Security Engineer (GRC)

Candid Health

United States

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Candid Health in United States is seeking a Security GRC Lead to build our first in-house GRC program from the ground up, treating compliance as an engineering and data problem.

You will develop automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines, turning point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and

Qualifications

  • 3+ years in a technical security role (Security Engineering/Cloud Security/Tech GRC).
  • Hands-on experience with at least one cloud platform (GCP preferred).
  • Experience with Terraform or other infrastructure-as-code tools.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).
  • Proficiency in Python, TypeScript, SQL; experience with APIs, logs, and databases.
  • Experience with modern continuous compliance platforms (Vanta, Drata, Anecdotes).
  • Background in software development, DevOps, or platform engineering.
  • Experience with Policy-as-Code engines.
  • Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.

Responsibilities

  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.
  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.
  • Automate vendor risk management workflows and API-driven vendor evaluations.
  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.
  • Partner with Legal on Medicare and Medicaid compliance, and with finance on due diligence projects.

Skills

Terraform
Docker
Kubernetes
Git workflows
Python
TypeScript
SQL
APIs
Logs querying

Tools

GCP
Policy-as-Code engines

Job description


  • We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won’t just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem

  • You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times

  • 1) Compliance Automation & Engineering

  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots

  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically

  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time

  • Partnering with Legal on Medicare and Medicaid compliance

  • Partnering closely with legal and finance teams on future due diligence and compliance projects

  • 2) Framework Mapping & Control Architecture

  • Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls

  • Map single technical controls across multiple overlapping frameworks to eliminate redundant work

  • Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery

  • 3) Risk Management & Audits

  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines

  • Automate vendor risk management workflows and API-driven vendor evaluations

  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys


3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRCDeep familiarity with core frameworks such asHands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as TerraformUnderstanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes)Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databasesExperience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes)Background in software development, DevOps, or platform engineeringExperience with Policy-as-Code enginesCertifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Lead: Automate Compliance in Cloud CI/CD
Security GRC Lead: Automate Compliance in Cloud CI/CD

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security GRC Engineer — Automation & Cloud Compliance
Security GRC Engineer — Automation & Cloud Compliance

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
GRC Automation Engineer: Cloud Security & Compliance
GRC Automation Engineer: Cloud Security & Compliance

Candid Health • United States

On-site
USD 120,000 - 180,000
Head of Risk and Compliance
Head of Risk and Compliance

Applied Intuition • United States

On-site
USD 180,000 - 250,000
Health Insurance
Fitness Stipend
401(k) Match
+3
Security Compliance Engineer
Security Compliance Engineer

ANAUTICS INC • Oklahoma City (OK)

On-site
USD 80,000 - 100,000
Looking GRC Engineer – San Jose CA / Lehi UT
Looking GRC Engineer – San Jose CA / Lehi UT

Tech Mirrors • San Jose (CA)

On-site
USD 120,000 - 150,000
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

6sense • United States

On-site
USD 140,000 - 200,000
Senior GRC Engineer: Cloud Security & Compliance
Senior GRC Engineer: Cloud Security & Compliance

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development