5 дней назад
GRC Engineer (Security Operations)
140 000 - 170 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Engineer (Security Operations): Building compliance automation, control testing, audit workflows, and risk-management integrations with an accent on SOC 2, ISO 27001/42001, API-driven evidence collection, and control monitoring. Focus on tuning SIEM/SOAR systems, triaging alerts, supporting incident response, and connecting operational findings back to GRC controls.
Location: Santa Clara, California, United States
Salary: $140,000–$170,000 per year
Company
develops a network digital twin platform that models production networks across cloud and vendor environments to support autonomous networking, change-impact analysis, and network security.
What you will do
- Build compliance automation, API integrations, and scripts that collect evidence directly from source systems.
- Write and maintain security policies, procedures, control tests, and continuous control-monitoring workflows.
- Manage the GRC platform and lead day-to-day SOC 2 Type II audit activities while preparing for ISO 27001 and ISO 42001.
- Maintain the risk register, conduct risk assessments, and manage vendor security reviews and due diligence.
- Integrate compliance requirements into CI/CD, access provisioning, and change-management workflows.
- Expand into security operations by tuning SIEM/SOAR rules and playbooks, triaging alerts, supporting endpoint incidents, and participating in incident response.
Requirements
- 3+ years of experience in GRC, compliance, security engineering, IT audit, or an equivalent field.
- Experience with control design, risk assessment, compliance frameworks, and writing testable security policies and procedures.
- Hands-on experience with a GRC or compliance-automation platform such as Vanta, Drata, Thoropass, or Anecdotes.
- Solid SOC 2 knowledge; experience with ISO 27001 is beneficial, and interest in AI governance is expected for future ISO 42001 work.
- Ability to read, troubleshoot, and deliver working scripts using Python or Bash, work with SQL, and pull or parse data through APIs and log files.
- Exposure to SIEM/SOAR tools, incident response, endpoint compliance, and Mac-centric environments; ability to communicate with both auditors and engineers.
Nice to have
- Linux administration and scripting experience, plus familiarity with Terraform or policy-as-code.
- Security+, CISA, CISSP, or ISO 27001 Lead Implementer/Auditor certification.
- Experience tuning or migrating SIEM/SOAR systems, conducting incident response, and running tabletop exercises and post-mortems.
Culture & Benefits
- Work across both cloud infrastructure and an internally operated data center.
- Build an evolving GRC Engineering function combining compliance automation and security operations.
- Use automation and source-system evidence instead of manual spreadsheets and recurring evidence collection.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Sr. GRC Engineer (AI)
133 400 - 160 000$
6 дней назад
Security Compliance Analyst (EV)
130 000 - 160 000$
7 дней назад
GRC Specialist (AI)
200 000 - 220 000$
9 дней назад
Staff Security Analyst - GRC
160 000 - 190 000$
9 дней назад
Senior GRC Analyst
120 000 - 150 000$
8 дней назад
Security Analyst, GRC
100 000 - 120 000$