Skip to content

Senior GRC Lead

Leads GRC initiatives by automating compliance workflows, building security tool integrations, and implementing controls for frameworks like SOC 2, PCI DSS, and ISO 27001 in cloud environments. Requires 5+ years experience, Python proficiency, and strong cross-functional collaboration.

154k – 192kSeattle, WASecurity EngineeringHybrid5+ YOE

About the role

Responsibilities

  • Manage and scale IT infrastructure, services and tooling
  • Work with a diverse group of IT partners to optimize our provided services
  • Implement new services in support of Information Technologies vision
  • Scale our services by implementing configuration as code via Terraform providers or APIs
  • Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  • Evangelize best practices both internally and externally facing

Requirements

  • 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments
  • Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems
  • Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics
  • Exceptional cross-functional collaboration and communication skills
  • Strong systems thinking for scalable GRC architectures
  • Bias for action as a self-starter

Nice-to-haves

  • Previous experience in Fintech or banking environments
  • Hands-on experience with Tines or other SOAR platforms
  • Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems
  • Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices
  • Relevant industry certifications such as CISSP, CISA, or CCSP
  • Experience building metrics dashboards for security visualization and reporting
  • Active contributions to the GRC or Security community

Compensation

Expected salary range: $153,600 - $192,000 base pay, depending on location, skills, experience, market demands, and internal pay parity. Equity and other forms of compensation may be provided.

Skills

PythonSOC 2Pci DssISO 27001Nist CsfTerraformTinesAWSGCPCissp

Senior Security Engineer, Security Engineering & Operations

Design and build scalable cloud-native security data pipelines and detection systems. Collaborate on detection engineering and Kubernetes security controls while participating in on-call rotations.

153k – 270kSan Francisco, CASecurity EngineeringOn-site5+ YOEGoGCP

Senior Security Engineer - GRC Controls and Audit

1Password is seeking a Senior Security Engineer to lead commercial audit programs, focusing on GRC controls and audit. This role involves defining and maintaining evidence libraries, executing control testing, and partnering with various teams to build durable evidence workflows, with an emphasis on AI-assisted automation.

153k – 214kUnited StatesSecurity EngineeringRemote5+ YOEAIDrata

Senior Security Engineer, GRC Automation

Senior Security Engineer focused on GRC automation: building AI-assisted workflows, Drata integrations, and compliance automation infrastructure for SOC 2, ISO 27001, and NIST frameworks.

153k – 214kUnited StatesSecurity EngineeringRemote5+ YOEAPIsLLMs

Senior Developer, Product Security

Senior security-focused developer implementing new security features and secure libraries for iOS and hybrid apps at 1Password. Requires 5+ years of security development experience, 3+ years with iOS and Rust.

153k – 214kUnited StatesSecurity EngineeringRemote5+ YOEFfiHsm

Senior Security Research Scientist

Conducts internet-wide security research using scan data to identify trends, vulnerabilities, and threats. Analyzes large datasets with tools like BigQuery and Snowflake, partners with engineering teams, and shares insights publicly. Requires deep knowledge of internet protocols.

153k – 212kSan Francisco, CA +3Security EngineeringRemoteTlsHttp