Senior Information Security Engineer
Core
Senior Information Security Engineer driving automation and technical implementation of Governance, Risk & Compliance (GRC) frameworks, business continuity, and AI security for a global SaaS platform.
Role type
Senior IC Information Security Engineer (GRC & Automation)
Builds
Automated compliance workflows, evidence collection systems, and scalable GRC tooling integrated into engineering pipelines.
Domain
Cybersecurity, GRC, Business Continuity, AI Security, Cloud Compliance
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
GRC framework expertise, technical security architecture assessment, automation/scripting, risk management, incident response, cloud security, AI security principles
Preferred skills
CISA/CRISC/CISM/CCSK certifications, ISO 9001/27017/27018 knowledge, BSI C5 framework experience, threat modelling, secure SDLC
Technologies
ISO 27001, ISO 22301, ISO 42001, SOC 2, AWS, CI/CD pipelines, compliance platforms
Responsibilities
Design automation blueprints for manual GRC processes (evidence collection, control monitoring, access reviews); Build and maintain automated workflows using scripting or integration tools; Collaborate with engineering teams to integrate security checks into CI/CD pipelines; Support SOC 2 Type II, ISO 27001, ISO 22301, and ISO 42001 audit lifecycles; Conduct vendor risk management and third-party security assessments; Evaluate security controls for AI/ML features and services.
Seniority
Senior, hands-on IC