GRC Engineer at security team to strengthen governance, risk, and compliance programs. Collaborating with technical security engineers to protect customer data.
Responsibilities
Own compliance programs including ISO 27001 and SOC 2, coordinating audits, managing evidence collection, and maintaining certifications
Implement and manage a GRC automation platform (Drata, Vanta, or similar) to streamline compliance workflows and continuous monitoring
Develop and refine security policies and procedures that meet regulatory requirements while remaining practical for engineering teams
Assess risks across production, non-production, and QA environments, prioritizing security initiatives based on business impact and compliance obligations
Bridge technical and business stakeholders by translating security requirements into language appropriate for different audiences
Manage vendor security assessments and third-party risk reviews in partnership with procurement and legal teams
Develop metrics and reporting that give leadership visibility into compliance status and risk landscape
Requirements
Strong hands-on experience with AWS environments and cloud security controls (EC2, IAM, CloudTrail, Config, Security Hub, etc.)
Scripting skills in Python, Bash, or similar languages to automate compliance tasks and evidence collection
Proven experience implementing and managing GRC automation tools such as Drata, Vanta, or similar platforms
Understanding of compliance frameworks like ISO 27001, SOC 2, GDPR, and CCPA (formal audit experience not required)
Comfort reading technical documentation and collaborating with engineering teams
Strong project management skills with ability to manage multiple compliance initiatives simultaneously
Clear communication skills for both technical and non-technical audiences
Technical background preferred over traditional audit experience
Certifications like AWS Security Specialty, CRISC, CISA, or CISSP a plus
Compliance Specialist overseeing regulatory adherence for youth programs in Gainesville. Ensuring DCF compliance and supporting youth program safety and integrity.
Technologist at FortisBC ensuring compliance with BCUC Critical Infrastructure Protection Standards. Focus on integrating business technology and providing technical support.
Compliance Examiner Business Lead at Freddie Mac conducting on - site examinations and ensuring financial activities align with laws. Engaging with financial institutions to enhance operational effectiveness.
Compliance Professional supporting Freddie Mac's investment and ethics policies. Engaging with compliance risks and overseeing regulatory obligations to promote best practices.
Compliance Officer at Hewlett Packard Enterprise ensuring adherence to compliance regulations, managing AML programs, and conducting risk assessments. Driving compliance culture across markets and delivering training to employees.
Risk Manager at Cisco Capital ensuring regulatory compliance and effective risk management practices. Focus on safeguarding financial health and collaboration within an international environment.
Regulatory Reporting Specialist managing outsourced reporting service providers in Germany and Spain. Ensuring compliance with banking regulations and supporting audits and reviews.
Assisting partners at Clyde & Co with business inception processes and anti - money laundering procedures. Involves reviewing requests and conducting conflict checks within the firm's compliance framework.
Senior Analyst, OSS Compliance managing open - source software assets for The Hartford. Ensuring compliance and visibility into OSS usage as part of software asset management process.