We are seeking a Senior Security Engineer, GRC — a hands‑on security engineer who also owns our governance, risk, and compliance programs for a regulated, SaaS based platform. This is a build‑and‑operate role, not a policy‑only one. You will configure and tune the protections that sit in front of our platform, independently evaluate and validate the security tooling we depend on, and automate the evidence and control monitoring behind our compliance programs. You will also own our SOC 2 audit cycle and our expansion into additional public sector authorization frameworks, our AI governance program, our security monitoring strategy and managed detection partnership, and our third‑party risk process. The through‑line is technical credibility: we want someone who proves a control works by testing the configuration, not only by documenting it, and who can work across engineering, legal, and product to make the result practical and durable.
Key Responsibilities:
Hands-On Security Engineering
- Configure, tune, and validate our edge and application‑layer protections — bot management, WAF rule sets, rate limiting, and DDoS/CDN policy — across our CDN and API gateway layers (e.g., Cloudflare, Azure Front Door, Azure API Management)
- Treat the security rule set as a living configuration: baseline it, tune it against real traffic, measure false positives against blocked‑attack coverage, and evolve it as the platform changes
- Review and harden identity and access controls across the platform — role design, privileged access, conditional access, and service principal and workload identity hygiene
Security Tooling & Detection
- Independently evaluate, configure, and validate our security stack: SIEM and telemetry pipelines, vulnerability scanning including AI‑enabled tooling, and cloud security posture management (CSPM) in Azure
- Judge whether each tool is actually configured to catch what it is supposed to catch — identify coverage gaps, tune signal‑to‑noise, and prove detections fire by testing them
- Own the security monitoring strategy in partnership with infrastructure, including telemetry coverage and detection use cases
- Manage the working relationship with our managed detection provider and hold that partnership to measurable outcomes
- Refine alert triage and escalation paths
- Maintain incident response runbooks and support incident response activities
- Validate NIST 800‑53 control implementations technically, using the tooling we already own, so that control assertions are evidence‑backed rather than asserted
Compliance Program Management & Automation
- Own the SOC 2 audit cycle end to end, including scoping, control mapping, evidence collection, auditor coordination, and remediation tracking
- Own our compliance automation platform — configure integrations, automate evidence collection and continuous control monitoring, and eliminate manual evidence gathering
- Keep compliance programs continuously audit‑ready and reduce the manual effort required to sustain them
- Lead expansion into additional security compliance and authorization frameworks as our public sector footprint grows
- Run readiness assessments, drive remediation, and produce system security documentation
- Manage third‑party assessors and sustain continuous monitoring obligations
Security Governance & Controls
- Own and mature our security control set aligned to NIST 800‑53 and applicable NIST guidelines
- Partner with infrastructure and engineering so controls are practical to operate, accurately documented, and validated to work as described — validated by testing the configuration, not by attestation alone
- Maintain framework crosswalks so control work and evidence are reused across programs
- Develop and maintain security policies, standards, and procedures
- Own the enterprise security risk register
AI Governance
- Own the AI governance program including usage policy, model and vendor intake, and risk assessment
- Define human oversight requirements and ongoing monitoring for AI‑enabled capabilities
- Align the program to the NIST AI Risk Management Framework and ISO/IEC 42001
- Partner with engineering and product to keep governance practical and adopted
Vendor & Third‑Party Risk
- Partner with Legal on the vendor security program including intake, tiering, and security review
- Advise on contract security terms and data protection agreements
- Own the vendor inventory and conduct periodic reassessment
Security Assurance & Documentation
- Serve as the internal security subject matter expert for RFPs, customer security questionnaires, audits, and public sector procurement reviews
- Maintain comprehensive documentation of our control environment and compliance posture
- Deliver security awareness and role‑based training programs
- Report on compliance status, risk posture, and program progress to leadership
Qualifications:
This role requires hands‑on technical depth. Candidates whose experience is limited to policy authorship, audit coordination, and evidence collection — without direct configuration and validation of security controls — will not be a fit for this position.
- 8 plus years across security engineering and security governance, risk, and compliance, with hands‑on technical ownership throughout
- Direct, hands‑on experience configuring and tuning edge and application‑layer protections — WAF rule sets, bot management, rate limiting, and DDoS/CDN controls on platforms such as Cloudflare, Azure Front Door, or Azure API Management. You should be able to walk us through rules you personally wrote or tuned and explain why
- Ability to independently evaluate, configure, and validate security tooling — SIEM and telemetry, vulnerability scanning, and cloud security posture management (CSPM) — and to assess whether a given deployment is actually catching what it should
- Hands‑on experience with identity and access management in Azure and Entra ID, including role design, privileged access, and conditional access
- Experience designing, implementing, and technically validating security controls in Microsoft Azure against NIST guidelines
- Hands‑on administration of a compliance automation platform such as Vanta or Drata — integration configuration, automated evidence collection, and continuous control monitoring, not just consuming its dashboards
- Hands‑on ownership of at least two of the following: SOC 2, NIST 800‑53, ISO 27001, FedRAMP, StateRAMP/GovRAMP, CMMC, FISMA, CSA
- Experience owning or materially supporting third‑party audits and assessments, including direct engagement with auditors and assessors
- Experience managing or working closely with a managed detection and response provider
- Experience with vendor risk management and third‑party security review
- Strong technical writing skills with the ability to produce documentation for auditors, assessors, and customers
- Strong problem‑solving and communication skills
Preferred Qualifications:
- Certifications such as CISSP, CISA, CRISC, CCSP, Microsoft Azure Security Engineer Associate (AZ‑500), or GIAC (GCIA, GCIH, GCSA)
- Hands‑on experience with AI‑enabled security tooling and its critical use cases
- Public sector or GovTech experience
- Familiarity with the NIST AI Risk Management Framework, ISO/IEC 42001, or emerging AI regulatory requirements
- Experience carrying an authorization program through certification