- We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem
- You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times
- 1) Compliance Automation & Engineering
- Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots
- Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically
- Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time
- Partnering with Legal on Medicare and Medicaid compliance
- Partnering closely with legal and finance teams on future due diligence and compliance projects
- 2) Framework Mapping & Control Architecture
- Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls
- Map single technical controls across multiple overlapping frameworks to eliminate redundant work
- Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery
- 3) Risk Management & Audits
- Lead technical audit readiness and external audit engagements using programmatic evidence pipelines
- Automate vendor risk management workflows and API-driven vendor evaluations
- Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys
3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRCDeep familiarity with core frameworks such asHands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as TerraformUnderstanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes)Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databasesExperience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes)Background in software development, DevOps, or platform engineeringExperience with Policy-as-Code enginesCertifications such as CISSP, CISA, CRISC, AWS Certified Security - Specialty, or CCSP