GRC Engineer
Core
Transform compliance, risk, and control programs from manual exercises into automated, continuously monitored systems using engineering and AI.
Role type
GRC Engineer (Engineering-first practitioner)
Builds
Automated evidence collection pipelines, GRC platform integrations, and technical controls for regulatory compliance.
Domain
Cybersecurity / GRC / Cloud Infrastructure
Deliverable
production ML models | infrastructure
Required skills
Python, Go, Bash, API integration, GRC tool automation, security frameworks (ISO 27001, SOC 2, NIST, PCI-DSS), third-party due diligence, risk management
Preferred skills
CISSP, CRISC, CCSP, AWS/Google security, continuous compliance engines (Vanta, Drata), AI risk governance (NIST AI RMF, EU AI Act)
Technologies
Python, Go, Bash, Vanta, Drata, Cloud APIs
Responsibilities
Translate regulatory requirements into technical controls; build automated evidence collection workflows; maintain ISO 27001, ISO 27701, and PCI DSS certifications; collaborate on risk management and third-party due diligence; develop security knowledge bases; manage partner security assessments.
Seniority
Mid-Senior, hands-on IC