Security GRC Lead: Automation & Continuous Compliance

Candid Health

New York, Northern (NY, KY)

Hybrid

USD 180,000 - 258,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Candid Health is seeking a Security GRC Lead to build our first in-house GRC program from the ground up. This role treats compliance as an engineering problem, building automated evidence pipelines and policy enforcement into our cloud stack.

You will establish continuous controls monitoring across GCP infrastructure, identity systems, and CI/CD pipelines to keep the platform audit-ready and secure at all times.

Qualifications

  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform.
  • Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).

Responsibilities

  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.
  • Partnering with Legal on Medicare and Medicaid compliance.
  • Partnering closely with legal and finance teams on future due diligence and compliance projects.
  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.
  • Automate vendor risk management workflows and API-driven vendor evaluations.
  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.

Skills

Python
TypeScript
SQL
APIs
Logs parsing

Tools

Terraform
GCP
Docker
Kubernetes

Job description

Candid Health is seeking a Security GRC Lead to build our first in-house GRC program from the ground up. This role treats compliance as an engineering problem, building automated evidence pipelines and policy enforcement into our cloud stack.

You will establish continuous controls monitoring across GCP infrastructure, identity systems, and CI/CD pipelines to keep the platform audit-ready and secure at all times.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Lead: Automate Compliance in Cloud CI/CD
Security GRC Lead: Automate Compliance in Cloud CI/CD

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security GRC Engineer: Automate Compliance at Scale
Security GRC Engineer: Automate Compliance at Scale

Candid Health • Denver (CO)

On-site
USD 180,000 - 258,000
Security GRC Lead - Automation & Cloud Compliance
Security GRC Lead - Automation & Cloud Compliance

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
GRC Automation Engineer: Continuous Compliance
GRC Automation Engineer: Continuous Compliance

Plaid • Seattle (WA)

On-site
USD 156,000 - 214,000
Equity
401(k)
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
GRC Automation Engineer — Controls & Compliance
GRC Automation Engineer — Controls & Compliance

Box • United States

On-site
USD 140,000 - 190,000
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
GRC Program Lead: Assurance Engineering & Controls
GRC Program Lead: Assurance Engineering & Controls

OpenAI • San Francisco (CA)

On-site
USD 160,000 - 260,000
GRC Engineering Lead: Automate Compliance & Risk
GRC Engineering Lead: Automate Compliance & Risk

Anduril • Boston (MA)

Hybrid
USD 166,000 - 253,000
Equity grants
Top-tier benefits
GRC Automation Lead, Security Engineering
GRC Automation Lead, Security Engineering

Anduril Industries • Boston (MA)

On-site
USD 166,000 - 253,000
Equity grants
Top-tier benefits
Competitive compensation