Staff GRC Engineer
Core
Leading the engineering design, scaling, and automation of strategic Governance, Risk & Compliance (GRC) initiatives to strengthen customer trust programs and drive third-party risk management.
Role type
Staff GRC Engineer (Technical/Engineering focus)
Builds
Automated GRC workflows, control evidence collection systems, and risk dashboards for customer trust and vendor risk management.
Domain
Cybersecurity / GRC / Third-Party Risk Management (TPRM)
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Engineering technical solutions for security/compliance, scaling enterprise GRC frameworks (ISO 27001, NIST CSF, SOC 2, FedRAMP), AI tool application for automation, cloud security evaluation (AWS, Azure, GCP), vendor risk assessment, technical control validation, Agile methodology, data insights for KRIs/KPIs
Preferred skills
Professional certifications (CISSP, CISM, CRISC, cloud security credentials)
Technologies
Anecdotes, OneTrust, RSA Archer, MetricStream, SOAR, GRC/AI tools
Responsibilities
Lead engineering and implementation of GRC framework, automate control evidence collection, define and monitor risk indicators, design vendor risk assessments, provide security intelligence on risks, collaborate with Legal/Procurement/Product to embed requirements, mentor team members
Seniority
Staff, hands-on IC with strategic influence