Source Job

Global

  • Own SOC 2 end to end, run auditor relationships, and keep the program audit-ready year round.
  • Run risk management, policy, BC/DR, and vendor/subprocessor programs with automated evidence.
  • Lead security questionnaires and TPRM reviews to close deals and scale compliance across frameworks.

Compliance SOC 2 Risk Management Python Security

20 jobs similar to GRC Engineer

Jobs ranked by similarity.

GRC Lead

Unknown
$160,000–$230,000/yr
Global

  • Own customer security reviews and compliance programs, driving fast and accurate responses.
  • Ensure practical risk decisions and reliable security answers through automation and AI.
  • Scale the function by building processes and self-service resources."

The company is a technology company that builds quickly and focuses on security and compliance. It is a remote-first small team with a culture of autonomy and growth.

US 3w PTO

  • Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
  • Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
  • Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.

The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

$180,000–$220,000/yr
US

  • Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
  • Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
  • Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.

AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.

Global

  • Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
  • Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
  • Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.

Duvo builds an AI operations platform for large enterprises, enabling customers to create AI agents that automate business-critical processes across systems like SAP, spreadsheets, and supplier portals. The company is growing fast and values velocity, direct feedback, autonomy, and heavy use of AI tools.

Global 4w PTO

  • Act as part vCISO and account manager, guiding clients through security and compliance programs.
  • Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
  • Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.

Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.

$175,000–$200,000/yr
US Canada

  • Lead compliance programs including SOC 2, GDPR, CCPA/CPRA, and Shopify partner security requirements.
  • Own security policies, risk management, business continuity, and incident response.
  • Manage IT operations, endpoint security, and cloud security across the company.

Rebuy revolutionizes shopping with intelligent, personalized experiences for DTC brands. They are a fully remote team with a culture rooted in ownership, drive, and empathy.

Global

  • Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
  • Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
  • Assess risks of emerging technologies and drive continuous compliance improvements across the organization.

Picus Security is an exposure validation company that proves what attackers can exploit and what defenses stop, turning exposures into defensible decisions. As a fast-growing global remote team, it values continuous security validation and has a 95% recommendation rate.

US 3w PTO

  • Lead Atmosera's internal GRC program and managed GRC service delivery.
  • Manage federal System Security Plans, POA&Ms, and audit responses.
  • Serve as a senior GRC advisor bridging executive and technical teams.

Atmosera empowers businesses to redefine what's possible with modern technology and human expertise across Applications, Data & AI, DevOps, Security, and Microsoft Azure. As a Microsoft Partner with seven specializations, the company values humility, hunger, and mindfulness in a collaborative team environment.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

$114,800–$165,000/yr
US

  • Own Abnormal's governance committees, including AI, Data, and Security Governance.
  • Manage the enterprise policy program end-to-end, from drafting to stakeholder acknowledgment.
  • Oversee risk management operations, including risk assessments, exceptions, and audits.

Abnormal AI protects the humans behind the world's most critical organizations from AI-powered cybercrime. Over 5,000 enterprises trust our behavioral AI platform, and we offer a collaborative, fast-paced security culture.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.

US

  • Lead and mature the organization's governance, risk management, compliance, and audit programs.
  • Own cybersecurity compliance initiatives including CMMC Level 2, SOC audits, and SOX IT General Controls.
  • Partner with business, technology, and executive stakeholders to align security controls with regulatory and business requirements.

Loenbro is a trusted construction lifecycle partner serving thousands of customers across the U.S. with services including electrical, mechanical, structural, inspection, and fabrication. The company has a national presence with a local approach and fosters a culture of integrity, teamwork, and purpose.

$80,000–$90,000/yr
US

  • Support day-to-day execution of IT risk, compliance, privacy, and governance programs.
  • Review client agreements and security questionnaires, coordinating redlines with legal.
  • Manage control evidence, vendor risk, data retention, and compliance policies.

Our partner provides IT risk, compliance, privacy, and governance services for clients. They have a small, collaborative team and value diverse perspectives and authentic contributions.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Anovia is an industry-leading technology outsourcing support provider specializing in workflow and knowledge processes, technical support, helpdesk, and multilingual services. With over 200 experts globally, we serve Fortune 500 companies and value growth, learning, and work-life balance.

$130,000–$150,000/yr
US

  • Own and mature security, privacy, and compliance programs across HIPAA, SOC 2, and HITRUST.
  • Lead HITRUST certification end to end, including scoping, evidence collection, and assessor coordination.
  • Partner with Engineering, Product, SRE, and IT to integrate security into architecture, SDLC, and cloud infrastructure.

IntusCare is an end-to-end ecosystem built specifically to help PACE programs deliver exceptional care, strengthen financial performance, and stay compliant. It is a growing healthcare SaaS organization that empowers teams to improve outcomes for dual-eligible seniors.

India Unlimited PTO

  • Define Sprinto's Professional Services portfolio and build a scalable delivery function.
  • Lead audit delivery partnerships and ensure independence and quality standards.
  • Work closely with Product to convert customer and auditor feedback into product improvements.

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we have raised $31.8M in funding and are trusted by over 4,000 organizations across 75 countries.

$160,000–$180,000/yr
US

  • Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
  • Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
  • Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.

Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.

India

  • Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
  • Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
  • Manage third-party risk assessments and track remediation of security findings.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They partner with companies to manage applications and hiring processes, offering remote roles and streamlined recruitment.