Skip to content

Jobgether

Commercial GRC Engineer - Sr. Security Engineer

Compensation
$175K–$227.5K / yr
From job posting
Location
US
Arrangement
Remote
Employment type
Full-time
Level
Senior
Posted
30 September 2026 (today)

Checked todayApplications go to the employer, never to RoleSprint

About this role

Accountabilities: • Own control automation for SOC 2, ISO 27001/27017/27701, HIPAA, and related commercial frameworks by designing automated evidence collection and continuous control monitoring across cloud, identity, endpoint, and SaaS systems.

• Express controls, control tests, and cross-framework mappings as version-controlled code so they remain reviewable, testable, reusable, and maintainable.

• Translate compliance requirements into technical control logic, workflows, and integrations while partnering with engineering, IT, and security teams to embed controls into existing systems and pipelines.

• Shift compliance left by contributing to architecture and design reviews, defining control requirements as acceptance criteria, and helping teams build compliant-by-default infrastructure.

• Design engineer-facing compliance experiences, including self-service control status, guardrails, paved-road patterns, and compliance feedback delivered through tools such as CI/CD, Jira, and Slack.

• Evaluate whether controls meaningfully reduce relevant risk and propose alternative controls when standard framework requirements do not align with the applicable threat model or workload architecture.

• Support audit cycles end-to-end by coordinating evidence requests, maintaining evidence libraries, responding to auditor follow-ups, and tracking remediation items through closure.

• Build and maintain dashboards and reporting that provide visibility into control health, evidence freshness, and audit readiness across multiple frameworks.

• Identify opportunities to eliminate duplicate evidence-gathering efforts by mapping controls once and reusing those mappings across SOC 2, ISO, and HIPAA.

• Diagnose recurring control failures and stale evidence by identifying root causes and improving the underlying processes, tooling, or ownership models.

• Partner with GRC and engineering stakeholders to expand control, evidence, and risk-lifecycle capabilities within internal platforms.

Requirements

• 4+ years of experience in GRC engineering, security engineering, compliance automation, IT audit support, or a related field, with hands-on ownership of at least one complete certification cycle such as SOC 2 or ISO 27001.

• Practical experience with GRC or compliance automation platforms such as Vanta, Drata, Secureframe, or comparable internal solutions, including configuring integrations and building evidence pipelines.

• Strong understanding of cloud security fundamentals, including AWS, GCP, or Azure IAM, logging, encryption, and their relationship to compliance controls.

• Solid working knowledge of SOC 2, ISO 27001, and ideally ISO 27017/27701 and HIPAA requirements, with the ability to map controls across frameworks and reduce duplicated evidence work.

• Comfort with scripting or light development using Python, JavaScript, or similar technologies to build integrations, automate evidence collection through APIs, or extend GRC tooling.

• Strong written communication skills, with the ability to document controls, gaps, and remediation plans clearly for both external auditors and internal engineering teams.

• A stakeholder-focused approach, with an emphasis on making compliance easier for engineers to maintain rather than simply accelerating evidence production.

• Demonstrated ability to trace control failures or audit findings to their root causes and drive durable remediation across teams.

• Legally eligible to work in the United States on an ongoing basis.

Benefits

• U.S. base salary range of $175,000 - $227,500 USD .

• Market-competitive incentive opportunity in addition to base compensation.

• Employer-subsidized medical, vision, and dental coverage for eligible full-time employees.

• 401(k) match covering 50% of employee contributions up to the first 6% of eligible pay.

• Monthly stipend to support work and productivity.

• Flexible Time Away Program plus sick time off.

• Employer-sponsored life insurance and short- and long-term disability coverage.

• 12 paid holidays per year.

• Up to 24 weeks of parental leave.

• One paid volunteer day each year.

• Professional growth and development opportunities, including access to Udemy courses.

• Additional funded perks, including counseling membership, local retail discounts, and access to a personal work account.

• Teleworking options from registered locations across the U.S., depending on role requirements.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Work location

  • US

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 30 September 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free