled manually each audit cycle. You will build the tooling, integrations, and pipelines that turn the control framework into code and give the organization continuous visibility into its compliance posture.
Responsibilities
- Build and operate compliance automation, including continuous controls monitoring, automated evidence collection, and control testing across cloud and corporate systems. - Implement compliance-as-code and policy-as-code so controls are defined, versioned, tested, and enforced programmatically. - Integrate GRC tooling with the systems that hold the evidence, such as cloud providers, identity providers, ticketing, CI/CD, and HRIS, via APIs. - Build dashboards and reporting that give real-time visibility into control health, drift, and audit readiness. - Reduce audit burden by automating the collection and packaging of evidence for SOC 2, ISO 27001, and other frameworks. - Partner with GRC analysts and risk owners to translate control requirements into technical checks and remediation workflows. - Automate access reviews, risk assessments, and vendor risk workflows. - Set engineering standards for the GRC function and mentor analysts and engineers on automation.
Requirements
- Significant experience, typically 8 or more years, spanning security or GRC and software engineering, with a strong hands-on engineering background. - Strong programming skills in Python, Go, or similar languages, with comfort building integrations against APIs. - Working knowledge of compliance frameworks such as SOC 2 and ISO 27001, including what evidence and control testing actually require. - Experience with cloud environments such as AWS, GCP, or Azure, and with infrastructure-as-code. - Familiarity with GRC or compliance automation platforms and continuous controls monitoring concepts. - Ability to lead cross-team initiatives and translate effectively between compliance and engineering.
Nice to have
- Experience implementing compliance-as-code or building custom GRC tooling. - Familiarity with policy-as-code tools such as OPA and with drift detection. - Prior experience surviving audits and knowing where the manual pain lives. - Relevant certifications such as CISA or CISSP.
Benefits and work setup
- Listed salary: $220,000. - Listed values include a client-first orientation, startup-speed execution, and an AI-forward approach to internal work.