Get more replies from employers
Send a job-specific resume in minutes.
Candid Health in United States is seeking a Security GRC Lead to build our first in-house GRC program from the ground up, treating compliance as an engineering and data problem.
You will develop automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines, turning point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and
3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRCDeep familiarity with core frameworks such asHands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as TerraformUnderstanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes)Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databasesExperience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes)Background in software development, DevOps, or platform engineeringExperience with Policy-as-Code enginesCertifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP