Commercial GRC Engineer - Sr. Security Engineer

engineeringjobs.net, Inc.

Town of Montana (WI)

Hybrid

USD 175,000 - 228,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) match
Paid holidays
Teleworking options

Job summary

engineeringjobs.net, Inc. seeks a Commercial GRC Engineer - Sr. Security Engineer in the United States to automate governance, risk and compliance across cloud, identity, endpoint and SaaS environments.

You will translate requirements into technical controls, embed them into CI/CD pipelines, and enable engineers with self-service compliance tooling and dashboards. Significant ownership of frameworks like SOC 2, ISO 27001/27017/27701 and HIPAA is expected.

Qualifications

  • 4+ years of experience in GRC engineering, security engineering, compliance automation, IT audit support, or related field.
  • Hands-on ownership of at least one complete certification cycle such as SOC 2 or ISO 27001.
  • Experience configuring integrations and building evidence pipelines with GRC platforms.
  • Strong understanding of cloud security fundamentals (AWS, GCP, Azure) and IAM, logging, encryption.

Responsibilities

  • Own control automation for SOC 2 and ISO/HIPAA frameworks by designing automated evidence collection.
  • Translate compliance requirements into technical control logic and integrate into pipelines.
  • Embed controls into architecture and development workflows to shift compliance left.
  • Build engineer-facing compliance experiences and dashboards for visibility into control health.
  • Support audit cycles end-to-end by coordinating evidence requests and remediation tracking.

Skills

GRC engineering
Security engineering
Compliance automation
Python
JavaScript
Documentation
Stakeholder management

Tools

Vanta
Drata
Secureframe

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Commercial GRC Engineer - Sr. Security Engineer based in United States.

This role brings an engineering mindset to commercial Governance, Risk, and Compliance, transforming compliance from a manual process into an automated, continuously monitored capability.

You will build control automation, evidence pipelines, and technical integrations across cloud, identity, endpoint, and SaaS environments.

The position combines hands‑on security engineering with GRC expertise, translating compliance requirements into technical controls that engineering teams can implement and consume.

You will help shift compliance left by embedding control requirements into architecture, development workflows, and existing engineering systems.

The role also offers significant ownership across SOC 2, ISO 27001/27017/27701, HIPAA, and related commercial frameworks.

Success means improving audit readiness, reducing repetitive evidence collection, and addressing the root causes of control gaps rather than managing symptoms.

This is a builder-focused environment where automation, continuous assurance, systems thinking, and collaboration are central to the way compliance is delivered.

Accountabilities:

  • Own control automation for SOC 2, ISO 27001/27017/27701, HIPAA, and related commercial frameworks by designing automated evidence collection and continuous control monitoring across cloud, identity, endpoint, and SaaS systems.
  • Express controls, control tests, and cross-framework mappings as version‑controlled code so they remain reviewable, testable, reusable, and maintainable.
  • Translate compliance requirements into technical control logic, workflows, and integrations while partnering with engineering, IT, and security teams to embed controls into existing systems and pipelines.
  • Shift compliance left by contributing to architecture and design reviews, defining control requirements as acceptance criteria, and helping teams build compliant‑by‑default infrastructure.
  • Design engineer‑facing compliance experiences, including self‑service control status, guardrails, paved‑road patterns, and compliance feedback delivered through tools such as CI/CD, Jira, and Slack.
  • Evaluate whether controls meaningfully reduce relevant risk and propose alternative controls when standard framework requirements do not align with the applicable threat model or workload architecture.
  • Support audit cycles end‑to‑end by coordinating evidence requests, maintaining evidence libraries, responding to auditor follow‑ups, and tracking remediation items through closure.
  • Build and maintain dashboards and reporting that provide visibility into control health, evidence freshness, and audit readiness across multiple frameworks.
  • Identify opportunities to eliminate duplicate evidence‑gathering efforts by mapping controls once and reusing those mappings across SOC 2, ISO, and HIPAA.
  • Diagnose recurring control failures and stale evidence by identifying root causes and improving the underlying processes, tooling, or ownership models.
  • Partner with GRC and engineering stakeholders to expand control, evidence, and risk‑lifecycle capabilities within internal platforms.
Requirements
  • 4+ years of experience in GRC engineering, security engineering, compliance automation, IT audit support, or a related field, with hands‑on ownership of at least one complete certification cycle such as SOC 2 or ISO 27001.
  • Practical experience with GRC or compliance automation platforms such as Vanta, Drata, Secureframe, or comparable internal solutions, including configuring integrations and building evidence pipelines.
  • Strong understanding of cloud security fundamentals, including AWS, GCP, or Azure IAM, logging, encryption, and their relationship to compliance controls.
  • Solid working knowledge of SOC 2, ISO 27001, and ideally ISO 27017/27701 and HIPAA requirements, with the ability to map controls across frameworks and reduce duplicated evidence work.
  • Comfort with scripting or light development using Python, JavaScript, or similar technologies to build integrations, automate evidence collection through APIs, or extend GRC tooling.
  • Strong written communication skills, with the ability to document controls, gaps, and remediation plans clearly for both external auditors and internal engineering teams.
  • A stakeholder‑focused approach, with an emphasis on making compliance easier for engineers to maintain rather than simply accelerating evidence production.
  • Demonstrated ability to trace control failures or audit findings to their root causes and drive durable remediation across teams.
  • Legally eligible to work in the United States on an ongoing basis.
Benefits
  • U.S. base salary range of $175,000 - $227,500 USD.
  • Market‑competitive incentive opportunity in addition to base compensation.
  • Employer‑subsidized medical, vision, and dental coverage for eligible full‑time employees.
  • 401(k) match covering 50% of employee contributions up to the first 6% of eligible pay.
  • Monthly stipend to support work and productivity.
  • Flexible Time Away Program plus sick time off.
  • Employer‑sponsored life insurance and short‑and‑long‑term disability coverage.
  • 12 paid holidays per year.
  • Up to 24 weeks of parental leave.
  • One paid volunteer day each year.
  • Professional growth and development opportunities, including access to Udemy courses.
  • Additional funded perks, including counseling membership, local retail discounts, and access to a personal work account.
  • Teleworking options from registered locations across the U.S., depending on role requirements.

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre‑contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Governance, Risk & Compliance
Director of Governance, Risk & Compliance

Jobgether SRL • United States

Remote
USD 140,000 - 210,000
401(k) match
Health insurance (employee)
Paid time off 3 weeks
+3
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
GRC Implementation and Integration Specialist
GRC Implementation and Integration Specialist

Prismhr Hire • Knoxville (TN)

Remote
USD 120,000 - 155,000
Medical
HSA + HRA
Telemedicine
+9
GRC Implementation and Integration Specialist
GRC Implementation and Integration Specialist

Prismhr Hire • United States

Remote
USD 100,000 - 150,000
Medical
HSA + HRA
Telemedicine
+5
Lead GRC Security Engineer
Lead GRC Security Engineer

Lorien • United States

On-site
USD 165,000 - 240,000
Lead Governance, Risk, and Compliance Engineer - Remote
Lead Governance, Risk, and Compliance Engineer - Remote

Jobgether • Illinois

On-site
USD 100,000 - 140,000
Flexible work environment
Employer contributions towards healthcare
Equity in the company
+3
Senior GRC Engineer
Senior GRC Engineer

Workstreet • United States

Remote
USD 120,000 - 170,000
Career development
Technical training
Competitive compensation
+2
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • Herndon (VA)

Remote
USD 112,000 - 179,000
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Group • United States

Remote
USD 140,000 - 190,000