Skip to content

GRC Automation & Assurance Lead

174k – 215kNew York, NYSecurity EngineeringOnsite4+ YOE
Summary

Lead GRC audit, assurance, and compliance programs while architecting and shipping AI agents to automate evidence collection, control testing, questionnaires, and audit prep for ISO 27001 and SOC 2.

About the role

Responsibilities

AI Automation and Tooling

  • Architect, build, and maintain agents on Rokt's internal Security Agent Suite for GRC workflows, including client security questionnaires, evidence collection, control testing, vendor assessments, DPIAs, and audit preparation
  • Design new GRC automations end-to-end: scope the workflow, build the agent or tool, validate outputs, and roll it out with the rest of the GRC team
  • Build internal tools and integrations using AI coding agents (Claude Code, Cursor, or equivalents) to extend in-house GRC systems and Jira-based workflows
  • Continuously evaluate agent performance, refine prompts and tool definitions, and improve coverage and accuracy of automated controls

Audit, Assurance, and Compliance

  • Lead the ISO 27001:2022 surveillance and recertification cycles, and SOC 1 and SOC 2 Type 2 audits, end-to-end
  • Plan and execute Rokt's internal audit program (user access, exemptions, DPIAs, SCF controls, AI controls), ideally with agent-assisted execution
  • Drive external auditor engagement, evidence collection, and remediation tracking
  • Manage the processing of client security questionnaires using and continuously improving the questionnaire agent
  • Maintain and evolve ISMS performance metrics, including new metrics covering AI control effectiveness and automation coverage
  • Coordinate Rokt's security calendar including audit windows
  • Produce and maintain quality procedure documentation co-authored with AI assistance

Requirements

Compliance and Audit Experience

  • 4+ years of relevant experience in Governance, Risk & Compliance, ideally in a fast-moving tech environment
  • Working knowledge of ISO 27000 family, SOC 1, SOC 2, NIST CSF, and privacy regulations (GDPR, CCPA, CPRA); bonus for PCI-DSS, CIS, SCF, ISO 42001, NIST AI RMF
  • Hands-on internal auditing experience against ISO 27001 and SOC 2
  • Track record managing external audits end-to-end, including evidence collection, auditor engagement, and findings remediation
  • Solid grasp of controller/processor concepts and broader privacy fundamentals

AI and Technical Skills

  • Demonstrated experience designing and shipping agentic AI systems — not just using a chatbot; built agents that take actions, call tools, integrate with APIs, and complete multi-step workflows
  • Comfortable using AI coding agents (Claude Code, Cursor, Copilot, or similar) to build and maintain internal tools; able to read, modify, and ship code even if not a software engineer
  • Familiarity with at least one agent framework (Google ADK, LangGraph, OpenAI Agents SDK, MCP, or similar) and the core patterns: tool use, memory, evaluation, guardrails
  • Understanding of LLM risks and controls — prompt injection, model misuse, agent autonomy, data leakage — and how they map to frameworks like OWASP Agentic Top 10 or NIST AI RMF
  • Working knowledge of basic IT, cloud (AWS preferred), APIs, and SQL
  • Comfort with version control (Git/GitHub) and basic scripting (Python or TypeScript)

Ways of Working

  • Strong written and verbal communication; able to translate technical detail into business language for leadership, clients, and auditors
  • Demonstrated ability to break complex compliance requirements into scalable, automated processes that don't slow the business down
  • Bias for shipping, comfort with ambiguity, and a builder mindset
  • Strong attention to detail balanced with willingness to use AI to extend it
  • Highly responsive, autonomous, and resilient

Compensation

Target total compensation ranges from $214,000 - $255,000, including a fixed annual salary of $174,000- $215,000, an employee equity plan grant, and world-class benefits.

Skills
ISO 27001SOC 2SOC 1NIST CSFGDPRCCPACPRAAWSSQLPythonTypeScriptGitLangGraphOpenAI Agents SDKAI agent development
Similar roles at this salary range
All Security Engineering jobs →
Novig

Senior Security Engineer

Senior Security Engineer building proactive, automated security systems including SOAR/SIEM workflows, AI agents, vulnerability management, and cloud hardening for a fast-growing sports prediction market platform.

200k – 250kNew York, NYSecurity EngineeringOn-site5+ YOECDKIAM
Novig

Security Engineer

Build and maintain security automation pipelines, AI agents, SOAR/SIEM integrations, vulnerability management, and IAM systems for a sports prediction market platform.

150k – 200kNew York, NYSecurity EngineeringOn-site5+ YOECDKIAM
Instacart

Senior Security Engineer, Cloud, AI, Product Security

Senior Security Engineer responsible for identifying infrastructure and product risks, defining remediation roadmaps, and building scalable secure engineering systems. Requires 5+ years in security engineering and strong IaC and code review experience.

192k – 242kUnited StatesSecurity EngineeringRemote5+ YOEGoOPA
Coinbase

Senior Software Engineer

Senior Software Engineer on the Core Cryptography team building and operating Tier-0 cryptographic infrastructure including MPC systems that secure 99% of customer assets. Requires 5+ years building highly available distributed systems and experience with applied cryptography, KMS/HSMs, and systems languages (Golang-heavy).

186k – 219kUnited StatesSecurity EngineeringRemote5+ YOEC++Java
Okta

Staff Product Security Engineer

Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.

141k – 248kBellevue, WA +4Security EngineeringHybrid7+ YOEGoSAML