Security GRC Engineer

Socket.dev

San Francisco (CA)

On-site

USD 180,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Socket.dev is seeking a Security GRC Engineer in San Francisco to automate compliance workflows and scale our governance, risk, and compliance program. You will lead evidence gathering, drive continuous control testing, and coordinate with auditors and customers to uphold high security standards.

You will collaborate with Engineering, Legal, GTM, Trust & Safety, and regulators to implement and audit SOC 2, ISO 27001, ISO 42001, and AIUC-1 controls across products and infrastructure.

Qualifications

  • Experience with GRC frameworks such as SOC 2, ISO 27001, ISO 42001, and AIUC-1.
  • Ability to trace external claims to how the product and infrastructure are configured using coding agents.
  • Strong cross-functional collaboration with Engineering, Legal, GTM, Trust & Safety, auditors, and regulators.

Responsibilities

  • Automate evidence gathering and continuous control testing.
  • Own the relationship with audit firms and customers—explain the security and AI governance program and earn their trust.
  • Conduct security compliance reviews for new products, features, and vendors.
  • Support Legal in contract negotiations with timely, accurate guidance on security and AI governance terms.
  • Support incident response communications—draft and review customer-facing updates during security incidents.
  • Build self-serve documentation and tools to answer customer security and AI governance inquiries.
  • Maintain corporate security policies.

Skills

GRC frameworks
Audit liaison
Security governance

Job description

Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.

About the Role

Security GRC Engineers design, implement, and scale our governance, risk, and compliance (GRC) program. You'll lead automation of compliance workflows, build self-serve tools to enable GTM teams, and ensure our products and infrastructure meet the highest security standards. This role blends technical implementation with strategic program development, directly shaping how we build trust with customers.

You may be a fit if

  • You have experience with GRC frameworks such as SOC 2, ISO 27001, ISO 42001, and AIUC-1.

  • You're comfortable tracing an external claim back to how the product and infrastructure are actually configured — you use coding agents and curiosity to confirm that what we say is what we do, flag issues that affect the security and AI governance program, and drive them to the right outcome.

  • You have strong cross-functional collaboration skills, especially with Engineering, Legal, GTM, Trust & Safety, auditors, and regulators.

Sample projects include

  • Automate evidence gathering and continuous control testing.

  • Own the relationship with audit firms and customers — you're the person who explains the security and AI governance program and earns their trust in it.

  • Conduct security compliance reviews for new products, features, and vendors.

  • Support Legal in contract negotiations with timely, accurate guidance on security and AI governance terms.

  • Support incident response communications — draft and review customer-facing updates during security incidents.

  • Build self-serve documentation and tools to answer customer security and AI governance inquiries.

  • Maintain corporate security policies.

Applying

If there appears to be a fit, we'll reach out to schedule 2-3 short technicals. After that, we'll schedule an onsite at our office, where you'll work on a small project, discuss ideas, and meet the team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Lead (GRC)
Security GRC Lead (GRC)

Candid Health • United States

On-site
USD 120,000 - 160,000
GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 150,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

6sense • United States

On-site
USD 140,000 - 200,000
Lead GRC Security Engineer
Lead GRC Security Engineer

Lorien • United States

Remote
USD 165,000 - 240,000
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters Inc • Town of Poland (NY)

Hybrid
USD 110,000 - 150,000
Competitive salaries
Remote-friendly culture
Strong internal mobility
Security GRC Engineer - Automate Compliance & Trust
Security GRC Engineer - Automate Compliance & Trust

Socket.dev • San Francisco (CA)

On-site
USD 180,000 - 230,000
Security GRC Engineer: Automation & Compliance
Security GRC Engineer: Automation & Compliance

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
GRC Manager
GRC Manager

Socket.dev • Chicago (IL)

On-site
USD 110,000 - 140,000