Senior Cybersecurity Engineer, GRC Automation
Core
Design, implement, and scale GRC and compliance automation solutions to reduce audit friction and strengthen operational confidence in a regulated energy environment.
Role type
Senior IC cybersecurity engineer (GRC automation & continuous controls monitoring)
Builds
Automated GRC/CCM evidence pipelines, continuous control testing workflows, and risk mitigation plans
Domain
Energy industry + Cybersecurity Governance, Risk, and Compliance (GRC)
Required skills
Python, REST API integration, GRC/CCM platform design, security control data normalization, cross-functional technical issue resolution, compliance framework application, incident investigation, SOP development, global security initiative leadership, security metrics reporting, AI/OT technology assessment
Preferred skills
LLM-backed agentic workflow development, NIST AI RMF/OWASP LLM Top 10 familiarity, professional security certifications (OSCP, GIAC, CEH)
Technologies
Azure AI Foundry, GitHub, Python, REST, IAM, ITSM, CNAPP, CSPM, SIEM, XDR, CTEM, VM, ASPM, DSPM, AI Agents
Responsibilities
Analyze cybersecurity solution changes to evaluate control effectiveness; resolve complex cross-functional technical issues; improve security solution efficiency and automated control effectiveness; review and lead improvements to processes and automation initiatives; develop and submit standard operating procedures; assess business-impacting events and evaluate control performance exceptions; investigate cyber incidents and compliance exceptions; support creation of risk mitigation and remediation plans; lead implementation of global security initiatives and continuous control monitoring; collect, validate, and report on security metrics and remediation activities; provide cybersecurity consulting to stakeholders; translate security principles for configuration teams; monitor emerging IT/OT, cybersecurity, automation, and AI technologies.
Seniority
Senior, hands-on IC