Senior GRC Engineer
Core
Designing the technical architecture for governance, risk, and compliance across multiple regulatory frameworks and brands.
Role type
Senior GRC Engineer (Technical)
Builds
Master Control List, AI-powered GRC tooling, multi-agent pipelines for risk quantification and evidence automation.
Domain
Cybersecurity, Compliance, GRC
Deliverable
production ML models | infrastructure
Required skills
GRC framework design, control mapping, compliance automation, AI/LLM pipeline development, relational database architecture, technical control implementation
Preferred skills
AWS services, external audit support, multi-brand control harmonization, security certifications
Technologies
OSCAL, AWS (Lambda, Step Functions, EventBridge, S3, Aurora/RDS), LLM-based pipelines, RAG architectures
Responsibilities
Design and build framework crosswalks across PCI DSS, SOC 1, ISO 27001, HITRUST, and NIST CSF/800-53; Own the Master Control List end-to-end; Manage the full lifecycle of controls and evidence requirements; Drive evidence automation in GRC tooling; Design and maintain AI-powered GRC tooling and multi-agent pipelines; Identify rationalization opportunities across frameworks.
Seniority
Senior, hands-on IC
