Назад
Company hidden
5 дней назад

Senior GRC Engineer (AI)

150 000 - 170 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Engineer (AI): Building a unified control architecture and AI-powered GRC tooling across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53 with an accent on framework crosswalks, evidence automation, and control lifecycle management. Focus on designing relational control schemas, building multi-agent compliance pipelines, and translating technical requirements into actionable engineering guidance.

Location: United States

Salary: $150,000–$170,000 base salary per year, plus potential performance bonus, benefits, and other applicable incentive compensation.

Company

hirify.global is a platform for intentional living and real-world experiences in fitness, wellness, and related areas, with brands including Mindbody, ClassPass, Booker, Kite, and EGYM.

What you will do

  • Design and maintain framework crosswalks and control mappings across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53.
  • Own the Master Control List, including control nomenclature, relational database architecture, evidence linkages, and ongoing maintenance across multiple brands.
  • Manage the lifecycle of controls, evidence requirements, and implementations as standards change and acquired entities enter scope.
  • Build evidence-collection workflows and compliance automation in GRC tooling.
  • Partner with Security Engineering, Legal, Finance, and product teams to turn control designs into practical implementation guidance.
  • Build AI-powered GRC tooling and multi-agent pipelines for risk quantification, evidence automation, vendor risk assessment, and compliance monitoring using cloud-native tools and APIs.

Requirements

  • 6+ years of experience in security engineering, GRC, or compliance engineering with hands-on work across multiple regulatory frameworks.
  • Deep knowledge of PCI DSS, SOC 1 or SOC 2, HITRUST, and at least one of ISO 27001 or NIST CSF/800-53.
  • Experience designing or maintaining control frameworks, crosswalks, or unified control architectures.
  • Hands-on experience managing evidence requirements and control implementation.
  • Proficiency with compliance automation tools such as Optro, Drata, Vanta, Hyperproof, or Anecdotes.
  • Experience building or operating production or near-production agentic AI workflows, including LLM pipelines, multi-agent systems, or RAG architectures.

Nice to have

  • Experience with AWS Lambda, Step Functions, EventBridge, S3, Aurora, or RDS for compliance automation infrastructure.
  • Experience supporting external audits or assessments as a primary technical contact.
  • Exposure to multi-brand or post-acquisition control harmonization.
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer, CCSFP, or PCI ISA.
  • Experience in a SaaS or consumer marketplace environment.

Culture & Benefits

  • Work on governance, risk, third-party risk, and compliance across a growing multi-brand portfolio.
  • Collaborate with Engineering, Legal, Finance, and product teams.
  • Compensation is designed to be competitive, fair, equitable, and transparent.
  • Total compensation may include a performance bonus, benefits, and other applicable incentive compensation.
  • hirify.global is an equal opportunity employer that values diverse backgrounds, experiences, abilities, and perspectives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →