GRC Engineer
$188,000–$221,000 year
On-siteNew York City, New York, United States
Job Summary
Build pipelines and integrations that aggregate control, asset, and identity data across the stack to automate checks, live dashboards, and audit evidence. Implement a unified controls library where evidence is collected once and mapped everywhere, ingesting from existing technical controls and SaaS portfolios rather than building parallel collectors. Translate written policies and regulatory requirements into enforceable rules for CI/CD and infrastructure deployment, instrumenting control effectiveness to report risk posture from live data. Design and run agentic workflows for evidence analysis, control testing, and audit response preparation, ensuring anything manual twice a quarter gets automated. This engineering seat within the Security organization proves how Legora's systems behave by turning certifications into an output of normal operations for our AI-native workspace used by 1,000+ customers across 50+ countries.
Required Qualifications
- 5+ years spanning software or automation engineering and security compliance
- Production-grade scripting (Python or similar) against APIs
- Hands-on experience building LLM/agent workflows
- Enough GRC domain fluency to work inside SOC 2 / ISO 27001 control language
- Clear technical writing
Desired Qualifications
- Experience with compliance platform APIs and when to build past them
- OSCAL or other machine-readable control/catalog formats
- Infrastructure-as-code (Terraform or similar) and CI/CD pipeline engineering
- Prior work on AI product assurance: evals, red-teaming evidence, or model/agent documentation
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.