GRC Engineer: Turn Compliance into Code & Signals

Plaid Inc

San Francisco (CA)

On-site

USD 190,000 - 270,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Plaid Inc. is seeking a GRC Engineer to own the GRC Engineering function, turning compliance into code and building an engineered, scalable system for continuous assurance.

You will define architecture, codify controls, and create live data pipelines across SOC 2, ISO, and NIST frameworks. The role emphasizes data-driven risk assessment, automated control monitoring, and AI-assisted workflows, with a focus on reducing manual toil and enabling rapid audits.

Qualifications

  • Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems.
  • Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it.
  • Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs.
  • Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal.
  • Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation.
  • Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets.
  • Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD.
  • Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation.

Responsibilities

  • Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on — controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state — so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit.
  • Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline — so audit readiness is continuous and gaps surface the moment they appear, not at audit time.
  • Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture.
  • Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data — keeping the risk management program running while cutting its manual overhead.
  • Automate Operational Toil: Eliminate the recurring manual work the team carries — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reporting — with durable automation that gives time back across every workstream.
  • Shift Compliance Left with Code and AI: Embed compliance checks into the CI/CD flow as policy-as-code so controls are validated as code ships, prototype self-healing policies reconciled against live infrastructure, and scale agentic / AI-assisted workflows across the function.
  • Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations.

Skills

Python
SQL
APIs & Webhooks
Internal Tooling
AWS
Cloud security controls

Education

Bachelor's or Master's in CS or related field

Tools

Terraform
OPA/Rego
Sentinel
Mode

Job description

Plaid Inc. is seeking a GRC Engineer to own the GRC Engineering function, turning compliance into code and building an engineered, scalable system for continuous assurance.

You will define architecture, codify controls, and create live data pipelines across SOC 2, ISO, and NIST frameworks. The role emphasizes data-driven risk assessment, automated control monitoring, and AI-assisted workflows, with a focus on reducing manual toil and enabling rapid audits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Engineer: Build Continuous, AI-Driven Compliance
GRC Engineer: Build Continuous, AI-Driven Compliance

Plaid • United States

On-site
USD 150,000 - 190,000
GRC Automation Engineer: Continuous Compliance
GRC Automation Engineer: Continuous Compliance

Plaid • Seattle (WA)

On-site
USD 156,000 - 214,000
Equity
401(k)
GRC Engineer: Continuous, Data-Driven Compliance
GRC Engineer: Continuous, Data-Driven Compliance

Plaid • New York (NY)

On-site
USD 156,000 - 214,000
GRC Security Analyst: Automate & Scale Compliance
GRC Security Analyst: Automate & Scale Compliance

Discord Inc. • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
GRC Automation Engineer — Controls & Compliance
GRC Automation Engineer — Controls & Compliance

Box • United States

On-site
USD 140,000 - 190,000
GRC Engineer I - Remote, Fast-Growing Compliance
GRC Engineer I - Remote, Fast-Growing Compliance

Workstreet • United States

On-site
USD 70,000 - 110,000
Remote-First Culture
Career Development
Training reimbursement
GRC Engineer - AI-Driven Compliance & Assurance
GRC Engineer - AI-Driven Compliance & Assurance

Legora • New York (NY)

On-site
Confidential
Medical plans
Dental plans
Vision plans
+7
GRC Program Manager: Enterprise Compliance Leader
GRC Program Manager: Enterprise Compliance Leader

Segment (Twilio) • Washington

Hybrid
USD 90,000 - 160,000
Medical, dental, and vision insurance
Commuter benefits
2 weeks paid time off at year end
Senior GRC Engineer - Automate Compliance & Risk
Senior GRC Engineer - Automate Compliance & Risk

laptop-battery • San Francisco (CA)

On-site
USD 180,000 - 200,000
Medical coverage
Flexible PTO
Wellness reimbursement
+2