Source Job

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

GRC Cloud Security Risk Management Automation

20 jobs similar to Senior GRC Engineer

Jobs ranked by similarity.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

India Unlimited PTO

  • Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
  • Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
  • Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.

Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

US Unlimited PTO

  • Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
  • Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
  • Answer customer security questionnaires and ensure compliance documents are accurate.

Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.

US

  • Execute NIST SP 800-53 control mappings and implement security baselines.
  • Develop and maintain SSPs, POA&Ms, and authorization documentation.
  • Support continuous monitoring and gap assessments for ATO and FedRAMP.

This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.

$139,000–$218,000/yr
US

  • Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
  • Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
  • Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.

Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.

$174,000–$238,000/yr
US

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
  • Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.

Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.

US

  • Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
  • Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
  • Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.

Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.

Global Unlimited PTO

  • Own and mature the compliance framework, including continuous controls monitoring, security awareness, and audit coordination.
  • Automate GRC processes using compliance platforms and AI tooling for evidence collection and risk management.
  • Develop policies, manage third-party risk, and scale customer security assurance end-to-end.

Monarch is an all-in-one personal finance platform that simplifies finances. Since 2021, they have become the top-recommended app, with a fully remote, AI-driven team focused on building a product people love.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

Germany

  • Drive end-to-end execution of GRC programs, leading audit strategy and cross-functional compliance projects.
  • Manage internal risk workflows, evidence collection, and remediation efforts for audits like SOC 2 and PCI DSS.
  • Translate regulatory requirements into actionable business processes and enable engineering teams to embed security controls.

They are a global leader in event ticketing technology, transforming ticketing for major events like the Grammys and Golden Globes. With over 160 employees and six offices worldwide, they have received over $65 million in funding and are known for their fast-growing, merit-driven culture.

Europe

  • Lead SOC 1 and SOC 2 examinations and support end-to-end SOX planning.
  • Partner with Security, Engineering, Data, and Finance to implement scalable IT controls.
  • Conduct controls assessments, drive remediation, and produce auditor-ready documentation.

Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions globally, offering spot trading, margin, futures, staking, and OTC services. Part of Payward, it is powered by people from around the world and celebrates diverse talents, backgrounds, and unique perspectives.

$114,000–$139,000/yr
US

  • Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
  • Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.

Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.

$115,000–$186,000/yr
US

  • Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
  • Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
  • Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.

Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

$102,500–$102,500/yr
US Unlimited PTO

  • Own GRC workstreams from initial request through evidence collection, testing, and remediation.
  • Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
  • Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.

YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.