GRC Engineer - Platform Team
RemoteUnited Kingdom or Germany
Job Summary
Own continuous compliance end-to-end for SOC 2, ISO 27001, and customer security reviews, keeping the organization audit-ready year-round. Manage and evolve the compliance roadmap, prioritizing initiatives against business needs while owning Vanta end-to-end, including tasks, documentation, and automated evidence collection. Lead quarterly access reviews across all systems in collaboration with IT and Engineering, ensuring findings are tracked through to remediation. Run vendor risk reviews and DPIAs for new tools, especially AI tooling, and help teams adopt new software without compromising the risk posture. Serve as the technical voice on customer security questionnaires and DPAs, working alongside Sales and Legal to keep deals moving. Define and report compliance and risk KPIs to leadership, giving them a clear, ongoing view of our posture and where investment is needed. Partner with the Security Architect to identify and close gaps between written policy and actual control implementation.
Required Qualifications
- 4+ years in GRC, security compliance, or audit readiness at a SaaS company, ideally in a regulated environment (Finance, Insurance, Healthcare)
- Has owned a SOC 2 program end-to-end (must-have)
- familiar with GDPR, PCI DSS, and the EU AI Act
- Deep experience running Vanta (or Drata/Secureframe) as a continuous compliance backbone, not a point-in-time checklist
- Technically hands-on: comfortable scripting against AWS APIs to automate evidence collection, with a solid grasp of software development and security concepts
- A strong writer and communicator who can turn around a 200-row security questionnaire quickly and accurately, and translate fluently between compliance and technical teams
Desired Qualifications
- Experience with customer trust programs (Trust Center, FAQs, security whitepapers)
- DORA / EU AI Act / fintech regulatory exposure
- Has shipped engineering-led automation (not just dashboards)
- Familiarity with NIST CSF, CIS Controls, or GDPR/DPAs
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.