GRC Engineer

Clerk

San Francisco (CA)

Remote

USD 150,000 - 210,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive Salary
Equity Ownership
Health Coverage
Work Gear
Flexible Vacation Policy
Diverse and Inclusive Team

Job summary

Clerk is seeking a Senior GRC Engineer to join our Security Team. You’ll own the program that makes vendor reviews easy: the controls, the evidence, the audits, and the answers.

You’ll work hands-on, building integrations, automations, and internal tools to enforce policies and automate evidence gathering. The program should be audit-ready and scalable across providers.

Qualifications

  • 5+ years in security with automation for a GRC or compliance program.
  • Technical owner of at least one SOC 2 Type II or ISO 27001 audit.
  • You write code and use LLMs to increase productivity without lowering quality.
  • Hands-on with a GRC platform’s API, not just its dashboard.
  • Cloud IAM and configuration depth on at least one provider; GCP preferred.

Responsibilities

  • Own SOC 2 Type II and HIPAA end to end: scoping, control design, evidence, auditor walkthroughs, and remediation.
  • Scope and lead our next framework (ISO 27001 likely) based on customer needs.
  • Build and maintain integrations that feed our GRC platform from cloud providers, SaaS tools, and internal systems.
  • Turn controls into continuous checks: policy-as-code, drift detection, and a control-failure pipeline.
  • Run the vendor security review program from intake to re-review.
  • Own the security questionnaire and trust center workflow.
  • Maintain the risk register and run risk assessments with documented decisions.
  • Embed compliance requirements into the SDLC and change management via tooling.
  • Reduce manual audit touchpoints and tooling complexity.

Skills

Security engineering
Automation
Policy writing
LLM-driven tooling
Audits
Documentation

Tools

GRC platform API
SOC 2 Type II tooling
ISO 27001 framework

Job description

About Clerk

Clerk is on a mission to solve the user identity layer once and for all. We are a globally distributed team dedicated to providing best-in-class developer infrastructure to build the next generation of AI software. Today, we provide developers with full-stack React components and hooks like , , , useUser, and useOrganization. These APIs allow developers to build hard‑to‑get‑right infrastructure for user identity, organization management and billing flows. We believe that a component is worth a thousand APIs.

Clerk is looking for a Senior GRC Engineer to join our Security Team. Our customers put Clerk in the middle of their authentication flow, and every one of them runs us through their own vendor review before they do. You’ll own the program that makes that review easy: the controls, the evidence, the audits, and the answers.

You’ll work as a hands‑on engineer. Expect to spend a lot of your time writing integrations, automations, and internal tools that enforce policies and automate the evidence gathering. The goal is a program that’s always current, so an audit is just someone observing it rather than a quarterly scramble.

What you’ll do
  • Own SOC 2 Type II and HIPAA end to end: scoping, control design, evidence, auditor walkthroughs, and remediation

  • Scope and lead our next framework (ISO 27001 is the likely candidate) based on what customers actually ask for

  • Build and maintain the integrations that feed our GRC platform from our cloud providers, SaaS tools, and internal systems

  • Turn controls into continuous checks: policy‑as‑code, config drift detection, and a control‑failure pipeline from detection to closure

  • Run the vendor security review program, from intake to periodic re‑review

  • Own the security questionnaire and trust center workflow

  • Maintain the risk register and run risk assessments that produce documented decisions

  • Embed compliance requirements into the SDLC and change management so they’re enforced by tooling, not by reminders

  • Reduce the number of things a human has to do to pass an audit every quarter

Who you’re
  • 5+ years in security, with demonstrated experience building automation for a GRC or compliance program

  • You’ve been the technical owner of at least one SOC 2 Type II or ISO 27001 audit and can tell us what you would do differently

  • You write code, and you use LLMs to get more done without lowering the bar

  • Hands‑on with a GRC platform’s API, not just its dashboard

  • Cloud IAM and configuration depth on at least one provider, GCP preferred

  • You can decide what evidence is sufficient and defend an automated test to an auditor

  • Comfortable being one of a few security engineers; you can scope, prioritize, and ship without a lot of process around you

  • Clear writer: policies, control narratives, and questionnaire answers are read by customers, so they have to be good

Nice‑to‑haves
  • Experience at an all‑remote company

  • Shipped LLM or agentic workflows in production for compliance work

  • Experience at a developer‑tools company

Benefits
  • Competitive Salary – We want you to know that we value the skills and experience you bring to the table. We go out of our way to make sure that you feel fairly compensated.

  • Equity Ownership – At Clerk, we believe in shared success. That’s why we offer a stock option plan so that everyone can benefit from the growth and prosperity of the company.

  • Health Coverage – We care about your well‑being. That’s why we offer top‑tier health insurance to ensure that your health needs are fully met.

  • Work Gear – Set up your ideal home office with the gear of your choice. At Clerk, we want to ensure that you have everything you need to perform at your best.

  • Flexible Vacation Policy – We believe in work‑life balance and trust you to take the time you need. Although we recommend 25 days per year, our vacation policy is unlimited. This is in addition to observing national holidays specific to your country of residence.

  • Diverse and Inclusive Team – Join our exceptional, diverse, and globally distributed team at Clerk. We are committed to fostering an inclusive environment where everyone can contribute their best in building impactful products and tools for the modern web.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Engineer
GRC Engineer

AegisAI, Inc. • United States

Remote
USD 120,000 - 180,000
GRC Engineer
GRC Engineer

Aegis AI • United States

On-site
USD 120,000 - 180,000
Commercial GRC Engineer - Sr. Security Engineer
Commercial GRC Engineer - Sr. Security Engineer

engineeringjobs.net, Inc. • Town of Montana (WI)

Hybrid
USD 175,000 - 228,000
Health insurance
401(k) match
Paid holidays
+1
GRC Engineer
GRC Engineer

Legora • New York (NY)

On-site
Confidential
Medical plans
Dental plans
Vision plans
+7
Manager, GRC Engineering
Manager, GRC Engineering

Workstreet • Northern (KY)

On-site
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
Security GRC Lead
Security GRC Lead

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • New York (NY), Northern (KY)

On-site
USD 180,000 - 258,000
Senior GRC Technical Engineer
Senior GRC Technical Engineer

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development
GRC Program Manager
GRC Program Manager

Tandem Inc. • Draper (UT)

On-site
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
GRC Engineer
GRC Engineer

Apex Fintech Solutions • United States

On-site
GBP 70,000 - 110,000
Market-leading salary
Annual bonus
28 days annual leave
+7