GRC Compliance Specialist
Owns GRC operations, audit coordination, evidence automation, customer security questionnaires, and risk reviews for SOC 2 and ISO 27001 compliance. The role requires 1–3 years of GRC, IT audit, or security compliance experience and familiarity with technical security controls and GRC platforms.
About the job
Responsibilities
- Maintain and improve compliance posture for SOC 2 Type II and ISO 27001.
- Assist with the roadmap for future certifications, including HIPAA and GDPR.
- Administer a GRC platform such as Vanta or Drata to automate evidence collection and monitor control health in real time.
- Lead external audit cycles and serve as the primary interface between auditors and internal technical teams.
- Own the security questionnaire process.
- Build and maintain a Trust Center or knowledge base with accurate security documentation for prospects.
- Conduct internal risk assessments and vendor security reviews.
- Work with engineers to automate evidence collection and ensure security controls are robust and well documented.
Requirements
- 1–3 years of experience in GRC, IT audit, or security compliance.
- Experience with SOC 2 or ISO 27001; end-to-end audit experience is a plus.
- Ability to understand technical security controls, including encryption, identity and access management, CI/CD, and cloud logs, and explain them to non-technical stakeholders.
- Experience with GRC automation platforms such as Vanta, Drata, or Secureframe.
- Exceptional written and verbal communication in English.
Nice-to-haves
- Experience in a high-growth SaaS startup.
- CISA, CRISC, or similar certification.
- Basic understanding of cloud infrastructure, including AWS or GCP.
Compensation and benefits
- Competitive salary and equity in a high-growth startup.
- Healthcare, dental, and vision coverage.
Skills
SOC 2, ISO 27001, HIPAA, GDPR, Vanta, Drata, Secureframe, Encryption, IAM, CI/CD, Cloud Logs, AWS, GCP, Cisa, Crisc
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.