Senior GRC Engineer

Playlist

United States

On-site

USD 150,000 - 170,000

Full time

32 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Playlist seeks a Senior GRC Engineer to own the technical spine of its control environment, designing architecture across PCI DSS, SOC 1/2, ISO 27001, HITRUST, and NIST CSF/800-53, with OSCAL as translation layer to reduce audit burden.

You will lead the Master Control List, evidence workflows, and AI-powered GRC tooling, collaborating with Security, Legal, and Finance to align controls with business operations and scale across a multi-brand footprint.

Qualifications

  • 6+ years of experience in security engineering, GRC, or compliance engineering across multiple regulatory frameworks.
  • Deep knowledge of PCI DSS, SOC 1/2, HITRUST and ISO 27001 or NIST CSF/800-53.
  • Experience designing or maintaining cross-framework control architectures.
  • Hands-on experience with evidence requirements and control implementation.
  • Proficiency with compliance automation tooling like Optro, Drata, Vanta, Hyperproof, Anecdotes.
  • Ability to translate technical control design into clear implementation guidance for engineering and product teams.
  • Experience building or operating agentic AI workflows in production contexts.

Responsibilities

  • Design and maintain framework crosswalks and control mappings across PCI DSS, SOC 1/2, ISO 27001, HITRUST, and NIST CSF/800-53.
  • Own the Master Control List including nomenclature, database architecture, and evidence linkages.
  • Manage lifecycle of controls, evidence requirements, and implementations as standards evolve.
  • Drive evidence automation and scalable collection workflows for audits.
  • Partner with Security, Legal, and Finance to align controls with business operations.
  • Design, build, and maintain AI-powered GRC tooling and pipelines for risk quantification and monitoring.
  • Identify rationalization opportunities across frameworks to minimize incremental work.

Skills

Security engineering
Regulatory frameworks
Control frameworks
Evidence management
Compliance automation tools
Implementation guidance
Agentic AI workflows

Education

Certifications such as CISA, CISSP, ISO 27001 Lead Implementer, CCSFP, PCI ISA

Tools

AWS (Lambda, Step Functions, EventBridge, S3, Aurora/RDS)

Job description

About the Company

At Playlist, life's richest moments happen when people step away from screens to move, connect, explore, and play. We're building the definitive platform for intentional living, connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, Playlist empowers businesses and individuals, making it effortless for aspirations to become actions. Join us in reshaping technology's role to foster meaningful, real-world connections.

Who we are

The GRC team at Playlist owns governance, risk, third-party risk, and compliance across a portfolio that spans Mindbody, ClassPass, Booker, Kite, and EGYM, with more brands coming as the company grows. We operate without a playbook, building programs, frameworks, and control architecture in an environment that's complex, not just big. The team works closely with Engineering, Legal, Finance, and product teams to make compliance real rather than ceremonial. If you want to do meaningful work on hard problems with people who take both rigor and pragmatism seriously, we'd love to meet you.

Your role

As a Senior GRC Engineer, you'll own the technical spine of how Playlist manages its control environment. That means designing the architecture that lets the team work across multiple compliance frameworks without duplicating effort at every audit, and making sure control design, evidence requirements, and implementation keep pace with regulatory change and business growth.

You will

  • Design and build framework crosswalks and control mappings across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53, using languages such as OSCAL as the translation layer to preserve framework-specific requirements while reducing duplicate audit burden
  • Own the Master Control List end-to-end, including control nomenclature, relational database architecture, evidence linkages, and the operational model for ongoing maintenance across Playlist's multi-brand footprint
  • Manage the full lifecycle of controls, evidence requirements, and implementation as new standards are adopted, requirements change, or acquired entities are brought into scope
  • Drive evidence automation in GRC tooling, building collection workflows that scale without turning every audit season into a manual sprint
  • Partner with Security Engineering, Legal, and Finance to validate that control design reflects how the business operates, translating compliance requirements into implementation guidance that engineering teams can act on
  • Design, build and maintain AI-powered GRC tooling, multi-agent pipelines for risk quantification, evidence automation, vendor risk assessment, and compliance monitoring using cloud native tools and APIs, so the team's analytical and operational capacity scales without scaling headcount
  • Identify rationalization opportunities across frameworks, so adding a new standard to the portfolio means incremental work, not starting from scratch
About The Right Team Member

You think in systems, not checklists. You're the person who looks at five overlapping compliance frameworks and immediately starts sketching how they relate to each other, where the evidence reuse opportunities are, and what a sustainable architecture looks like long-term. You also see AI as a genuine lever, not a novelty, and you know how to wire agentic workflows into compliance programs in ways that hold up under audit scrutiny. You're equally comfortable whiteboarding a control schema, shipping a pipeline, and sitting with an auditor challenging a scope interpretation. You don't wait for someone to hand you the answer; you dig in, form a view, and bring it to leadership with the reasoning laid out. You're precise without being rigid, and you understand that compliance programs have to serve the business, not the other way around.

You'll thrive in this role with experience in:
Must Have:
  • 6+ years of experience in security engineering, GRC, or compliance engineering, with direct hands-on work across multiple regulatory frameworks
  • Deep working knowledge of PCI DSS, SOC 1 or SOC 2, HITRUST, and at least one of ISO 27001 or NIST CSF/800-53
  • Experience designing or maintaining control frameworks, crosswalks, or unified control architectures across multiple compliance standards
  • Hands-on experience managing evidence requirements and control implementation, not just documentation
  • Proficiency with compliance automation tooling (Optro, Drata, Vanta, Hyperproof, Anecdotes, or similar)
  • Ability to translate technical control design into clear implementation guidance for engineering and product teams
  • Experience building or operating agentic AI workflows (LLM-based pipelines, multi-agent systems, RAG architectures) in a production or near-production context
Nice to Have:
  • Hands-on experience with AWS services (Lambda, Step Functions, EventBridge, S3, Aurora/RDS) for building and maintaining compliance automation infrastructure
  • Experience supporting external audits or assessments as a primary technical contact
  • Exposure to multi-brand or post-acquisition control harmonization
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer, CCSFP (HITRUST), or PCI ISA
  • Experience in a SaaS or consumer marketplace environment
Compensation and Benefits
  • It is the Company's intent to pay all Team Members competitive wages and salaries that are motivational, fair and equitable.
  • The goal of Company's compensation program is to be transparent, attract potential employees, meet the needs of all current employees, and encourage Team Members to stay with our organization.
  • Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location.
  • The base salary range for this position in the United States is $150,000 to $170,000.
  • The total compensation package for this position may also include a performance bonus, benefits and/or other applicable incentive compensation plans.
Equal Opportunity Employer

The Company is an Equal Opportunity Employer. We highly value diversity at our company and encourage people of all different backgrounds, experiences, abilities and perspectives to apply. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.

Note

Note: This description outlines key responsibilities but isn’t intended to cover every task or duty. Additional responsibilities may be assigned as needed to support the team and business goals.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Software Engineer - Playlist
Sr Software Engineer - Playlist

Playlist • United States

On-site
USD 151,000 - 252,000
Security Engineer, GRC
Security Engineer, GRC

Plaid • Seattle (WA)

On-site
USD 156,000 - 214,000
Equity
401(k)
Security Engineer, GRC
Security Engineer, GRC

Plaid • New York (NY)

On-site
USD 156,000 - 214,000
Engineering Manager - Platform
Engineering Manager - Platform

Mindbody • United States

On-site
USD 151,000 - 201,000
Sr Technical Program Manager - Cybersecurity Strategy
Sr Technical Program Manager - Cybersecurity Strategy

Playlist • New York (NY)

On-site
USD 100,000 - 132,000
Manager, Technical Program Management (Cyber Security)
Manager, Technical Program Management (Cyber Security)

Playlist • New York (NY)

On-site
USD 131,000 - 175,000
Competitive compensation
Equal opportunity employer
Security Engineer, GRC
Security Engineer, GRC

Plaid Inc • San Francisco (CA)

On-site
USD 190,000 - 270,000
Senior Security GRC Lead
Senior Security GRC Lead

Gong • Austin (CO)

Hybrid
USD 121,000 - 185,000
Medical, dental, and vision plans
Flexible wellness stipend
401(k) program
+2
Senior Security GRC Lead
Senior Security GRC Lead

Gong • San Francisco (CA)

On-site
USD 121,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
401(k) program
+2
GRC Engineer
GRC Engineer

Talanto • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Paid holidays
Parental leave