Senior GRC Engineer

Align Technology

United States

Hybrid

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Life and Health Insurance
Bonus Structure
Home Office Reimbursement
Technology Allowance
Certification Reimbursement
Loyalty Program
Career Coaching
Paid Time Off
Office Closure

Job summary

A‑LIGN is the leading provider of cybersecurity compliance programs, seeking a Senior GRC Engineer to own audit evidence collection across FedRAMP, ISO, SOC 2, and NIST. You will work closely with IT, DevOps, and security teams to keep certifications audit-ready.

You will drive evidence automation across GRC tooling and cloud environments (GCP, GitHub, Entra ID), support continuous monitoring, risk assessments, and external assessor interactions while reducing audit burden.

Qualifications

  • 5+ years in information security, GRC, IT audit, or compliance engineering.
  • Hands-on audit evidence collection for FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171.
  • DevSecOps or cloud engineering to extract evidence from GCP, GitHub, and Microsoft 365/Entra ID.
  • Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata).
  • Experience supporting external audits and assessor interactions (3PAO).
  • Knowledge of vulnerability management, CI/CD pipelines, IaC, and IAM concepts.
  • Scripting/automation for evidence collection preferred (Python/PowerShell).
  • Familiarity with risk assessment methodologies and threat modeling.

Responsibilities

  • Own end-to-end audit evidence collection across FedRAMP, ISO, SOC 2, and NIST.
  • Maintain and verify technical controls in GCP, GitHub, and Entra ID.
  • Coordinate between GRC and IT/Engineering/DevOps to reduce audit burden.
  • Support FedRAMP continuous monitoring activities, including KSI evidence, scans, and 3PAO requests.
  • Build evidence automation linking GRC tooling to source systems and workflows.
  • Support ISO 42001 AI Management System (AIMS) evidence, AI risk registers, and nonconformity tracking.
  • Prepare audit-ready evidence packages and coordinate with external assessors and certification bodies.
  • Monitor control health and drive remediation with owners before findings.

Skills

Cross-functional collaboration
Translate requirements
Highly organized
Written communication
Self-directed
AI tooling
Fast-paced environment

Education

Bachelor's degree in information systems, cybersecurity, business

Tools

AuditBoard
Vanta
Drata

Job description

About the Role

The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands‑on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A‑LIGN continuously audit‑ready. The Senior GRC Engineer works cross‑functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A‑LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.

Reports to

Chief Information Security Officer

Pay Classification

Full‑Time

Responsibilities
  • Own end‑to‑end audit evidence collection, validation, and organization across A‑LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
  • Maintain and continuously verify technical controls across A‑LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID
  • Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams
  • Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA and M tracking, and assessor (3PAO) requests
  • Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort
  • Support A‑LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking
  • Prepare audit‑ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows
  • Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur
  • Maintain compliance documentation, including control narratives, policies, and procedures
  • Support supplier and vendor security reviews with framework‑specific evidence requirements
  • Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates
  • Conduct security risk assessments and contribute to A‑LIGN's corporate risk management program and risk register
  • Participate in threat modeling for A‑SCEND features, internal systems, and AI use cases, and translate findings into control improvements
  • Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities
  • Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A‑LIGN's AI Management System
  • Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership
Minimum Qualifications
EDUCATION

Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience

EXPERIENCE
  • 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
  • Hands‑on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
  • DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
  • Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)
  • Experience supporting external audits and assessor interactions, including 3PAO assessments
  • Working knowledge of vulnerability management, CI/CD pipelines, infrastructure‑as‑code, and identity and access management concepts
  • Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred
  • Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred
CERTIFICATIONS

CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required

SKILLS
  • Strong cross‑functional collaboration and project management skills
  • Ability to translate framework requirements into clear, actionable requests for technical teams
  • Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles
  • Excellent written communication for control narratives, evidence descriptions, and assessor responses
  • Self‑directed with strong follow‑through in a fast‑paced, deadline‑driven environment
  • Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency
  • Experience operating in PE‑backed or high‑growth environments preferred
Benefits
  • Employer Paid Life and Health Insurance
  • Competitive Bonus Structure
  • Home Office Reimbursement
  • Technology Allowance
  • Certification Reimbursement
  • BeneficiaT Discount Loyalty Program
  • Personalized Career Coaching
  • Generous Paid Time Off
  • Paid Office Closure December 25-January 1
  • Summer Hours
About A‑LIGN

A‑LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A‑LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A‑LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a‑lign.com.

Come Work for A‑LIGN!

A‑LIGN is an Equal Opportunity Employer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Engineer
Senior GRC Engineer

A-LIGN • Northern (KY)

Hybrid
USD 120,000 - 180,000
Healthcare benefits
Life Insurance
Disability Insurance
+9
Senior GRC Engineer: Audit Readiness & Cloud Controls
Senior GRC Engineer: Audit Readiness & Cloud Controls

Align Technology • United States

Hybrid
USD 120,000 - 180,000
Life and Health Insurance
Bonus Structure
Home Office Reimbursement
+6
Federal Staff Consultant
Federal Staff Consultant

A-LIGN • United States

On-site
USD 60,000 - 100,000
401 (K) Plan with Employer Matching
Competitive Bonus Structure
Employer Paid Life Insurance and Disability Insurance
+6
Remote Senior GRC Engineer: Cloud Controls
Remote Senior GRC Engineer: Cloud Controls

A-LIGN • Northern (KY)

Hybrid
USD 120,000 - 180,000
Healthcare benefits
Life Insurance
Disability Insurance
+9
Project Coordinator
Project Coordinator

A-LIGN • United States

On-site
USD 50,000 - 70,000
401 (K) Plan with Employer Matching
Competitive Bonus Structure
Employer Paid Life Insurance
+7
Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • New York (NY)

Remote
USD 170,000 - 240,000
GRC Engineer
GRC Engineer

Clerk • San Francisco (CA)

Remote
USD 150,000 - 210,000
Competitive Salary
Equity Ownership
Health Coverage
+3
GRC Engineer
GRC Engineer

Aegis AI • United States

On-site
USD 120,000 - 180,000
Senior Technical Consultant - Security GRC
Senior Technical Consultant - Security GRC

Gohyred • United States

Remote
USD 150,000 - 210,000
GRC Engineer
GRC Engineer

AegisAI, Inc. • United States

Remote
USD 120,000 - 180,000