Get more replies from employers
Send a job-specific resume in minutes.
6sense's Governance, Risk and Compliance (GRC) team builds automated security controls and continuous evidence pipelines to meet industry standards. The Senior Security Engineer role focuses on integrating AI-native approaches and ensuring audit-ready evidence through secure-by-design practices.
The engineer will design CCM, code in Python, and partner with Platform Engineering and IT to shift controls left, with self-serve evidence access for auditors and control owners.
6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.
6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.
People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Win as One Team, Stay Curious, Do The Right Thing, Own the Outcome, and Create Belonging. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career.
Senior Security Engineer, GRC (Governance, Risk and Compliance)
Director, Security Assurance
Business Technology / Security
As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense. This role is the engineering capability behind that mission. Rather than testing controls after the fact, this engineer builds the systems that test them continuously. The expectation is that controls are monitored as code, technical evidence is produced automatically from AWS and other source systems, control owners can self-serve their own evidence without a GRC ticket, and AI is used as core infrastructure across GRC workflows rather than as an experiment. Audit readiness should be a byproduct of the running system, not a project.