Skip to content
6sense6sense

Senior Security Assurance Engineer

Build and operate automated continuous security control monitoring, AWS evidence collection, and AI-enabled GRC workflows. The role requires at least five years of GRC experience, hands-on automation and AWS expertise, and the ability to defend automated controls and evidence to auditors.

About the job

Responsibilities

  • Design, build, and own automated security control monitoring using production-quality, version-controlled code, peer review, and CI/CD.
  • Convert manual, sample-based control testing to continuous control monitoring by defining technical signals, test frequency, pass/fail thresholds, alerting, and escalation.
  • Engineer self-service AWS evidence collection using native services, eliminating screenshot-based and ticket-driven processes.
  • Apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, questionnaires, policy drafting, and risk triage with human review and guardrails.
  • Maintain a normalized control library mapped across ISO 27001, SOC 2, PCI DSS, SOX, GDPR, and NIST.
  • Build end-to-end control-failure workflows for detection, enrichment, ticketing, routing, SLA tracking, remediation verification, exceptions, and risk acceptance.
  • Partner with Platform Engineering, DevOps, and IT to implement preventive guardrails, policy-as-code, and secure-by-default infrastructure.
  • Report control health, automation coverage, evidence freshness, failure rates, remediation times, and audit readiness through dashboards.
  • Lead internal and external audits and defend automated test designs and system-generated evidence.
  • Execute control tests and third-party and operational security risk assessments; develop treatment plans and validate remediation through automated retesting.
  • Review GRC automation and provide technical guidance, enablement, and distributed ownership across the team.
  • Administer GRC technology, integrations, API data flows, and user training.
  • Maintain governance programs, documentation, runbooks, dashboards, and controlled security documents; execute quarterly OKRs.

Requirements

  • 5+ years of experience in GRC or a similar security function.
  • 2+ years building and maintaining automation.
  • Proficiency in at least one scripting or programming language, preferably Python.
  • Experience with Git, code review, and CI/CD.
  • Hands-on AWS experience with Config, Security Hub, CloudTrail, IAM, Organizations, SCPs, Lambda, EventBridge, S3, Athena, and CloudWatch.
  • Experience retrieving, normalizing, and reconciling data through APIs and SQL.
  • Practical experience applying LLMs or AI agents to real workflows, including prompt design, workflow design, output evaluation, review, and guardrails.
  • Experience with GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, and cloud environments.
  • Knowledge of ISO 27001, SOC 2, GDPR, PCI DSS, SOX, NIST, and related standards.
  • Ability to determine sufficient audit evidence and defend automated testing to auditors.

Preferred Qualifications

  • Infrastructure as code experience with Terraform or CloudFormation.
  • Policy-as-code experience with OPA/Rego, AWS Config custom rules, cfn-guard, or similar tools.
  • Experience implementing continuous control monitoring at scale in SaaS or multi-account cloud environments.
  • Experience integrating GRC platforms through APIs and building internal self-service tooling.
  • Big Four or similar experience.
  • Bachelor's degree in a related field.
  • CISSP, CISM, GIAC, AWS Certified Security – Specialty, CCSK, or CCSP certification.

Skills

Python, Git, CI/CD, Aws Config, Aws Security Hub, Aws Cloudtrail, Aws Iam, Aws Organizations, Aws Scps, AWS Lambda, Amazon Eventbridge, Amazon S3, Amazon Athena, Amazon Cloudwatch, Terraform

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.