Senior GRC Engineer
Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
About the job
Responsibilities
- Build and operate pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from source control, service registries, identity providers, ticketing, data platforms, and CI/CD systems.
- Translate security standards and compliance requirements into versioned, tested policy-as-code rules.
- Design agentic AI workflows combining LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment.
- Build evaluation, benchmarking, and calibration harnesses for automated governance systems.
- Automate evidence collection and continuous control monitoring.
- Define technical approaches for ambiguous, cross-team problem spaces and carry them across team boundaries.
- Partner with Security Governance, Compliance, and Engineering teams to productize manual processes.
- Help govern the company's AI systems by assessing agent autonomy and safety.
- Contribute to technical design discussions and evaluate platform security and reliability.
Requirements
- 7+ years building production software in backend, platform, data, or security engineering.
- Multi-year ownership of a production system, including on-call, SLOs, and post-launch maintenance.
- Proficiency in Python, Kotlin, Java, or Go, with the ability to read unfamiliar codebases.
- Hands-on experience building with LLMs, including prompting, tool use, agents, or LLM-backed features.
- Experience with REST APIs, webhooks, authentication flows, and event-driven architectures.
- Experience pulling, normalizing, and joining data from multiple imperfect sources.
- Experience defining technical direction for ambiguous problems and coordinating across teams.
- Strong attention to detail and pragmatic, risk-based prioritization.
Nice to Have
- Knowledge of PCI DSS, SOX, SOC 2, ISO 27001, or NIST.
- Production-scale LLM or agentic systems experience.
Technologies
- Python
- Java
- Kotlin
- Go
- LLM APIs
- Model Context Protocol
- REST APIs
- gRPC
- Protocol Buffers
- SQL
- Snowflake
- AWS
- Google Cloud
- Kubernetes
- Terraform
- CI/CD
Compensation
- Annual base salary range: $185,200–$326,800 USD, depending on location and market zone.
- Benefits include remote work, medical insurance, flexible time off, retirement savings plans, and family planning benefits.
Skills
Python, Java, Kotlin, Go, LLM APIs, Model Context Protocol, REST APIs, gRPC, Protocol Buffers, SQL, Snowflake, AWS, GCP, Kubernetes, Terraform
Similar jobs
Security Engineering jobsThis role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.
Own end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.
The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.
Build and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.