GRC Engineer
Hands-on mid-level GRC Engineer role focused on automating continuous control monitoring, evidence collection, audit readiness, compliance workflows, risk management, and cross-functional security compliance efforts.
Responsibilities
- Build and maintain automation for continuous control monitoring, evidence collection, and audit readiness.
- Integrate compliance workflows with cloud providers, identity systems, ticketing platforms, and CI/CD pipelines.
- Codify control checks and collect evidence directly from source systems.
- Develop dashboards and reporting for control health and audit readiness.
- Run and coordinate SOC 2, ISO 27001, and SOX audits.
- Map controls across compliance frameworks and maintain a unified control library.
- Track audit findings and control gaps through remediation and closure.
- Maintain audit-ready policies, procedures, control narratives, and evidence repositories.
- Maintain the enterprise risk register and support risk assessments.
- Evaluate control impacts of new systems, vendors, and architectural changes.
- Contribute to third-party risk management.
- Partner with control owners to ensure effective controls and appropriate evidence.
- Translate compliance requirements into engineering-focused guidance.
- Support customer security questionnaires, trust requests, and due diligence activities.
Requirements
- 3–5 years of experience in GRC, IT audit, security compliance, or a related field.
- Hands-on experience supporting or leading SOC 2, ISO 27001, SOX, or comparable audits.
- Working knowledge of SOC 2 Trust Services Criteria, ISO 27001 Annex A, COSO/SOX ITGCs, NIST, or similar frameworks.
- Experience with Python or a similar scripting language and REST APIs for evidence collection.
- Familiarity with AWS, GCP, or Azure and related security and logging services.
- Strong understanding of access management, change management, logging and monitoring, vulnerability management, and SDLC controls.
- Excellent written communication and documentation skills.
- Ability to manage multiple priorities and drive audit findings and remediation to completion.
- Bonus: Terraform, CI/CD pipeline security, SQL or data analysis, relevant certifications, and external auditor experience.
Benefits
- Generous PTO
- 7 paid holidays annually plus 5 conditional holidays annually
- 1 service day annually
- 401k with 3.5% company match
- Paid parental bonding leave
- Health, vision, and dental coverage
- Life and disability insurance covered 100% by NinjaTrader
- 20 additional flex remote days annually
- 5 company-wide office-optional weeks tied to major holidays
- Annual target bonus of 10%