Senior GRC Engineer

A-LIGN

Remote regions

US

Benefits

Similar Jobs

See all

About the Role:

  • The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's compliance frameworks, including FedRAMP, ISO 27001, and SOC 2.
  • This role bridges the GRC function and technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to keep A-LIGN continuously audit-ready.
  • Reports to the Chief Information Security Officer and supports broader information security activities.

Responsibilities:

  • Own end-to-end audit evidence collection, validation, and organization across FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171.
  • Maintain and continuously verify technical controls across cloud and corporate environments, including GCP, GitHub, and Microsoft 365/Entra ID.
  • Serve as the primary liaison between GRC and technical departments to gather evidence, validate controls, and reduce audit burden.

Minimum Qualifications:

  • Bachelor's degree in information systems, cybersecurity, or equivalent; 5+ years in GRC, IT audit, or compliance engineering.
  • Hands-on experience with audit evidence collection and technical control validation for at least two of: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171.
  • DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments.

A-LIGN

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

Apply for This Position