Skip to content

Security GRC Specialist

Hands-on Security GRC Specialist owning compliance frameworks like SOC 2 and ISO 27001, driving audits, customer trust initiatives, and engineering collaborations to implement scalable security controls. Requires 3-7+ years experience with technical mindset in cloud environments.

150k – 270kNew York, NYSan Francisco, CASecurity EngineeringHybrid3+ YOE

About the role

What You'll Do

Compliance & Security Programs

  • Own and operate compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, etc.)
  • Drive audits end-to-end: readiness, evidence collection, auditor coordination
  • Continuously improve controls and reduce compliance overhead through automation

Customer Trust & Sales Enablement

  • Lead responses to customer security questionnaires, RFPs, and due diligence requests
  • Partner with Sales and Customer Success to unblock deals and build trust
  • Develop and maintain security documentation (trust center, whitepapers, FAQs)

Engineering Collaboration

  • Work directly with engineering teams to design and implement practical security controls
  • Translate compliance requirements into technical, scalable solutions
  • Identify gaps and drive remediation projects (not just report them)

Risk & Governance

  • Run risk assessments across systems, vendors, and processes
  • Maintain policies and standards, but keep them lightweight and actionable
  • Track and report on security posture and compliance status

Process & Tooling

  • Improve how we manage compliance (evidence collection, control mapping, automation)
  • Evaluate and implement GRC/security tools where appropriate

Requirements

Core Experience

  • 3–7+ years in security GRC, compliance, or security engineering-adjacent roles
  • Hands-on experience with frameworks like SOC 2, ISO 27001, or similar
  • Experience supporting audits and customer-facing security conversations

Technical Mindset (Important)

  • Comfortable working with engineers and understanding systems (cloud, infra, APIs, etc.)
  • Ability to translate between compliance language and technical implementation
  • Experience with modern cloud environments (AWS/GCP/Azure) is a strong plus

Execution & Ownership

  • Proactive and hands-on—you drive changes, not just track them
  • Able to balance rigor with pragmatism in a fast-moving environment
  • Strong communication skills, especially with customers and cross-functional teams

Bonus

  • Experience building or scaling a GRC program from early stages
  • Familiarity with automation in compliance workflows
  • Background in security engineering or DevOps

Skills

SOC 2ISO 27001GDPRAWSGCPAzureGrc ToolsCloud InfrastructureAutomationDevOps

IT Security Operations Engineer

IT Security Operations Engineer responsible for implementing DLP, email security, endpoint protection, Okta/Google Workspace hardening, automation, compliance evidence collection, and incident response in a hybrid healthcare AI startup.

150k – 190kSan Francisco, CASecurity EngineeringHybrid4+ YOEGoDlp

Security Engineer

Build and maintain security automation pipelines, AI agents, SOAR/SIEM integrations, vulnerability management, and IAM systems for a sports prediction market platform.

150k – 200kNew York, NYSecurity EngineeringOn-site5+ YOECdkIAM

Manager, Security Incident Response Team (USA)

Leads the Security Incident Response Team in the Americas, managing engineers through threat hunting, investigations, triage, and large-scale responses while coaching performance and driving process improvements using AI and automation.

150k – 235kUnited StatesSecurity EngineeringRemoteAIGCP

Security Engineer (Purple Team)

Performs offensive security testing, penetration assessments, and risk analysis on vehicle software platforms and embedded systems. Collaborates with engineering teams to design secure architectures and implement mitigations for automotive products.

150k – 220kSunnyvale, CASecurity EngineeringOn-siteCC++

Infrastructure Security Engineer

Designs and secures core infrastructure for multi-tenant AI platform, focusing on container isolation, orchestration (Kubernetes), identity management, secrets handling, and cloud security across AWS/GCP. Requires production experience in cloud-native systems and builder mindset for hands-on implementation.

150k – 270kNew York, NY +1Security EngineeringHybridAWSGCP