Senior Risk & Governance Engineer
Core
Design and build automated compliance testing pipelines, GRC platform integrations, and AI-native governance frameworks for a SaaS market intelligence platform.
Role type
Senior GRC Engineer (AI-native, automation focus)
Builds
Automated compliance testing pipelines, GRC platform integrations, AI-assisted evidence workflows, and policy-as-code frameworks
Domain
SaaS / Cloud Security / Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | infrastructure
Required skills
GRC frameworks (SOC 2, ISO 27001, NIST CSF, ISO 42001), Cloud security (AWS/Azure/GCP), GRC platforms (Drata, Vanta, AuditBoard), API integration, Policy as Code, AI/LLM application for substantive work, Automated control collection
Preferred skills
Experience with agentic systems, NIST AI RMF, SIEM/EDR/CSPM tooling
Technologies
Drata, Vanta, AuditBoard, ServiceNow GRC, AWS, Azure, GCP, LLMs, Agentic frameworks, SIEM, EDR, CSPM
Responsibilities
Design automated compliance testing pipelines; Own GRC platform configuration and API integrations; Develop AI-assisted workflows for evidence and risk analysis; Define governance frameworks for AI and agentic systems; Build policy-as-code programs; Instrument controls with observability tooling; Integrate GRC tooling with security stacks
Seniority
Senior, hands-on IC