Назад
Company hidden
4 дня назад

Sr. GRC Engineer (AI)

133 400 - 160 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. GRC Engineer (AI): Building and evolving governance, risk, and compliance programs across SOC 2, ISO 27001/42001, PCI-DSS, GovRAMP, and FedRAMP with an accent on AI-driven compliance operations, durable controls, and business-risk translation. Focus on leading complex incident investigations, designing audit-ready programs, and turning security findings into prioritized roadmap and investment decisions.

Location: Raleigh, NC; hybrid schedule with in-office work three days per week

Salary: $133,400–$160,000 base salary per year

Company

hirify.global is a SaaS company founded in 2013 that develops software focused on improving product experiences and product success.

What you will do

  • Use AI to accelerate audit evidence preparation, policy documentation, control testing, regulatory research, and security operations.
  • Identify security and compliance maturity gaps and translate them into prioritized roadmap and investment recommendations.
  • Own compliance programs such as SOC 2 Type II, ISO 27001/42001, PCI-DSS, GovRAMP, and FedRAMP from control design through audits and remediation.
  • Conduct organizational risk assessments and communicate technical exposure in business-risk terms to leadership.
  • Lead complex, multi-system incident response investigations, root cause analysis, post-incident reviews, and corrective actions.
  • Partner with engineering, product, and IT teams to embed security and compliance requirements into technical delivery.

Requirements

  • 3–5 years of hands-on security experience with ownership of compliance programs or security operations.
  • Deep working knowledge of at least two frameworks, including SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or the NIST 800-series.
  • Ability to independently manage auditor relationships and complete audit cycles end-to-end.
  • Experience leading incident response from triage through root cause analysis and producing actionable post-incident documentation.
  • Ability to translate security risk into business-risk language for investment and prioritization decisions.
  • Demonstrated use of AI tools in security workflows and strong written and verbal communication skills.

Nice to have

  • Experience with SIEM or EDR platforms such as Splunk, Elastic, CrowdStrike, or SentinelOne.
  • GRC platform administration experience with Vanta, Drata, or Archer.
  • Threat intelligence or threat hunting experience using MITRE ATT&CK.
  • Security certification such as CISA, CISSP, CISM, Security+, or equivalent.
  • Experience in a SaaS company with concurrent multi-framework compliance obligations.

Culture & Benefits

  • Hybrid culture with three in-office days per week for this role.
  • Employer-heavy health coverage, including $0 premium options.
  • Strong 401(k) match, equity, and flexible time off.
  • Values include Bias to Act, Hone Your Craft, The Team is hirify.global, and Maniacal Focus.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →