8 дней назад
Senior GRC Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC Engineer (Security Automation/Compliance): Building production GRC systems that collect, validate, preserve, and monitor technical control evidence with an accent on security controls, evidence pipelines, and continuous control testing. Focus on translating compliance requirements into testable controls, detecting evidence drift and failures, and operating maintainable automation for audits and regulated healthcare systems.
Location: On-site at the headquarters in central Stockholm, Sweden
Company
is a fast-scaling health-tech company building clinician-focused medical notes and healthcare workflows for global use.
What you will do
- Build production systems that collect, validate, preserve, and monitor technical control evidence.
- Automate shared security controls and create tests that verify controls operate as designed over time.
- Connect requirements, controls, implementations, tests, evidence, policies, and procedures with traceable records.
- Detect missing, stale, incomplete, or failed evidence and route issues to responsible owners.
- Build and operate GRC automation, evidence workflows, and policy-versus-implementation drift monitoring in production.
- Prepare reproducible evidence packages, support audits as a technical subject matter expert, and advise go-to-market, Compliance, and Legal teams.
Requirements
- Senior-level experience owning engineering problems from design through production and operating software, automation, or data pipelines.
- Experience working with APIs, cloud services, and structured data from multiple systems.
- Ability to translate security and compliance requirements into technical controls and testable conditions.
- Experience designing evidence records with provenance, scope, collection time, retention, access control, and auditability requirements.
- Strong software engineering practices, including testing, version control, code review, monitoring, and operational documentation.
- Ability to work primarily on-site from Stockholm, Sweden.
Nice to have
- Experience with ISO 27001, C5, SOC 2, or other security and quality management assessments.
- Experience with controls as code, policy as code, or continuous control monitoring.
- Experience in healthcare, regulated environments, or high-growth technology companies.
- Experience with infrastructure as code, cloud security, identity systems, CI/CD pipelines, or compliance platform integrations.
- Experience using AI for control mapping, evidence review, or policy analysis with human approval and traceable outputs.
Culture & Benefits
- Competitive salary and company stock options.
- 30 days of paid holiday annually.
- 5,000 SEK wellness allowance and 6,000 SEK annually for other health-related initiatives.
- Parental leave top-up, private medical insurance, mental health support through Mindler, and a pension programme.
- Regular social and team activities, including off-sites and seasonal events.
- Background check required before hiring due to sensitive patient data access.
Hiring process
- Applications are reviewed continuously; submit a CV in English.
- A background check is conducted before hiring.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Cybersecurity Engineer
13 дней назад
AI Security Consultant
6 дней назад
Senior Application Security Engineer (Mobile Apps)
11 дней назад
Experienced Security Tools Engineer (Static Code Analysis)
12 дней назад
Senior Consultant Automotive & Product Security
11 дней назад