GRC Engineer

Hands-on mid-level GRC Engineer role focused on automating continuous control monitoring, evidence collection, audit readiness, compliance workflows, risk management, and cross-functional security compliance efforts.

Responsibilities

  • Build and maintain automation for continuous control monitoring, evidence collection, and audit readiness.
  • Integrate compliance workflows with cloud providers, identity systems, ticketing platforms, and CI/CD pipelines.
  • Codify control checks and collect evidence directly from source systems.
  • Develop dashboards and reporting for control health and audit readiness.
  • Run and coordinate SOC 2, ISO 27001, and SOX audits.
  • Map controls across compliance frameworks and maintain a unified control library.
  • Track audit findings and control gaps through remediation and closure.
  • Maintain audit-ready policies, procedures, control narratives, and evidence repositories.
  • Maintain the enterprise risk register and support risk assessments.
  • Evaluate control impacts of new systems, vendors, and architectural changes.
  • Contribute to third-party risk management.
  • Partner with control owners to ensure effective controls and appropriate evidence.
  • Translate compliance requirements into engineering-focused guidance.
  • Support customer security questionnaires, trust requests, and due diligence activities.

Requirements

  • 3–5 years of experience in GRC, IT audit, security compliance, or a related field.
  • Hands-on experience supporting or leading SOC 2, ISO 27001, SOX, or comparable audits.
  • Working knowledge of SOC 2 Trust Services Criteria, ISO 27001 Annex A, COSO/SOX ITGCs, NIST, or similar frameworks.
  • Experience with Python or a similar scripting language and REST APIs for evidence collection.
  • Familiarity with AWS, GCP, or Azure and related security and logging services.
  • Strong understanding of access management, change management, logging and monitoring, vulnerability management, and SDLC controls.
  • Excellent written communication and documentation skills.
  • Ability to manage multiple priorities and drive audit findings and remediation to completion.
  • Bonus: Terraform, CI/CD pipeline security, SQL or data analysis, relevant certifications, and external auditor experience.

Benefits

  • Generous PTO
  • 7 paid holidays annually plus 5 conditional holidays annually
  • 1 service day annually
  • 401k with 3.5% company match
  • Paid parental bonding leave
  • Health, vision, and dental coverage
  • Life and disability insurance covered 100% by NinjaTrader
  • 20 additional flex remote days annually
  • 5 company-wide office-optional weeks tied to major holidays
  • Annual target bonus of 10%

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available