GRC Engineer
RemoteUnited States
Job Summary
Conduct cybersecurity risk assessments, including third-party/vendor risk evaluations, and proactively identify security & policy gaps in existing systems. Bring and keep ZBD systems, processes, and procedures into compliance with frameworks like SOC 2, DORA, GDPR, and PCI DSS. Design, implement, and maintain security solutions to address vulnerabilities, enforce technical standards, and develop cloud recovery and backup solutions. Work closely with software engineers to establish security compliance posture and contribute to security documentation. Participate in an On-Call rotation while applying appropriate technical approaches based on problem complexity.
Required Qualifications
- 3+ years of experience in security governance, cloud and application security assessments, risk management, and/or third party risk
- Thorough understanding of cybersecurity principles, cloud security, and identity and access management
- Firm grasp on cloud computing principles
- Demonstrated experience with Infrastructure as Code using Terraform/OpenTofu
- Working knowledge of Linux
- Experience with metrics gathering, alerting, reporting
- Experience with git, GitLab, and CI/CD pipelines
- Ability to design, implement, and improve cybersecurity solutions
- Ability to balance cybersecurity initiatives with business initiatives
- Ability to identify and analyze potential methods of attack
- Comfortable working in a growth-stage startup
- Comfort navigating ambiguity and fast-paced environments
- Participate in an On-Call rotation
Desired Qualifications
- Experience with AWS Organizations and Multi Accounts
- Experience as a software engineer
- Experience with SOC 2 compliance efforts
- Knowledge of, and experience working with Bitcoin and Lightning Network software
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.