A complete application in a minute — tailored resume and cover letter, ready to send.
Playlist seeks a Senior GRC Engineer to own the technical spine of its control environment, designing architecture across PCI DSS, SOC 1/2, ISO 27001, HITRUST, and NIST CSF/800-53, with OSCAL as translation layer to reduce audit burden.
You will lead the Master Control List, evidence workflows, and AI-powered GRC tooling, collaborating with Security, Legal, and Finance to align controls with business operations and scale across a multi-brand footprint.
At Playlist, life's richest moments happen when people step away from screens to move, connect, explore, and play. We're building the definitive platform for intentional living, connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, Playlist empowers businesses and individuals, making it effortless for aspirations to become actions. Join us in reshaping technology's role to foster meaningful, real-world connections.
The GRC team at Playlist owns governance, risk, third-party risk, and compliance across a portfolio that spans Mindbody, ClassPass, Booker, Kite, and EGYM, with more brands coming as the company grows. We operate without a playbook, building programs, frameworks, and control architecture in an environment that's complex, not just big. The team works closely with Engineering, Legal, Finance, and product teams to make compliance real rather than ceremonial. If you want to do meaningful work on hard problems with people who take both rigor and pragmatism seriously, we'd love to meet you.
As a Senior GRC Engineer, you'll own the technical spine of how Playlist manages its control environment. That means designing the architecture that lets the team work across multiple compliance frameworks without duplicating effort at every audit, and making sure control design, evidence requirements, and implementation keep pace with regulatory change and business growth.
You will
You think in systems, not checklists. You're the person who looks at five overlapping compliance frameworks and immediately starts sketching how they relate to each other, where the evidence reuse opportunities are, and what a sustainable architecture looks like long-term. You also see AI as a genuine lever, not a novelty, and you know how to wire agentic workflows into compliance programs in ways that hold up under audit scrutiny. You're equally comfortable whiteboarding a control schema, shipping a pipeline, and sitting with an auditor challenging a scope interpretation. You don't wait for someone to hand you the answer; you dig in, form a view, and bring it to leadership with the reasoning laid out. You're precise without being rigid, and you understand that compliance programs have to serve the business, not the other way around.
The Company is an Equal Opportunity Employer. We highly value diversity at our company and encourage people of all different backgrounds, experiences, abilities and perspectives to apply. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.
Note: This description outlines key responsibilities but isn’t intended to cover every task or duty. Additional responsibilities may be assigned as needed to support the team and business goals.