Senior Security Assurance Engineer
Build and operate automated continuous security control monitoring, AWS evidence collection, and AI-enabled GRC workflows. The role requires at least five years of GRC experience, hands-on automation and AWS expertise, and the ability to defend automated controls and evidence to auditors.
About the job
Responsibilities
- Design, build, and own automated security control monitoring using production-quality, version-controlled code, peer review, and CI/CD.
- Convert manual, sample-based control testing to continuous control monitoring by defining technical signals, test frequency, pass/fail thresholds, alerting, and escalation.
- Engineer self-service AWS evidence collection using native services, eliminating screenshot-based and ticket-driven processes.
- Apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, questionnaires, policy drafting, and risk triage with human review and guardrails.
- Maintain a normalized control library mapped across ISO 27001, SOC 2, PCI DSS, SOX, GDPR, and NIST.
- Build end-to-end control-failure workflows for detection, enrichment, ticketing, routing, SLA tracking, remediation verification, exceptions, and risk acceptance.
- Partner with Platform Engineering, DevOps, and IT to implement preventive guardrails, policy-as-code, and secure-by-default infrastructure.
- Report control health, automation coverage, evidence freshness, failure rates, remediation times, and audit readiness through dashboards.
- Lead internal and external audits and defend automated test designs and system-generated evidence.
- Execute control tests and third-party and operational security risk assessments; develop treatment plans and validate remediation through automated retesting.
- Review GRC automation and provide technical guidance, enablement, and distributed ownership across the team.
- Administer GRC technology, integrations, API data flows, and user training.
- Maintain governance programs, documentation, runbooks, dashboards, and controlled security documents; execute quarterly OKRs.
Requirements
- 5+ years of experience in GRC or a similar security function.
- 2+ years building and maintaining automation.
- Proficiency in at least one scripting or programming language, preferably Python.
- Experience with Git, code review, and CI/CD.
- Hands-on AWS experience with Config, Security Hub, CloudTrail, IAM, Organizations, SCPs, Lambda, EventBridge, S3, Athena, and CloudWatch.
- Experience retrieving, normalizing, and reconciling data through APIs and SQL.
- Practical experience applying LLMs or AI agents to real workflows, including prompt design, workflow design, output evaluation, review, and guardrails.
- Experience with GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, and cloud environments.
- Knowledge of ISO 27001, SOC 2, GDPR, PCI DSS, SOX, NIST, and related standards.
- Ability to determine sufficient audit evidence and defend automated testing to auditors.
Preferred Qualifications
- Infrastructure as code experience with Terraform or CloudFormation.
- Policy-as-code experience with OPA/Rego, AWS Config custom rules, cfn-guard, or similar tools.
- Experience implementing continuous control monitoring at scale in SaaS or multi-account cloud environments.
- Experience integrating GRC platforms through APIs and building internal self-service tooling.
- Big Four or similar experience.
- Bachelor's degree in a related field.
- CISSP, CISM, GIAC, AWS Certified Security – Specialty, CCSK, or CCSP certification.
Skills
Python, Git, CI/CD, Aws Config, Aws Security Hub, Aws Cloudtrail, Aws Iam, Aws Organizations, Aws Scps, AWS Lambda, Amazon Eventbridge, Amazon S3, Amazon Athena, Amazon Cloudwatch, Terraform
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.