Senior GRC Engineer
Core
Owns end-to-end audit evidence collection, validation, and organization across multiple compliance frameworks while maintaining technical controls in cloud environments.
Role type
Senior GRC Engineer (Compliance Engineering)
Builds
Production compliance evidence packages, automated evidence integrations, and continuous monitoring artifacts for FedRAMP, ISO, and SOC 2 frameworks.
Domain
Cybersecurity Compliance / Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Audit evidence collection, technical control validation, GCP/GKE, GitHub, Microsoft 365/Entra ID, GRC platforms (AuditBoard, Vanta, Drata), Python/PowerShell scripting, risk assessment, threat modeling, vendor security reviews, AI technical safeguards
Preferred skills
DevSecOps, CI/CD pipelines, infrastructure-as-code, IAM concepts, CISA/CISSP/CCSK/CCSP/ISO Lead Auditor certifications, PE-backed environment experience
Technologies
GCP, GKE, GitHub, Microsoft 365, Entra ID, AuditBoard, Vanta, Drata, Python, PowerShell
Responsibilities
Collect and validate audit evidence for FedRAMP, ISO 27001, ISO 42001, SOC 2, and NIST frameworks; Maintain technical controls across cloud and corporate environments; Liaise with technical teams to reduce audit burden; Support FedRAMP continuous monitoring and 3PAO assessments; Build evidence automation integrations; Support ISO 42001 AI Management System; Coordinate with external assessors; Monitor control health and drive remediation; Conduct security risk assessments and threat modeling; Perform security reviews of new tools and vendors; Implement AI technical controls and safeguards.
Seniority
Senior, hands-on IC