Security GRC Lead - Automation & Cloud Compliance

Candid Health

San Francisco (CA)

On-site

USD 180,000 - 258,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Candid Health is building a first-in-house GRC program from the ground up in the United States. This role focuses on turning compliance into an engineering challenge, automating evidence pipelines, and embedding controls into CI/CD and cloud infrastructure.

You will lead automated governance across GCP, identity systems, and pipelines, delivering continuous, auditable compliance as part of a scalable back-end platform for healthcare providers.

Qualifications

  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform
  • Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).

Responsibilities

  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.

Skills

Python
TypeScript
SQL
APIs
CI/CD
Git workflows
Docker
Kubernetes
SOC 2
PCI DSS
NIST
HITRUST

Tools

GCP
Terraform

Job description

Candid Health is building a first-in-house GRC program from the ground up in the United States. This role focuses on turning compliance into an engineering challenge, automating evidence pipelines, and embedding controls into CI/CD and cloud infrastructure.

You will lead automated governance across GCP, identity systems, and pipelines, delivering continuous, auditable compliance as part of a scalable back-end platform for healthcare providers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Lead: Automation & Continuous Compliance
Security GRC Lead: Automation & Continuous Compliance

Candid Health • New York (NY), Northern (KY)

Hybrid
USD 180,000 - 258,000
Security GRC Lead: Automate Compliance in Cloud CI/CD
Security GRC Lead: Automate Compliance in Cloud CI/CD

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security GRC Engineer — Automation & Cloud Compliance
Security GRC Engineer — Automation & Cloud Compliance

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security GRC Engineer: Automate Compliance at Scale
Security GRC Engineer: Automate Compliance at Scale

Candid Health • Denver (CO)

On-site
USD 180,000 - 258,000
GRC Automation Engineer: Continuous Compliance
GRC Automation Engineer: Continuous Compliance

Plaid • Seattle (WA)

On-site
USD 156,000 - 214,000
Equity
401(k)
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
Remote GRC Engineer: Compliance & Cloud Controls
Remote GRC Engineer: Compliance & Cloud Controls

Insight Global • Woonsocket (RI)

Remote
USD 62,000 - 69,000
Medical insurance
Dental insurance
Vision insurance
+3
GRC Automation Engineer — Controls & Compliance
GRC Automation Engineer — Controls & Compliance

Box • United States

On-site
USD 140,000 - 190,000
GRC Engineering Lead: Automate Compliance Pipelines
GRC Engineering Lead: Automate Compliance Pipelines

Anduril Industries • Seattle (WA)

On-site
USD 166,000 - 253,000
GRC Automation Architect
GRC Automation Architect

Anthropic • New York (NY)

On-site
USD 405,000