Sr. Security Assurance Engineer

6sense

United States

On-site

USD 140,000 - 200,000

Full time

15 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

6sense's Governance, Risk and Compliance (GRC) team builds automated security controls and continuous evidence pipelines to meet industry standards. The Senior Security Engineer role focuses on integrating AI-native approaches and ensuring audit-ready evidence through secure-by-design practices.

The engineer will design CCM, code in Python, and partner with Platform Engineering and IT to shift controls left, with self-serve evidence access for auditors and control owners.

Responsibilities

  • Design, build, and own automated security control monitoring; write production-quality code under version control, peer review, and CI/CD.

Skills

Python
CI/CD
AWS
LLMs
Automation

Tools

AWS Config
Security Hub
CloudTrail
IAM Access Analyzer
Systems Manager
EventBridge
Lambda
Athena/S3
CloudWatch

Job description

Our Mission

6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.

Our Mission

6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.

Our People

People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Win as One Team, Stay Curious, Do The Right Thing, Own the Outcome, and Create Belonging. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career.

Job Title

Senior Security Engineer, GRC (Governance, Risk and Compliance)

Organizational Reporting

Director, Security Assurance

Function/Dept

Business Technology / Security

Purpose of the Job

As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense. This role is the engineering capability behind that mission. Rather than testing controls after the fact, this engineer builds the systems that test them continuously. The expectation is that controls are monitored as code, technical evidence is produced automatically from AWS and other source systems, control owners can self-serve their own evidence without a GRC ticket, and AI is used as core infrastructure across GRC workflows rather than as an experiment. Audit readiness should be a byproduct of the running system, not a project.

Job Description
Responsibilities & Accountabilities
  • All responsibilities of GRC Security Engineer III, and;
  • Design, build, and own automated security control monitoring; write production-quality code (e.g., Python) under version control, peer review, and CI/CD, and treat control logic as a maintained software asset rather than a documented procedure
  • Convert the control library from periodic, sample-based manual testing to continuous control monitoring (CCM): define the technical signal for each control, its test frequency, pass/fail thresholds, and alerting and escalation path
  • Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch), so control owners and auditors retrieve current evidence on demand without GRC acting as an intermediary
  • Eliminate manual, screenshot-based, and ticket-driven evidence collection; retire manual test procedures as automated equivalents come online and document the transition so auditors can rely on it
  • Redesign GRC processes to be AI-native; apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaire and customer due diligence response, policy and procedure drafting, and risk assessment triage, with explicit human-in-the-loop review, guardrails, and output validation
  • Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so that one automated test satisfies multiple obligations
  • Build the control-failure pipeline end to end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling where remediation is not viable
  • Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns
  • Instrument control health reporting: automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture, surfaced in dashboards consumable by Security leadership and control owners
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

6Sense • Austin (TX)

Hybrid
USD 141,000 - 180,000
Health insurance
401K matching
Paid holidays
+2
Sr. Security Assurance Engineer New United States, Remote
Sr. Security Assurance Engineer New United States, Remote

6Sense • Northern (KY)

Hybrid
USD 141,000 - 180,000
Health insurance
401K matching
Stock options
+1
Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

Sapphire Partners • United States

On-site
USD 141,000 - 180,000
Health insurance
401K matching
Paid time off
Senior GRC Security Engineer—Automated Compliance
Senior GRC Security Engineer—Automated Compliance

6sense • United States

On-site
USD 140,000 - 200,000
Senior GRC Automation Engineer
Senior GRC Automation Engineer

Sapphire Partners • United States

On-site
USD 141,000 - 180,000
Health insurance
401K matching
Paid time off
Senior GRC Engineer: AI-Driven Security & Compliance
Senior GRC Engineer: AI-Driven Security & Compliance

6Sense • Austin (TX)

Hybrid
USD 141,000 - 180,000
Health insurance
401K matching
Paid holidays
+2
Senior GRC Engineer — AI‑Driven, Remote
Senior GRC Engineer — AI‑Driven, Remote

6Sense • Northern (KY)

Hybrid
USD 141,000 - 180,000
Health insurance
401K matching
Stock options
+1
Security Engineer (GRC)
Security Engineer (GRC)

Candid Health • United States

On-site
USD 120,000 - 180,000
Security Compliance Engineer
Security Compliance Engineer

ANAUTICS INC • Oklahoma City (OK)

On-site
USD 80,000 - 100,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000