Skip to content
HappyRobotHappyRobot

GRC Compliance Specialist

Owns GRC operations, audit coordination, evidence automation, customer security questionnaires, and risk reviews for SOC 2 and ISO 27001 compliance. The role requires 1–3 years of GRC, IT audit, or security compliance experience and familiarity with technical security controls and GRC platforms.

About the job

Responsibilities

  • Maintain and improve compliance posture for SOC 2 Type II and ISO 27001.
  • Assist with the roadmap for future certifications, including HIPAA and GDPR.
  • Administer a GRC platform such as Vanta or Drata to automate evidence collection and monitor control health in real time.
  • Lead external audit cycles and serve as the primary interface between auditors and internal technical teams.
  • Own the security questionnaire process.
  • Build and maintain a Trust Center or knowledge base with accurate security documentation for prospects.
  • Conduct internal risk assessments and vendor security reviews.
  • Work with engineers to automate evidence collection and ensure security controls are robust and well documented.

Requirements

  • 1–3 years of experience in GRC, IT audit, or security compliance.
  • Experience with SOC 2 or ISO 27001; end-to-end audit experience is a plus.
  • Ability to understand technical security controls, including encryption, identity and access management, CI/CD, and cloud logs, and explain them to non-technical stakeholders.
  • Experience with GRC automation platforms such as Vanta, Drata, or Secureframe.
  • Exceptional written and verbal communication in English.

Nice-to-haves

  • Experience in a high-growth SaaS startup.
  • CISA, CRISC, or similar certification.
  • Basic understanding of cloud infrastructure, including AWS or GCP.

Compensation and benefits

  • Competitive salary and equity in a high-growth startup.
  • Healthcare, dental, and vision coverage.

Skills

SOC 2, ISO 27001, HIPAA, GDPR, Vanta, Drata, Secureframe, Encryption, IAM, CI/CD, Cloud Logs, AWS, GCP, Cisa, Crisc

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Docker

Docker

United Kingdom
Senior Security Engineer, Offensive Security
€119k+/yrRemote5+ YOESecurity Engineering

Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Wiz

Wiz

Berlin, Germany
Security Engineer - Product
No salary listedOn-site7+ YOESecurity Engineering

Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.