Looking GRC Engineer – San Jose CA / Lehi UT

Tech Mirrors

San Jose (CA)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Tech Mirrors is seeking a hands-on GRC Engineer for a 6+ months contract in San Jose, CA. This role requires expertise in Python, API development, and familiarity with compliance frameworks.

The ideal candidate will have strong database skills, experience with microservices architecture, and a builder mindset focused on security and compliance. Join us to help develop secure, scalable systems that meet industry standards.

Qualifications

  • Hands-on experience in Python backend development with REST APIs.
  • Experience building microservices using modern architectures.
  • Strong understanding of GRC/compliance frameworks.

Responsibilities

  • Build secure and scalable systems with a focus on compliance.
  • Integrate security/compliance controls into CI/CD pipelines.
  • Develop governance workflows and audit-ready systems.

Skills

Python backend development
REST API development
Microservices architecture
Docker
Kubernetes
AWS
Compliance frameworks
Database experience (SQL/NoSQL)

Education

Bachelor’s degree in Computer Science or related field

Tools

Terraform
Prometheus
Grafana

Job description

Position: GRC Engineer

Location: San Jose CA/ Lehi UT (Onsite)

Duration: 6+ months contract

Job Description

Seeking a hands‑on GRC Engineer with expertise in Python, API development, and modern architectures (microservices, Kubernetes, Docker). Must have experience building secure, scalable systems with strong database skills and understanding of compliance frameworks.

Must Haves
  • Strong hands‑on experience in Python backend development with REST API development.
  • Experience building microservices‑based applications using modern architectures.
  • Hands‑on expertise with Docker, Kubernetes, and cloud platforms (AWS preferred).
  • Strong understanding of GRC/compliance frameworks such as SOC2, ISO 27001, NIST, FedRAMP, etc.
  • Experience building or supporting compliance automation, audit‑ready systems, risk/control platforms, or governance workflows.
  • Strong knowledge of security implementation including RBAC, OAuth2/JWT, encryption, IAM, audit logging, and secure coding practices.
  • Experience integrating security/compliance controls into CI/CD pipelines (DevSecOps).
  • Strong database experience with SQL/NoSQL (PostgreSQL, MongoDB, Oracle, etc.).
  • Candidate should have a builder mindset — not just policy/audit experience, but actual engineering and system implementation experience.
Good to Have
  • Experience with Node.js / FastAPI / Flask.
  • Exposure to real‑time compliance monitoring or governance platforms.
  • Experience in regulated environments such as banking, healthcare, fintech, or enterprise compliance systems.
  • Knowledge of Infrastructure as Code (Terraform, CloudFormation).
  • Experience with monitoring/observability tools like Prometheus, Grafana, Datadog, CloudWatch.
  • Exposure to GenAI/AI‑driven compliance automation.
  • Experience with data governance, lineage, and audit traceability systems.
  • Familiarity with Agile, DevSecOps, and secure SDLC practices.
  • Strong communication skills and ability to work with cross‑functional security/compliance stakeholders.

Education: At least a bachelor’s degree (or equivalent experience) in Computer Science, Software/Electronics Engineering, Information Systems, or closely related field is required.

Get your free, confidential resume review.
or drag and drop your file here.