Source Job

US 4w PTO

  • Manage inbound security questionnaires from partner physician practices.
  • Lead security evaluations for Aledade’s vendors and analyze SOC2 reports.
  • Maintain and optimize our security response repository and identify bottlenecks.

SOC2 HIPAA HITRUST Risk Management

20 jobs similar to Security Engineer II (GRC)

Jobs ranked by similarity.

US

  • Drive execution of complex technical programs at the intersection of Security, Engineering, and Compliance.
  • Translate complex technical initiatives into clear programs that meet security and regulatory obligations.
  • Influence security strategy and drive alignment across Engineering, Compliance, and People Ops.

Rula is dedicated to treating the whole person and creating a world where mental health is embraced. They are a remote-first company that strives to be a force for positive change in the field of mental healthcare and hire in most U.S. states.

US

  • Own vulnerability management, SIEM tuning and monitoring, incident response, and threat investigation.
  • Maintain secure baseline configurations based on industry standards.
  • Oversee AWS security controls and enforce cloud security guardrails.

Jobgether posts this position on behalf of a partner company. They use an AI-powered matching process to ensure applications are reviewed quickly and fairly.

Global

  • Maintain and improve security policies and controls across the platform.
  • Perform compliance validation and prepare for audits.
  • Conduct risk assessments on new workloads and track mitigation actions.

Jobgether is a platform that connects job seekers with companies. They use AI-powered matching to ensure applications are reviewed quickly and fairly. We do not have enough information to assess the company size and culture.

$135,000–$150,000/yr
US Unlimited PTO 12w maternity 4w paternity

  • Lead customer due diligence questionnaire (DDQ) and RFP response process and third-party risk management process.
  • Support enterprise sales with technical customer security discussions.
  • Lead SOC 2 Type II audit preparation, evidence collection, and remediation.

Vanilla is an AI-powered estate advisory platform that aims to modernize estate planning. They are a startup distributed across the U.S. with a mix of fully remote and hybrid roles that embraces flexibility and values curious builders and problem-solvers.

$140,000–$175,000/yr
US 3w PTO

  • Drive and enable proactive identification, analysis, and remediation of security vulnerabilities.
  • Respond to manage pen testing and bug bounty programs.
  • Work in partnership with Software Architecture, Risk/Compliance, the SRE team, and other partners, to integrate security capabilities into the SDLC.

Subsplash builds The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. They are a family-owned and operated company of 290+ mission-driven people.

$120,000–$160,000/yr
US Unlimited PTO 12w maternity

  • Own and lead Impiricus’s security architecture across AWS.
  • Design and implement application and infrastructure security controls across the SDLC.
  • Build and operate detection and response capabilities, including logging, monitoring, and alerting.

Impiricus is an AI-powered HCP Engagement Engine transforming how life sciences companies support physicians. They ethically connect HCPs to pharma resources and are known for their unique access to a large network of HCP advisors.

$130,000–$186,000/yr
US

  • Create, manage, and maintain the application security strategy and roadmap.
  • Develop, execute, and track the performance of security measures to protect Alma’s data, applications, and systems.
  • Build and provide high-quality application security documentation and training to engineers.

Alma simplifies access to high-quality, affordable mental health care by making it easy and financially rewarding for therapists to accept insurance. Alma has over 20,000 therapists in their growing network and was named one of Inc’s Best Workplaces in 2022 and 2023.

US Unlimited PTO

  • Deliver world-class cyber security assessment and advisory services across multiple Compliance offerings.
  • Work effectively as a team member on large engagements and remain current on technical knowledge.
  • Demonstrate GuidePoint’s Core Values at all times and achieve and maintain relevant cyber security and audit certifications.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. Since its inception in 2011, GuidePoint has grown to over 1000 employees and firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere.

$103,500–$158,000/yr
US

  • Respond to customer and prospect security questions.
  • Maintain knowledge repository and artifacts for customer due diligence.
  • Improve security content with a customer-first mindset.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company built on trust, transparency, and creativity. From entrepreneurs to global enterprises, they empower teams to design, launch, and optimize for the web without barriers.

US

  • Lead execution of the enterprise information security program.
  • Oversee threat detection/response, vulnerability management, and incident response processes.
  • Partner with Engineering and Infrastructure teams to secure cloud environments and CI/CD pipelines.

bswift transforms benefits administration, making it simpler and smarter. They serve thousands of companies and millions of people nationwide, reducing administrative burdens and freeing HR teams to focus on creating thriving, people-first workplaces.

$149,500–$169,202/yr
US

  • Design, build, and maintain security tools, scripts, and automations.
  • Partner with Engineering teams to manage and drive remediation of security vulnerabilities.
  • Evaluate and prioritize security risks based on industry standards and business context.

Weedmaps is a global leader in the cannabis industry. They are dedicated to transparency, education, and community, serving cannabis to consumers and businesses in the U.S. and worldwide.

Global

  • Maintain and improve security policies and controls across the platform.
  • Perform compliance validation and prepare for audits.
  • Conduct risk assessments on new workloads and track mitigation actions.

Jobgether is a platform that connects job seekers with companies. They appear to value teamwork and innovation, and invest in employee growth.

$130,000–$140,000/yr
US UK

  • Design, deploy, and manage security tools and infrastructure to detect and prevent threats across cloud (AWS and GCP), corporate, and product environments.
  • Work collaboratively with engineering and product teams to integrate security into the SDLC (Secure Software Development Life Cycle) via threat modeling, code reviews, and automated testing.
  • Conduct security assessments, penetration testing, and vulnerability management to identify and remediate risks in our applications and services.

Acorns is a financial wellness app helping people and families save and invest money for the long term. Since 2014, Acorns has grown into a global company with multiple life-stage products serving the needs of kids, teens, adults, and parents.

US

  • Design and automate Azure security controls.
  • Build “secure‑by‑default” CI/CD and tooling.
  • Lead incident response and ensure compliance with HIPAA, SOC 2, and HITRUST.

IntusCare is dedicated to providing a HIPAA-compliant healthcare platform for vulnerable elderly populations. As a fast-growing startup, they are scaling to support hundreds of customers and prioritize security.

5w PTO

  • Provide consistent and qualified responses to tenders and assurance questionnaires from customers.
  • Produce and maintain security assurance documentation required for accreditation.
  • Ensure compliance with relevant security standards, service management procedures, regulations, and industry best practices.

NEC Software Solutions is part of global tech giant NEC Corporation and has over 3,000 employees. They provide software to dispatch ambulances, support families, keep trains on the move, locate missing people and even test the hearing of newborn babies, working with governments, hospitals, police forces, housing providers, local authorities and more.

$94,000–$178,500/yr
US

  • Serve as a cloud security technical expert to develop and execute cloud security policies and procedures.
  • Collaborate with cloud technology teams across the enterprise to ensure the integrity and security of our digital assets in AWS/Azure IaaS environments.
  • Demonstrate high proficiency across a wide range of cloud security technologies to establish guardrails to prevent or automatically remediate common security misconfigurations.

AbbVie discovers and delivers innovative medicines and solutions that solve serious health issues today and addresses the medical challenges of tomorrow. It strives to have a remarkable impact on people's lives across several key therapeutic areas.

US Canada Unlimited PTO

  • Own and lead the delivery of large, multi-quarter Application Security and Engineering initiatives.
  • Improve existing complex application security architectures and provide guidance for securing AI-based workflows.
  • Proactively identify emerging industry threats and act as Incident Commander for large-scale security incidents.

Wrapbook provides a unified payroll platform that seamlessly connects your entire team in one place. It empowers production teams to manage projects, pay cast and crew, track expenses, and generate data-driven insights. With a growing team of 250+ people across the USA and Canada, Wrapbook is backed by top-tier investors and has raised $130M.

Europe US

  • Collaborate with cross-functional teams to maintain and improve the company's comprehensive compliance program.
  • Manage the end-to-end audit process for SOC 2 compliance, ensuring timely and accurate completion.
  • Oversee the Information Security Risk Management Program, documenting identified risks, coordinating mitigation efforts.

airSlate is a global SaaS technology company that develops no-code workflow automation, electronic signature, and document management solutions. They have teammates in more than 20 countries across three continents and main hubs in the United States, Poland, Romania, Ukraine and Philippines.

$120,000–$165,000/yr
US

  • Serve as the system Security Manager / ISSO for My HealtheVet and act as the primary security point of contact for internal leadership and VA stakeholders.
  • Drive a risk-based security approach appropriate for a FISMA High / HVA system.
  • Coordinate incident response activities, including investigation support, escalation, documentation, and communication with VA security operations and CISO teams.

Oddball believes that the best products are built when companies understand and value the things they are working on. They value learning and growth and the ability to make a big impact at a small company.

US

  • Play a critical role in the technical development, implementation, and maintenance of the GRC platform.
  • Drive integration strategies between GRC platforms and enterprise systems for automated data sharing and reporting.
  • Provide expert guidance and leadership on GRC technical matters to senior leadership and business stakeholders.

Jobgether is a platform helping candidates find jobs. They use AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements.