Security GRC Engineer: Automation & Compliance

candidhealth

San Francisco (CA)

On-site

USD 180,000 - 258,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Candid Health seeks a Security GRC Lead to build our first in-house GRC program from the ground up. You will implement automated evidence pipelines, compliance-as-code, and continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines.

You will turn point-in-time audits into a continuous telemetry system that keeps our platform secure, audit-ready, and resilient while guiding legal and finance on regulatory programs and vendor risk management.

Qualifications

  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform.
  • Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).

Responsibilities

  • Compliance Automation & Engineering: Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.
  • Partnering with Legal on Medicare and Medicaid compliance
  • Partnering closely with legal and finance teams on future due diligence and compliance projects

Skills

Python
TypeScript
SQL
APIs
Log parsing
Databases
GCP
Terraform
CI/CD
Docker
Kubernetes
SOC 1/2
PCI
NIST
HITRUST
CISSP
CISA
CRISC
AWS Certified Security
CCSP

Tools

Terraform

Job description

Candid Health seeks a Security GRC Lead to build our first in-house GRC program from the ground up. You will implement automated evidence pipelines, compliance-as-code, and continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines.

You will turn point-in-time audits into a continuous telemetry system that keeps our platform secure, audit-ready, and resilient while guiding legal and finance on regulatory programs and vendor risk management.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Engineer: Automate Compliance at Scale
Security GRC Engineer: Automate Compliance at Scale

Candid Health • Denver (CO)

On-site
USD 180,000 - 258,000
Security GRC Lead: Automation & Continuous Compliance
Security GRC Lead: Automation & Continuous Compliance

Candid Health • New York (NY), Northern (KY)

Hybrid
USD 180,000 - 258,000
Security GRC Lead: Automate Compliance in Cloud CI/CD
Security GRC Lead: Automate Compliance in Cloud CI/CD

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security GRC Lead - Automation & Cloud Compliance
Security GRC Lead - Automation & Cloud Compliance

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security GRC Lead (GRC)
Security GRC Lead (GRC)

Candid Health • United States

On-site
USD 120,000 - 160,000
GRC Automation Engineer: Continuous Compliance
GRC Automation Engineer: Continuous Compliance

Plaid • Seattle (WA)

On-site
USD 156,000 - 214,000
Equity
401(k)
GRC Automation Engineer — Controls & Compliance
GRC Automation Engineer — Controls & Compliance

Box • United States

On-site
USD 140,000 - 190,000
GRC Engineer: Continuous, Data-Driven Compliance
GRC Engineer: Continuous, Data-Driven Compliance

Plaid • New York (NY)

On-site
USD 156,000 - 214,000
Senior GRC Security Engineer—Automated Compliance
Senior GRC Security Engineer—Automated Compliance

6sense • United States

On-site
USD 140,000 - 200,000
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000