CareerPlanSign in

Senior Security Engineer, GRC (Governance, Risk and Compliance)

💼 Full-time🗓 2026-08-13 → 2026-09-24

Core

Senior Security Engineer leading Governance, Risk, and Compliance (GRC) initiatives as the second line of defense, aligning security with business objectives and managing risks.

Role type

Senior IC GRC Security Engineer

Builds

Security governance programs, risk management strategies, compliance frameworks, and automated control tests

Domain

Cybersecurity, GRC, Cloud Security, Regulatory Compliance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

GRC frameworks (ISO 27001, SOC 2, GDPR, PCI, SOX, NIST), security automation, cloud environments (AWS), vulnerability scanning, SIEM, SOAR, control testing, risk assessment, audit engagement management, remediation planning

Preferred skills

Big 4 consulting experience, CISSP/CISM/GIAC certifications

Technologies

AWS, GRC tools, Vulnerability Scanners, SIEM, SOAR

Responsibilities

Lead internal and external audit engagements; execute complex control tests and third-party risk assessments; develop issue and risk treatment plans; design and improve security control test activities; mature security governance, training, and awareness programs; design and implement GRC control automation; maintain security program controlled documents

Seniority

Senior, hands-on IC

Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.