Senior Security Engineer, GRC
Core
Primary owner of the customer-facing compliance program, managing security questionnaires, due diligence, and compliance reviews to ensure customer confidence in the security posture.
Role type
Senior GRC Security Engineer (Customer-Facing)
Builds
End-to-end lifecycle of security questionnaires, automations for compliance validation, dashboards for program health, and third-party risk assessment processes.
Domain
SaaS / Cybersecurity Compliance
Deliverable
dashboards & analysis | client delivery
Required skills
GRC and information security compliance expertise, hands-on experience with SOC2/ISO 27001/HIPAA/PCI-DSS, managing high-volume security questionnaires, scripting and automation (Python/Bash), risk management principles, translating technical controls to business language.
Preferred skills
Security certifications (CISSP/CISM/CRISC/CISA/CCSP), experience with GRC platforms (Vanta/Drata/Sprinto), NIST CSF/800-53 familiarity, SaaS/fintech/healthcare background, drafting Data Processing Agreements.
Technologies
Python, Bash, Vanta, Drata, Sprinto, SOC2, ISO 27001, HIPAA, PCI-DSS, FedRAMP, SIG, CAIQ, NIST CSF, NIST 800-53
Responsibilities
Own intake and completion of inbound customer security questionnaires and due diligence requests; serve as primary customer-facing representative for security and compliance; build and maintain an evergreen response library; build automations to validate compliance posture across frameworks; design and automate third-party risk assessment processes; perform ongoing risk assessments and maintain a risk register; author and operationalize security policies; coordinate customer security review meetings.
Seniority
Senior, hands-on IC