Senior GRC Engineer
$130,000β$150,000 year
RemoteUnited States
Job Summary
Lead audit readiness and evidence management for SOC 2, ISO 27001, ISO 27701, and privacy frameworks using an automation-first approach. Architect and deploy automated workflows to transform point-in-time audits into continuous compliance monitoring across cloud and SaaS systems. Manage customer assurance requests, security questionnaires, and due diligence activities to maintain customer trust. Partner with Engineering, Security, Legal, Privacy, and Product teams to integrate compliance controls directly into software development and operational processes. Maintain and update security policies, controls, and compliance documentation to align with evolving regulatory requirements. This role focuses on engineering-driven automation rather than manual audit or checklist management.
Required Qualifications
- Demonstrated experience in GRC, cybersecurity, or IT audit within SaaS or cloud environments
- Hands-on experience supporting multi-framework audits such as SOC 2 or ISO 27001
- Capability to interpret regulatory requirements and translate compliance controls into actionable engineering and operational workflows
- Practical understanding of cloud security concepts, automation platforms, and workflow tools used to scale compliance operations
Desired Qualifications
- Relevant industry certifications such as Security+, CISA, CRISC, or ISO 27001 Internal Auditor
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.