This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a GRC Automation Engineer to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will report to the Head of GRC and help shape the next iteration of the GRC program and further embed data governance principles and compliance requirements into the business.
Job Responsibility:
Design and automate control testing and evidence collection to reduce manual effort and improve accuracy
Build and maintain scripts and APIs across infrastructure, endpoints, and SaaS platforms (e.g., AWS, GitHub, Okta) that interface with compliance tooling
Support recurring internal and external audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) by ensuring reliable control monitoring
Champion security, compliance, data governance strategies and processes, including data deletion, data retention, data storage, and more
Leverage AI/ML tools to improve efficiency and outcomes for GRC processes and overall compliance posture
Define technical control requirements and collaborate with internal partners to embed compliance checks into CI/CD pipelines and infrastructure deployment workflows
Requirements:
Experience in scripting or automation with a focus on security, infrastructure, or GRC
Knowledge of audit processes, evidence requirements, and remediation actions for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS)
Ability to write scripts and basic code to automate audit and evidence gathering processes
Ability to build API end points and command-line tools, work with structured data (JSON, CSV, YAML), and extract compliance-relevant information from security, IT, and GRC systems
Experience owning a project or scope, building relationships, collaborating with both technical and non-technical teams and driving initiatives to completion
Nice to have:
Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Satori, Github, etc.)
Experience with frontend cloud, AI/ML systems, and open source development
Experience with FedRAMP or NIST frameworks, such as 800-53, 800-171, RMF
Security certifications (e.g. CISA, CISSP)
What we offer:
Competitive compensation package, including equity
Inclusive Healthcare Package
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills
Flexible Time Off
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed