# Senior Security Assurance Engineer

**Company:** [6sense](https://hotfix.jobs/companies/6sense)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Python, Git, CI/CD, Aws Config, Aws Security Hub, Aws Cloudtrail, Aws Iam, Aws Organizations, Aws Scps, AWS Lambda, Amazon Eventbridge, Amazon S3, Amazon Athena, Amazon Cloudwatch, Terraform
**Posted:** 2026-08-28

> Build and operate automated continuous security control monitoring, AWS evidence collection, and AI-enabled GRC workflows. The role requires at least five years of GRC experience, hands-on automation and AWS expertise, and the ability to defend automated controls and evidence to auditors.

## Job Description

## Responsibilities
- Design, build, and own automated security control monitoring using production-quality, version-controlled code, peer review, and CI/CD.
- Convert manual, sample-based control testing to continuous control monitoring by defining technical signals, test frequency, pass/fail thresholds, alerting, and escalation.
- Engineer self-service AWS evidence collection using native services, eliminating screenshot-based and ticket-driven processes.
- Apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, questionnaires, policy drafting, and risk triage with human review and guardrails.
- Maintain a normalized control library mapped across ISO 27001, SOC 2, PCI DSS, SOX, GDPR, and NIST.
- Build end-to-end control-failure workflows for detection, enrichment, ticketing, routing, SLA tracking, remediation verification, exceptions, and risk acceptance.
- Partner with Platform Engineering, DevOps, and IT to implement preventive guardrails, policy-as-code, and secure-by-default infrastructure.
- Report control health, automation coverage, evidence freshness, failure rates, remediation times, and audit readiness through dashboards.
- Lead internal and external audits and defend automated test designs and system-generated evidence.
- Execute control tests and third-party and operational security risk assessments; develop treatment plans and validate remediation through automated retesting.
- Review GRC automation and provide technical guidance, enablement, and distributed ownership across the team.
- Administer GRC technology, integrations, API data flows, and user training.
- Maintain governance programs, documentation, runbooks, dashboards, and controlled security documents; execute quarterly OKRs.

## Requirements
- 5+ years of experience in GRC or a similar security function.
- 2+ years building and maintaining automation.
- Proficiency in at least one scripting or programming language, preferably Python.
- Experience with Git, code review, and CI/CD.
- Hands-on AWS experience with Config, Security Hub, CloudTrail, IAM, Organizations, SCPs, Lambda, EventBridge, S3, Athena, and CloudWatch.
- Experience retrieving, normalizing, and reconciling data through APIs and SQL.
- Practical experience applying LLMs or AI agents to real workflows, including prompt design, workflow design, output evaluation, review, and guardrails.
- Experience with GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, and cloud environments.
- Knowledge of ISO 27001, SOC 2, GDPR, PCI DSS, SOX, NIST, and related standards.
- Ability to determine sufficient audit evidence and defend automated testing to auditors.

## Preferred Qualifications
- Infrastructure as code experience with Terraform or CloudFormation.
- Policy-as-code experience with OPA/Rego, AWS Config custom rules, cfn-guard, or similar tools.
- Experience implementing continuous control monitoring at scale in SaaS or multi-account cloud environments.
- Experience integrating GRC platforms through APIs and building internal self-service tooling.
- Big Four or similar experience.
- Bachelor's degree in a related field.
- CISSP, CISM, GIAC, AWS Certified Security – Specialty, CCSK, or CCSP certification.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/6dd1b7f0-e6ab-42a7-ba23-90ab24eca77d
**Canonical:** https://hotfix.jobs/jobs/6dd1b7f0-e6ab-42a7-ba23-90ab24eca77d